Configuring NAT Settings for Outbound Access

After the default route has been set, the PIX/ASA is almost ready to pass traffic between the inside, higher-security interface and the outside, lower-security interface. In most situations, to provide for this outbound traffic functionality you need to configure NAT because the firewall will typically be hiding the internal network IP addresses from the external network resources using NAT. This is not a requirement, however (although it is generally recommended), and the PIX/ASA 7.0 in particular does not require NAT for outbound communications. The configuration (or lack thereof) for NAT differs depending on whether you are using PIX 6.x or PIX/ASA 7.0.

Configuring NAT for PIX 6.x

Outbound access for the PIX firewall generally requires the configuration of two policies. First, define the translation method that is going to be used for the outbound requests. Second, ensure that if an ACL exists for the given network interface that an access rule is defined to allow the traffic in question. By default, the PIX firewall allows all traffic from a higher-security interface to a lower-security interface, by virtue of the fact that there is not a default ACL on any interface.

There are two primary methods of performing translation: a static translation or a dynamic translation. Static translations are essentially a one to one mapping of internal addresses to external addresses. Therefore, they require that the internal address not change and consequently do not tend to be an effective method of providing outside access to a bunch of hosts. Instead, they tend to be used in conjunction with ACLs to provide access to internal resources from external sources (we address this configuration later in this chapter).

Dynamic translation uses NAT/PAT to dynamically assign addresses (or ports) to internal hosts that require external access. The firewall keeps track of which communications sessions belong to each internal host and allows the firewall to perform the required translations.

To configure dynamic NAT, you need to build a NAT rule. The simplest way to do this is to specify what traffic is to be translated using the nat command and then set up a global pool using the global command. The nat command is used to define what local addresses will be included for NAT. The syntax of the command is this:

nat [(local-interface)] id local-ip [mask [ dns ] [ outside | [ norandomseq ]

The id and local-ip syntax are used to define the local IP addresses that will be included in the corresponding NAT translation (defined by the ID). A notable exception to this is the nat 0 access-list acl-name command, which configures the firewall to not use NAT for any addresses that match the corresponding ACL. This is typically used for access across VPN connections. In most other cases, you would define the NAT addresses as follows:

houqepixfw02(config)# nat (inside)1 0.0.0.0 0.0.0.0

In this case, we have specified to use NAT for all addresses. If we only wanted NAT to be used for addresses on the 10.1.1.0/24 subnet, we could have replaced the local-ip and mask with 10.1.1.0 and 255.255.255.0. After you have defined what local addresses should use NAT, the next step is to configure the global pool.

The global command is used to define the pool of global addresses that will be used by the translation rule. The easiest way to think of the global addresses is that these are the external addresses that the internal clients will appear to be coming from when they access external resources. You can specify one or more global addresses in the pool. If you specify a single address instead of performing NAT, the firewall will automatically perform PAT instead. The syntax of the command is this:

global [(if-name)] nat-id {global-ip [-global-ip] [netmask global-mask]} | interface

The interface syntax can be used to specify to use the interface IP address for PAT instead of defining an additional IP address for the global pool. This is particularly useful in cases where there is a single address available for use (for example, when using a PIX firewall in a SOHO environment over a broadband connection such as digital subscriber line [DSL] or cable modem). The following command configures a global pool on an outside interface to use addresses 10.21.67.40/28-10.21.67.45/28:

houqepixfw02(config)# global (outside)1 10.21.67.40-10.21.67.45 netmask

255.255.255.240

When all the IP addresses are being used by NAT, the firewall will automatically switch to using PAT (assuming that a PAT statement has been configured) to allow more addresses out. Alternatively, if you only have the IP address that is assigned to the interface, you can simplify the global command as follows:

houqepixfw02(config)# global (outside)1 interface outside interface address added to PAT pool houqepixfw02(config)#

Assuming that there is not an ACL that needs to be configured, the hosts defined by the NAT translation rule will have outbound access.

Configuring NAT for PIX/ASA 7.x

A major difference between the PIX/ASA 7.x software and previous versions is that by default the firewall does not require NAT and will allow outbound access with no additional configuration required. Of course, if your environment requires

NAT (which most Internet-connected firewalls require), you must execute the appropriate NAT configuration commands on the firewall.

To require NAT for communications, you must first run the nat-control command (no additional syntax). When NAT control is disabled (the default), the firewall allows communications with outside hosts without the configuration of a NAT rule. When NAT control has been enabled, the next step is to run the nat and global commands. For the PIX/ASA 7.x, the nat and global syntax differs slightly:

nat (real-ifc) nat-id real-ip [mask [dns] [outside] [ [tcp] tcp-max-conns

[emb-limit]] [udp> udp-max-conns] [norandomseq]] global (mapped-ifc) nat-id {mapped-ip [-mapped-ip] [netmask mask] | interface}

In this particular case, however, the actual commands are the exact same command syntax for previous versions of software. Therefore, running all three commands might look like this:

houqepixfw01(config)# nat-control houqepixfw01(config)# nat (inside)1 0.0.0.0 0.0.0.0 houqepixfw01(config)# global (outside)1 10.21.67.10-10.21.67.14 netmask

255.255.255.240

In this case, NAT control is enabled, a NAT pool for all internal addresses is configured, and a global pool from 10.21.67.10 through 10.21.67.14 is configured. At this point, internal hosts can access external resources using NAT.

Alternatively, if you only have the IP address that is assigned to the interface, you can simplify the global command as follows:

houqepixfw01(config)# global (outside)1 interface INFO: outside interface address added to PAT pool houqepixfw01(config)#

Continue reading here: Configuring the ACLs

Was this article helpful?

0 0