Configuring Static Identity NAT

information about policy NAT). For example, you can use policy static identity NAT for an inside address when it accesses the outside interface and the destination is server A, but use a normal translation when accessing the outside server B.

Figure 17-24 shows a typical static identity NAT scenario.

Figure 17-24 Static Identity NAT

Security

Figure 17-24 Static Identity NAT

Security

209.165.201.1

-

209.165.201.1

209.165.201.2

*

209.165.201.2

4

Inside /Outside

Note If you remove a static command, existing connections that use the translation are not affected. To remove these connections, enter the clear local-host command.

You cannot clear static translations from the translation table with the clear xlate command; you must remove the static command instead. Only dynamic translations created by the nat and global commands can be removed with the clear xlate command.

To configure static identity NAT, enter one of the following commands:

• To configure policy static identity NAT, enter the following command:

hostname(config)# static (real_interface,mapped_interface) real_ip access-list acl_id [dns] [norandomseq] [[tcp] tcp_max_conns [emb_limit]] [udp udp_max_conns]

Create the access list using the access-list command (see the "Adding an Extended Access List" section on page 16-5). This access list should include only permit ACEs. Make sure the source address in the access list matches the real_ip in this command. Policy NAT does not consider the inactive or time-range keywords; all ACEs are considered to be active for policy NAT configuration. See the "Policy NAT" section on page 17-9 for more information.

See the "Configuring Dynamic NAT or PAT" section on page 17-22 for information about the other options.

• To configure regular static identity NAT, enter the following command:

hostname(config)# static (real_interface,mapped_interface) real_ip real_ip [netmask mask] [dns] [norandomseq] [[tcp] tcp_max_conns [emb_limit]] [udp udp_max_conns]

Specify the same IP address for both real_ip arguments.

See the "Configuring Dynamic NAT or PAT" section on page 17-22 for information about the other options.

For example, the following command uses static identity NAT for an inside IP address (10.1.1.3) when accessed by the outside:

hostname(config)# static (inside,outside) 10.1.1.3 10.1.1.3 netmask 255.255.255.255

The following command uses static identity NAT for an outside address (209.165.201.15) when accessed by the inside:

hostname(config)# static (outside,inside) 209.165.201.15 2 09.165.201.15 netmask 255.255.255.255

The following command statically maps an entire subnet:

hostname(config)# static (inside,dmz) 10.1.2.0 10.1.2.0 netmask 255.255.255.0

The following static identity policy NAT example shows a single real address that uses identity NAT when accessing one destination address, and a translation when accessing another:

hostname(config)# access-list NET1 permit ip host 10.1.2.27 209.165.201.0 255.255.255.224 hostname(config)# access-list NET2 permit ip host 10.1.2.27 209.165.200.224 255.255.255.224

hostname(config)# static (inside,outside) 10.1.2.27 access-list NET1 hostname(config)# static (inside,outside) 209.165.202.130 access-list NET2

Continue reading here: Configuring NAT Exemption

Was this article helpful?

0 0