Ip address and Security Level Assignment :
interface e0/0
nameif outside
security-level 0
ip address 10.10.10.1 255.255.255.248
nameif outside
security-level 0
ip address 10.10.10.1 255.255.255.248
!
!
!
Dynamic NAT/PAT :
object network obj-192.168.1.0
subnet 192.168.1.0 255.255.255.0
nat (inside,outside) dynamic 209.165.201.3
!
!
object network obj-10.1.1.0
subnet 10.1.1.0 255.255.255.0
nat (dmz,outside) dynamic 209.165.201.3
!
!
Static NAT/PAT :
object network obj-10.1.1.16
host 10.1.1.16
nat (inside,outside) static 10.1.2.45 service tcp 8080 www
!
!
object network obj_any
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic interface
!
!
!
NAT Control :
Four interfaces : inside, outside, dmz, and mgmt
Four interfaces : inside, outside, dmz, and mgmt
!
object network obj_any
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic obj-0.0.0.0
!
object network obj-0.0.0.0
host 0.0.0.0
!
object network obj_any-01
subnet 0.0.0.0 0.0.0.0
nat (inside,mgmt) dynamic obj-0.0.0.0
!
object network obj_any-02
subnet 0.0.0.0 0.0.0.0
nat (inside,dmz) dynamic obj-0.0.0.0
!
object network obj_any-03
subnet 0.0.0.0 0.0.0.0
nat (mgmt,outside) dynamic obj-0.0.0.0
!
object network obj_any-04
subnet 0.0.0.0 0.0.0.0
nat (dmz,outside) dynamic obj-0.0.0.0
!
object network obj_any-05
subnet 0.0.0.0 0.0.0.0
nat (dmz,mgmt) dynamic obj-0.0.0.0
!
!
DNS Rewrite :
object network obj-192.168.100.10
host 192.168.100.10
nat (inside,outside) static 172.20.1.10 dns
!
!
Static : PAT (Port Forwarding)
access-list inbound extended permit tcp any object obj-192.168.1.10-01 eq smtp
access-list inbound extended permit tcp any object obj-192.168.1.10 eq www
!
!
object network obj-192.168.1.10
host 192.168.1.10
!
object network obj-192.168.1.10-01
host 192.168.1.10
!
!
object network obj-192.168.1.10
nat (inside,outside) static interface service tcp www www
!
object network obj-192.168.1.10-01
nat (inside,outside) static interface service tcp smtp smtp
!
!
!
No NAT :
object network obj-192.168.1.10
subnet 192.168.1.10 255.255.255.0
!
object network obj-66.67.70.0
subnet 66.67.70.0 255.255.255.0
!
nat (inside,any) source static obj-192.168.1.10.0 obj-192.168.1.10.0 destination static obj-66.67.70.0 obj-66.67.70.0
!
!
!
Access Lists :
access-list inbound extended permit tcp any object obj-10.254.254.5
!
access-group inbound in interface outside
!
!
object network obj-10.254.254.5
host 10.254.254.5
!
!
nat (inside,outside) static 123.123.123.123 service tcp www www
Comments
(There are currently no comments for this post.)