Policy Based NaTing
object network obj-any
subnet 0.0.0.0 0.0.0.0
!
object service obj-icmp
service icmp
!
nat (outside,outside) source dynamic obj-any interface destination obj-any obj-any
service obj-icmp obj-icmp
!
!
So for example we want to NAT our internal (real) addresses to a public (mapped)
address only if they are destined for a particular destination.
We begin by creating our first network object and enter our inside network addresses.
(config)# object network NAT_INSIDE_HOSTS
(config-network-object)#subnet 192.168.1.0 255.255.255.0
We then create a separate network object and specify our public (mapped) address.
(config)# object network NAT_PUBLIC
(config-network-object)#host 10.1.1.1
And then create a third object for our destination hosts our inside users will be accessing.
(config)# object network NAT_PUBLIC_HOSTS
(config-network-object)#host 172.31.1.1
We can now create our NAT rule using the three network objects above.
(config)#nat (inside,outside) source dynamic NAT_INSIDE_HOSTS NAT_PUBLIC
destination static NAT_PUBLIC_HOSTS NAT_PUBLIC_HOSTS
!
!
If we wanted to only NAT our inside hosts to our public address when they were
attempting to access the public hosts above on a specific port we use the second type
of object, the service object like so.
(config)# object service DESTINATION_PORT
(config-network-object)#service tcp destination eq smtp
!
(config)#nat (inside,outside) source dynamic NAT_INSIDE_HOSTS NAT_PUBLIC
destination static NAT_PUBLIC_HOSTS NAT_PUBLIC_HOSTS service
DESTINATION_PORT DESTINATION_PORT
Now your probably wondering why I’ve entered the object group NAT_PUBLIC_HOSTS
twice in each of the NAT rules above, this is due to the behavior of identity NAT,
when entering the NAT command after the ‘destination static’ keywords we are given the
option of specifying a ‘real’ address and a ‘mapped’ address,
which would come in handy if for example we wanted to NAT both the destination and
source addresses of traffic at the same time in one rule.
However for this example and for the majority of real life configuration scenarios you will
want to keep the original destination address as this is likely to be a public address on the
internet and you do this by configuring ‘Identity NAT’ by specifying the same address,
In this case 172.31.1.1, for both the real and mapped addresses, the same applies for the
services, i.e. source and destination ports as shown in the final NAT rule above.
Comments
(There are currently no comments for this post.)