From a 3rd Party company there is a Fibre link terminating into interface
GigabitEthernet0/2 – RR_VLAB – 192.168.#.100/24.
The IP Address of the 3rd party is 192.168.#.5/24
The 3rd Party is connecting to network 192.168.#.100/24 on interface
GigabitEthernet0/2 – RR_VLAB to interface
GigabitEthernet0/3 – DMZ_QUICK – 10.0.#.1/24 to access the server 0n IP 10.0.#.2
The 3rd Party is coming into network on interface GigabitEthernet0/2 using these IP Network
addresses :
10.121.67.64 255.255.255.192
10.253.119.251 255.255.255.255
160.50.100.0 255.255.255.0
We need to translate the incoming network address from the 3rd party to a private routable address from
within the network within the RR_VLAB interface network address.
All traffic from the 3rd party to get to the server on the internal network on IP 10.0.#.2 will have their
destination address NaTed to 192.168.#.101 and further translated to IP 10.0.#.2 of the internal server.
Here is the ASA Configuration :
interface GigabitEthernet0/3
nameif DMZ_QUICK
security-level 30
ip address 10.0.#.1 255.255.255.0
!
interface GigabitEthernet0/2
nameif RR_VLAB
security-level 10
ip address 192.168.#.100 255.255.255.0
!
Static Nat Translation :
static (DMZ_QUICK,RR_VLAB) 192.168.#.101 10.0.#.2 netmask 255.255.255.255
!
Routing Table :
S 10.121.67.64 255.255.255.192 [1/0] via 192.168.#.5, RR_VLAB
S 10.253.119.251 255.255.255.255 [1/0] via 192.168.#.5, RR_VLAB
S 160.50.100.0 255.255.255.0 [1/0] via 192.168.#.5, RR_VLAB
C 192.168.#.0 255.255.255.0 is directly connected, RR_VLAB
Note : No reverse static NAT translation is configured here. This only applies to 1 way traffic.
Comments
(There are currently no comments for this post.)