nat (inside,outside) static = Provided 1 to 1 nat from external to internal and gets nested
within the object network group
.
!
nat (inside,outside) source static = Provides internal traffic to get naTTed using the
Public naTTed ip address rather than using the global dynamic ip address otherwise packets
would get lost and dropped
.
!
object network CCTV_ACL  (This object is referenced on a firewall rule below & NaT source).
host 10.0.0.100
!
object network CCTV_PUBLIC-IP
(This object is referenced on a NaT static).
host 2. 2.2.211
!
object network CCTV_WEB
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  www www
!
object network CCTV_FTP
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  ftp ftp
!
object network CCTV_TELNET
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  telnet telnet
!
object network CCTV_5201
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  5201 5201
!
object network CCTV_1025
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  1025 1025
!
object network CCTV_2074
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  2074 2074
!
object network CCTV_2075
host 10.0.0.100
nat (inside,outside) static CCTV_PUBLIC-IP service tcp  2075 2075
!
!
object-group service CCTV_PORTS tcp
description CCTV_COMMUNICATION_PORTS
port-object eq www
port-object eq ftp
port-object eq telnet
port-object eq 5201
port-object eq 1025
port-object range 2074 2075
!
access-list outside_in line 10 extended permit tcp any object CCTV_ACL object-group CCTV_PORTS
access-list inside_out line 6 extended permit tcp any object CCTV_ACL object-group CCTV_PORTS
!
access-group outside_in in interface outside (Assign to outside in Interface).
access-group inside_out out interface inside (Assign to inside out Interface).
!
nat (inside,outside) source static CCTV_ACL CCTV_PUBLIC-IP destination
static CCTV_PUBLIC-IP CCTV_ACL