{"id":1191,"date":"2010-12-24T09:22:44","date_gmt":"2010-12-24T09:22:44","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=1191"},"modified":"2016-08-09T12:06:00","modified_gmt":"2016-08-09T12:06:00","slug":"asa-8-3x-dynamic-pat-with-two-internal-networks-and-internet-configuration","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2010\/12\/24\/asa-8-3x-dynamic-pat-with-two-internal-networks-and-internet-configuration\/","title":{"rendered":"ASA 8.3(x) Dynamic PAT with Two Internal Networks and Internet Configuration"},"content":{"rendered":"<h3><a name=\"req\">Requirements<\/a><\/h3>\n<p>Ensure that you meet these requirements before you attempt this \t configuration:<\/p>\n<ul>\n<li>Make sure the internal network has two networks located on the inside \t\tof the ASA:\n<ul>\n<li>192.168.0.0\/24\u2014Network directly connected to the \t\t  ASA.<\/li>\n<li>192.168.1.0\/24\u2014Network on the inside of the ASA, but behind another \t\t  device (for example, a router).<\/li>\n<\/ul>\n<\/li>\n<li>Make sure the internal users get PAT as follows:\n<ul>\n<li>Hosts on the 192.168.1.0\/24 subnet will get PAT to a spare IP \t\t  address given by the ISP (10.1.5.5).<\/li>\n<li>Any other host behind the inside of the ASA will get PAT to the \t\t  outside interface IP address of the ASA \t\t  (10.1.5.1).<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3><a name=\"hw\">Components Used<\/a><\/h3>\n<p>The information in this document is based on these software and \t hardware versions:<\/p>\n<ul>\n<li>Cisco Adaptive Security Appliance (ASA) with version \t\t8.3(1)<\/li>\n<li>ASDM version 6.3(1)\n<p><img decoding=\"async\" src=\"file:\/\/\/tmp\/moz-screenshot.png\" alt=\"\" \/><\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"http:\/\/www.cisco.com\/image\/gif\/paws\/111842\/asa-dynamic-pat-01.gif\" border=\"0\" alt=\"asa-dynamic-pat-01.gif\" \/><\/p>\n<h3><a name=\"cli\">ASA CLI Configuration<\/a><\/h3>\n<p>This document uses the configurations shown below.<\/p>\n<p><a name=\"config\"> <\/a><\/p>\n<table border=\"1\" cellspacing=\"1\" cellpadding=\"3\" width=\"60%\" bgcolor=\"#ffffff\">\n<tbody>\n<tr>\n<th>ASA Dynamic PAT Configuration<\/th>\n<\/tr>\n<tr>\n<td bgcolor=\"#ffffff\">\n<pre>ASA#<strong>configure terminal<\/strong>\nEnter configuration commands, one per line.  End with CNTL\/Z.\n\n<em>\n<span style=\"color: #0000ff;\">!--- Creates an object called OBJ_GENERIC_ALL.\n!--- Any host IP not already matching another configured\n!--- object will get PAT to the outside interface IP\n!--- on the ASA (or 10.1.5.1), for internet bound traffic.<\/span>\n<\/em>\n\nASA(config)#<strong>object network OBJ_GENERIC_ALL<\/strong>\nASA(config-obj)#<strong>subnet 0.0.0.0 0.0.0.0<\/strong>\nASA(config-obj)#<strong>exit<\/strong>\nASA(config)#<strong>nat (inside,outside) source dynamic OBJ_GENERIC_ALL interface<\/strong>\n\n<em>\n<span style=\"color: #0000ff;\">!--- The above statements are the equivalent of the\n!--- nat\/global combination (as shown below) in v7.0(x),\n!--- v7.1(x), v7.2(x), v8.0(x), v8.1(x) and v8.2(x) ASA code:<\/span>\n<\/em>\n\n<strong>nat (inside) 1 0.0.0.0 0.0.0.0\nglobal (outside) 1 interface<\/strong>\n\n\n<em>\n<span style=\"color: #0000ff;\">!--- Creates an object called OBJ_SPECIFIC_192-168-1-0.\n!--- Any host IP facing the the \u2018inside\u2019 interface of the ASA\n!--- with an address in the 192.168.1.0\/24 subnet will get PAT\n!--- to the 10.1.5.5 address, for internet bound traffic.<\/span>\n<\/em>\n\nASA(config)#<strong>object network OBJ_SPECIFIC_192-168-1-0<\/strong>\nASA(config-obj)#<strong>subnet 192.168.1.0 255.255.255.0<\/strong>\nASA(config-obj)#<strong>exit<\/strong>\nASA(config)#<strong>nat (inside,outside) source dynamic OBJ_SPECIFIC_192-168-1-0 10.1.5.5<\/strong>\n\n<em>\n<span style=\"color: #0000ff;\">!--- The above statements are the equivalent of the nat\/global\n!--- combination (as shown below) in v7.0(x), v7.1(x), v7.2(x), v8.0(x),\n!--- v8.1(x) and v8.2(x) ASA code:<\/span>\n<\/em>\n\n<strong>nat (inside) 2 192.168.1.0 255.255.255.0\nglobal (outside) 2 10.1.5.5<\/strong>\n<\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a name=\"config\"> <\/a><a name=\"configpix\"> <\/a><\/p>\n<table border=\"1\" cellspacing=\"1\" cellpadding=\"3\" width=\"60%\" bgcolor=\"#ffffff\">\n<tbody>\n<tr>\n<th>ASA 8.3(1) Running Config<\/th>\n<\/tr>\n<tr>\n<td bgcolor=\"#ffffff\">\n<pre>ASA Version 8.3(1)\n!\nhostname ASA\n1\nnames\n!\n<em>\n<span style=\"color: #0000ff;\">!--- Configure the outside interface.<\/span>\n<\/em>\n!\ninterface GigabitEthernet0\/0\n nameif outside\n security-level 0\n ip address 10.1.5.1 255.255.255.0\n<em>\n<span style=\"color: #0000ff;\">!--- Configure the inside interface.<\/span>\n<\/em>\n!\ninterface GigabitEthernet0\/1\n nameif inside\n security-level 100\n ip address 192.168.0.1 255.255.255.0 \n!\n!\nboot system disk0:\/asa831-k8.bin\n!\n!\n<strong>object network OBJ_SPECIFIC_192-168-1-0 \n subnet 192.168.1.0 255.255.255.0\nobject network OBJ_GENERIC_ALL \n subnet 0.0.0.0 0.0.0.0<\/strong>\n!\n<strong>nat (inside,outside) source dynamic OBJ_GENERIC_ALL interface\nnat (inside,outside) source dynamic OBJ_SPECIFIC_192-168-1-0 10.1.5.5<\/strong>\n<\/pre>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Requirements Ensure that you meet these requirements before you attempt this configuration: Make sure the internal network has two networks located on the inside of the ASA: 192.168.0.0\/24\u2014Network directly connected to the ASA. 192.168.1.0\/24\u2014Network on the inside of the ASA, but behind another device (for example, a router). Make sure the internal users get PAT [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16,802,17,2,3,4,5,6,7,804,18,8,9,11,803,14,15],"tags":[70,89,97,164],"class_list":["post-1191","post","type-post","status-publish","format-standard","hentry","category-bgp-2","category-checkpoint","category-cisco-asa","category-cisco-mpls","category-cisco-routers","category-cisco-switch","category-firebrick","category-firewalsl","category-hot-standby","category-hp","category-iptables-linux","category-linux","category-microsoft","category-routing-protocol","category-vm","category-xrio","category-zyxel-router","tag-asa-8-3","tag-asa-pat","tag-asa-static-nat","tag-cisco-asa-8-3"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=1191"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1191\/revisions"}],"predecessor-version":[{"id":4852,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1191\/revisions\/4852"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=1191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=1191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=1191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}