by Guest » Sat Jan 08, 2011 6:08 pm
Hi halijenn, thanks for the reply, i will test it out after hour (cannot conduct any testing on production time...) but anyhow, i never do the attemp same like what you showing on the screenshot do... i hope you can give more idea on how to do on ASA - NAT. (im ok with fundamental routing & switching part, but i am still very fresh with ASA, esp ASDM GUI..) (1) normal practice doing firewalling, first is it need to define the network object and service object, so that these element can let for re-use on either ACL or NAT section,rite? then only we go for ACL, for lower security-level interface would like go inside interface etc etc...then come to NAT (2) assuming this topology, 2 interface (inside, outside). i just wonder why once i create NAT then it will auto treat my source and destination network be part of any new object ? it seems like defeat my (1) step action, making duplicated on the network object. (3) for firewall > NAT rules, how to configure on "Add NAT Rulebefore /after network onect NAT rules.." mean? (attachment)It just confuse me why original packet with soure and destination address, then action:translate packet also with source and destination address.. (4) once i do in CLI, natting now seem only can do on network object..i am more on old school like static (inside, outside)... confuse..hope u can guide
Hi halijenn, thanks for the reply, i will test it out after hour (cannot conduct any testing on production time...) but anyhow, i never do the attemp same like what you showing on the screenshot do... i hope you can give more idea on how to do on ASA - NAT. (im ok with fundamental routing & switching part, but i am still very fresh with ASA, esp ASDM GUI..) (1) normal practice doing firewalling, first is it need to define the network object and service object, so that these element can let for re-use on either ACL or NAT section,rite? then only we go for ACL, for lower security-level interface would like go inside interface etc etc...then come to NAT (2) assuming this topology, 2 interface (inside, outside). i just wonder why once i create NAT then it will auto treat my source and destination network be part of any new object ? it seems like defeat my (1) step action, making duplicated on the network object. (3) for firewall > NAT rules, how to configure on "Add NAT Rulebefore /after network onect NAT rules.." mean? (attachment)It just confuse me why original packet with soure and destination address, then action:translate packet also with source and destination address.. (4) once i do in CLI, natting now seem only can do on network object..i am more on old school like static (inside, outside)... confuse..hope u can guide