Cisco ASA NAT question

regnez

Golden Member
Aug 11, 2006
1,156
0
76
Let me preface with how little I actually know about Cisco PIX/ASA hardware and configuration, so I apologize if this is something simple or, on the other end of the spectrum, not possible.

Say I wanted to translate an internal address that machines were trying to hit -- 172.16.1.50 as an example -- into an external, public address of 12.200.242.26. That public address is NOT an address of mine, just a public IP of something available on the internet.

Is this something achievable with a Cisco ASA 5505 using NAT?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
No. That's a function of internet routing. If it's an address that isn't in your public address space there is no way for the traffic to reach you or the ASA.
 

DnetMHZ

Diamond Member
Apr 10, 2001
9,826
1
81
Are you saying that you want your internal users who try to access 172.16.1.50 to be redirected to 12.200.242.26?
 

Railgun

Golden Member
Mar 27, 2010
1,289
2
81
If you want your hosts to hit 12.200....instead of 172.16....you can do it but you have to have the FW between that 172.16 subnet and the rest of your environment to put it simply. There are other ways so you don't have to do that, but it depends on what you want to do.

There are other routing considerations you have to take into account as well. Can you explain exactly what you want to do and how your environment is set up? Is this completely internal to your environment?
 

regnez

Golden Member
Aug 11, 2006
1,156
0
76
Are you saying that you want your internal users who try to access 172.16.1.50 to be redirected to 12.200.242.26?

Right, I simply want that internal address to be redirected to the external one.
 

regnez

Golden Member
Aug 11, 2006
1,156
0
76
No, you cannot route, therefore NAT something that is not your address to route.

I'm not looking to use that address to cross the internet. My goal is simply to redirect folks trying to access 172.16.1.50 to a separate address.
 

regnez

Golden Member
Aug 11, 2006
1,156
0
76
No. That's a function of internet routing. If it's an address that isn't in your public address space there is no way for the traffic to reach you or the ASA.

I am not looking to cross the internet with an address that is not mine, nor am I looking to assign that address to my ASA. I simply want the requested internal address to be redirected to the external one.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
I am not looking to cross the internet with an address that is not mine, nor am I looking to assign that address to my ASA. I simply want the requested internal address to be redirected to the external one.

Then you'll need a web server, proxy server or load balancer to do the HTTP redirection.
 

Railgun

Golden Member
Mar 27, 2010
1,289
2
81
So if it truely is an external address, then why not just have the users hit that address?

Otherwise, yes you CAN do it. It's not pretty though...

Create a static route in your environment for the 172 host that points to that FW. You NAT the destination address to that public then it goes out towards your internet connection. The FW will have a route for that public pointing to wherever your current default route may go (depending on your network).

If it's as simple as making one destination address really go to another address, we have several environments that do the same thing today. Like I said, it's not the prettiest setup, but it works just fine.

The ASA can route. You just need to set it up that way.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |