Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ASA 5510 NAT and No NAT

Status
Not open for further replies.

philjray

ISP
May 16, 2006
1
GB
Hi, is it possible to set up the outside interface 0/0 with a virtual interface and have both a NAT and No NAT configuration?
The reason for this is to have VoIP devices on their own range behind the firewall with No NAT (routing is done privately over MPLS) and data going out via the NAT interface on another range.
Regards, Phil
 
I think you have to have the unit in either routed/transparent mode so you dont really have a choice.

You can however setup a NAT rule that translates your external IP to the same external IP but on the inside interface. That should do what you're trying to achieve and let you have the Firewall operate in routed mode.

The difference between genius and stupidity is that genius has its limits

Rob
 
It depends on networks and goals. Can you post a config and a topology that you want to achieve?

Brent
Systems Engineer / Consultant
CCNP, CCSP
 
It's possible to enable and disable the NAT based on traffic but for this, NAT must be enable on your ASA means " NAT-Control" should be enabled.

You can define the traffic and type of NAT for that traffic. Make sure if you are doing NAT for voice traffic then voice traffic related inspection is enable on ASA otherwise you will have issue on voice client registration.

Thanks,

Mustafa Gangardiwala
CCIE-Security # 16253, CISA
CISM,CISSP,INFOSEC, MCSE, CNE
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top