How to for NAT internal IP address so it only gets teeth when you go to a particular destination and is also the United Nations concerns

Hi all

I have the following 2 sites. A branch, a data center.  The two race NPA 8.3.

(192.168.120.1 (L3SW) - ASA)-PUBLIC INTERNET-(202.xxx.xx.242) ASA

DATA CENTER                                                                           BRANCH

I need 192.168.120.1 to be able to do a ping 202.xxx.xx.242 for the purpose of the SLA, which means that I need to NAT to break the internet. However, I also need to be able to SSH to 192.168.120.1 during several VPN tunnels to other branches on private subnets.

How can I configure a NAT to my ASA rule so that 192.168.120.1 tries to talk to 202.xxx.xx.242, NAT 192.168.120.1 to the internet, but all other destinations than 192.168.120.1 should talk to the service (IE LAN via VPN), do not NAT?

Hello Dean,

I would recommend a NAT twice basically is the same terminology as a 'political NAT', you can specify that your source host will be translated to some IP only when it is addressed to some destination or destinations, so, basically, you can create a network of the object with the IP address of the source, another network object with the public IP address you want to use to translate the 192.168.x.x address and then click the destination network object, so it will be like this:

network of the IP_192.168.120.1 object

Home 192.168.120.1

network of the TRANSLATED_IP_FOR_192.168.120.X object

host 99.99.99.99 -> an example

Network IP_202.XXX of the object. XXX.242

202.xxx of the host. XXX.242

NAT static IP_192.168.120.1 TRANSLATED_IP_FOR_192.168.120.X destination (indoor, outdoor) static source IP_202.XXX. XXX.242 IP_202.XXX. XXX.242

In this way traffic that comes 192.168.120.1 form through a VPN tunnel, it will not be matched this NAT statement, since this statements NAT says that he will only translated when switching to the 202.XXX. Address xxx.242, now you can run a package tracer and see how it goes,

Please note and hides as correct this answer if it helped you, keep me posted!

Thank you

David Castro,

Tags: Cisco Security

Similar Questions

Maybe you are looking for

  • Auto unblocking does not connect to Apple Watch

    Mac OS can not the Apple Watch checked all setting and still does not... its a pain in the tip of the ideas of troubleshooting?

  • Support for webOS

    I wonder if Firefox is available for HP webOS version 3.0.4?

  • Cannot mount .dmg: invalid protocol for socket type

    Hello. I can't climb any .dmg. Whenever I open a .dmg file, I get the error: protocol type invalid for the sleeve, despite several different .dmg files from different sources. Screenshot of error attached. I've rebooted my MacBook Pro several times,

  • On the Satellite L650-12Z DVD player does not work

    (this is posted on the US forums who sent me here) Hello. I have a bit of a problem with my portable DVD player. If I put a DVD in there, he turns and runs for 2 minutes, but he made nothing read (read: I do not hear the lens engine). Now, in this ag

  • WIN8 will not be upgraded

    WIN8 will be not updated, last update was 2 computer months ago will not be reset to zero/refresh, win8, 64 bit compaq 58... said storage of register file has been moved/changed...fixit does not.