Cisco Security Cloud Control: Secure Firewall ASA Management

PDF

Cisco Security Cloud Control: Secure Firewall ASA Management

Network Address Translation wizard

Want to summarize with AI?

Log in

An overview of network address translation wizard for ASA devices, including translated addresses, rule behavior, interface scope, and policy impact.


The Network Address Translation (NAT) wizard helps you create NAT rules on your devices for these types of access:

  • Enable Internet Access for Internal Users. You may use this NAT rule to allow users on an internal network to reach the internet.

  • Expose an Internal Server to the Internet. You may use this NAT rule to allow people outside your network to reach an internal web or email server.

Prerequisites to "Enable Internet Access for Internal Users"

Before you create your NAT rule, gather this information:

  • The interface that is closest to your users; this is usually called the "inside" interface.

  • The interface closest to your Internet connection; this is usually called the "outside" interface.

  • If you want to allow only specific users to reach the internet, you need the subnet addresses for those users.

Prerequisites to "Expose an Internal Server to the Internet"

Before you create your NAT rule, gather this information:

  • The interface that is closest to your users; this is usually called the "inside" interface.

  • The interface closest to your Internet connection; this is usually called the "outside" interface.

  • The IP address of the server inside your network that you would like to translate to an internet-facing IP address.

  • The public IP address you want the server to use.

What to do Next

See Create a NAT Rule by using the NAT Wizard.


Create a NAT Rule by using the NAT Wizard

Before you begin

See Network Address Translation wizard for the prerequisites needed to create NAT rules using the NAT wizard.

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab to locate the device or the Templates tab to locate the model device.

3.

Click the appropriate device type tab.

4.

Use the filter (filter) and search (search) fields to find the device for which you want to create the NAT rule.

5.

In the Management area of the details panel, click NAT .

6.

Click > NAT Wizard.

7.

Respond to the NAT Wizard questions and follow the on-screen instructions.

  • The NAT Wizard creates rules with Network objects. Either select an existing object from the drop-down menu, or create a new object with the create button .

  • Before you can save the NAT rule, all IP addresses need to be defined as network objects.

8.

Review and deploy now the changes you made, or wait and deploy multiple changes at once.