Re: OT:ASA question

From: David Rothera <david.rothera_at_gmail.com>
Date: Wed, 1 May 2013 18:42:40 +0100

Do a static one-to-one NAT for the 10.10.10.12 and then use more specific PAT's for the other addresses.

It will warn you about it being bad but it will work all the same.

That is as long as 2.2.2.2 isnt your firewalls outside interface IP, in which case take extra care...

-- 
David Rothera
CCIE #38338
david.rothera_at_gmail.com
M: 07584060207
W: networkbroadcast.co.uk
On Saturday, 27 April 2013 at 16:30, Dennis Worth wrote:
> Group,
> 
> I ran into an issue with port ranges for static Natting in ver 8.2.1 Anyone
> come up with a work around this?
> 
> static (DMZ,OUTSIDE) tcp 2.2.2.2 https 10.10.10.10 https netmask
> 255.255.255.255
> static (DMZ,OUTSIDE) tcp 2.2.2.2 444 10.10.10.11 444 netmask
> 255.255.255.255
> static (DMZ,OUTSIDE) tcp 2.2.2.2 445 10.10.10.12 445 netmask
> 255.255.255.255
> 
> 
> This is what i want to do, but can't.
> static (DMZ,OUTSIDE) udp 2.2.2.2 50000-59999 10.10.10.12 50000-59999
> netmask 255.255.255.255
> 
> Thanks,
> 
> -- 
> Dennis Worth
> 
> 
> Blogs and organic groups at http://www.ccie.net
> 
> _______________________________________________________________________
> Subscription information may be found at: 
> http://www.groupstudy.com/list/CCIELab.html
Blogs and organic groups at http://www.ccie.net
Received on Wed May 01 2013 - 18:42:40 ART

This archive was generated by hypermail 2.2.0 : Mon Jun 03 2013 - 06:34:34 ART