Configuring Network Address Translation (NAT) | Cisco ASA Firewalls

  Рет қаралды 38,568

Network Direction

Network Direction

Күн бұрын

Configuring Network Address Translation (NAT) | Cisco ASA Firewalls
By popular demand, here is the live config and explanation of Network Address Translation (NAT) on the Cisco ASA Firewall.
We’re approaching this by using a lab, built in VIRL. This is based on the lab we used in the ACL video. If you’re a Patreon supporter you can download this lab in VIRL, GNS3, or just the config files (link below).
We’ve created a more realistic scenario, where we need public IP addresses to reach the internet. There’s a few things that we need to configure now; We need an IP for general internet access (dynamic NAT, using PAT or a PAT pool), We also need a static NAT, so devices on the internet can reach the intranet server.
In addition, we want to consider how DNS will work, now that there will be different IP addresses on the Inside, DMZ, and Outside areas.
There are some concepts we’ll cover as well. These include Object NAT and Twice NAT, and how they apply in different sections to create NAT policies.
Another concept is real addresses (the original address) and mapped addresses (the translated address). In addition, we need to consider unidirectional NAT and bidirectional NAT. Not to mention talking about source NAT and destination NAT.
Lab: networkdirection.net/labsandq...
Patreon information: networkdirection.net/patreon/
ASA Clustering: • ASA Firewalls | High A...
Cisco ASA: All-in-one Next-Generation Firewall, IPS, and VPN Services (affiliate): click.linksynergy.com/link?id...
Overview of this video:
0:00 Introduction
0:21 Lab Setup
2:17 ASA’s Viewpoint of NAT
4:34 Static NAT
7:02 Dynamic NAT
12:47 Rule Order
16:40 Static Port Translation
18:28 Identity NAT
20:57 DNS Rewrite
LET'S CONNECT
🌏 / networkdirection
🌏 / netwrkdirection
🌏 / networkdirection
🌏 www.networkdirection.net
#NetworkDirection

Пікірлер: 20
@NetworkDirection
@NetworkDirection 5 жыл бұрын
Thanks for watching! Lab files here: networkdirection.net/labsandquizzes/labs/lab-nat-on-the-cisco-asa/
@fernandoalbuquerque6645
@fernandoalbuquerque6645 3 жыл бұрын
Terrific teaching.
@NetworkDirection
@NetworkDirection 3 жыл бұрын
Thanks!
@markspeeps
@markspeeps 4 жыл бұрын
OMG I wish I would have seen a video like this when I first started working on ASA firewalls. It fills in many of the blanks I had in the past.
@NetworkDirection
@NetworkDirection 4 жыл бұрын
Too bad I couldn't have done this sooner!
@rebeccarobertson8360
@rebeccarobertson8360 5 жыл бұрын
Loving the beginning of this video! The visuals are great!
@NetworkDirection
@NetworkDirection 5 жыл бұрын
Thanks!
@johnvincentsison7147
@johnvincentsison7147 4 жыл бұрын
Great reference for NAT in ASA!!! Big THANKS!
@keooka
@keooka 4 жыл бұрын
Very good video. Make more! Thanks
@NetworkDirection
@NetworkDirection 4 жыл бұрын
Glad you like it!
@AmbientMelancholy
@AmbientMelancholy 3 жыл бұрын
I must have missed it, but at 9:25 when you're configuring the ACL again, you use object-group web...when/what video was that object group defined?
@ChampionCCC
@ChampionCCC 4 жыл бұрын
Excellent video tutorial. I paid the Patreon sub and downloaded the Lab and imported it into GNS3, but it gives me an error - The image notexisting.bin is missing - and will not allow the files to be opened by GNS3. Please provide an openable solution under GNS3.
@TheRealoldcar
@TheRealoldcar 4 жыл бұрын
is it possible for an inside user computer to connect to a fixed known IP address and have the ASA forward the request to a internet server by its domain name with a continually changing dynamic IP address; with a NAT rule that would have something like NAT (Inside, Outside) static x.x.x.x domain name
@haroldcalderon4514
@haroldcalderon4514 3 жыл бұрын
thanks a lot. One question What happen if I configure a Static nat interface inside interface outside source static a.a.a.a b.b.b.b destination c.c.c.c c.c.c.c but what happend if the destiny is who open the ¿connection? make the nat in reverse too or not?
@Up.Surged
@Up.Surged 4 жыл бұрын
10:10 Can this make the firewall generate traffic with its own IP as source? and thereby looking like a spoofing attempt? If so, how to avoid?
@lkfng
@lkfng 4 жыл бұрын
Do you have any videos about configuring an ASA firewall for basic internet?
@NetworkDirection
@NetworkDirection 4 жыл бұрын
I have some, but not a lot. Check out: kzbin.info/www/bejne/nXfUq42jZpJ-fpo kzbin.info/www/bejne/iF7EpqOkr7SqirM
@studioxxswe
@studioxxswe 4 жыл бұрын
2 bad this wont help when your outside is not static, instead its dhcp
@musalyh
@musalyh 2 жыл бұрын
Subtitle please
@skolarii
@skolarii 4 жыл бұрын
The only recommendation I'd have mate is to not speed up your config video so much. Let us see what you're typing. You know your objects, we dont
Firepower Threat Defense Hidden CLI
1:35
Network Direction
Рет қаралды 18 М.
Configuring Access Control Lists (ACL) | Cisco ASA Firewalls
28:23
Network Direction
Рет қаралды 55 М.
Indian sharing by Secret Vlog #shorts
00:13
Secret Vlog
Рет қаралды 53 МЛН
КАК СПРЯТАТЬ КОНФЕТЫ
00:59
123 GO! Shorts Russian
Рет қаралды 2,9 МЛН
КАРМАНЧИК 2 СЕЗОН 5 СЕРИЯ
27:21
Inter Production
Рет қаралды 584 М.
NAT Explained | Overload, Dynamic & Static
8:45
CertBros
Рет қаралды 300 М.
Static NAT - Network Address Translation
7:24
Practical Networking
Рет қаралды 30 М.
NAT basics for beginners CCNA - Part 1
13:35
danscourses
Рет қаралды 372 М.
NAT vs PAT, Static vs Dynamic -- demystified! -- Network Address Translation
7:07
Security - Configuring ASA Site to Site VPN with NAT Exemption
27:36
Rob Riker's Tech Channel
Рет қаралды 9 М.
NAT - SNAT, DNAT, PAT & Port Forwarding
9:50
Sunny Classroom
Рет қаралды 346 М.
Traceroute (tracert) Explained - Network Troubleshooting
9:24
PowerCert Animated Videos
Рет қаралды 522 М.
Pratik Cat6 kablo soyma
0:15
Elektrik-Elektronik
Рет қаралды 8 МЛН
Apple watch hidden camera
0:34
_vector_
Рет қаралды 51 МЛН
Обзор игрового компьютера Макса 2в1
23:34