A SERVICE OF

logo

35-7
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter 35 Configuring NAT (ASA 8.2 and Earlier)
NAT Overview
Figure 35-6 Remote Host Attempts to Connect to the Real Address
Figure 35-7 shows a remote host attempting to initiate a connection to a mapped address. This address
is not currently in the translation table; therefore, the ASA drops the packet.
Figure 35-7 Remote Host Attempts to Initiate a Connection to a Mapped Address
Note For the duration of the translation, a remote host can initiate a connection to the translated host if an
access list allows it. Because the address is unpredictable, a connection to the host is unlikely.
Nevertheless, in this case, you can rely on the security of the access list.
Web Server
www.example.com
Outside
Inside
209.165.201.2
10.1.2.1
10.1.2.27
Translation
209.165.201.1010.1.2.27
10.1.2.27
Security
Appliance
132216
Web Server
www.example.com
Outside
Inside
209.165.201.2
10.1.2.1
10.1.2.27
Security
Appliance
209.165.201.10
132217