Configuring Nat Or Pat - Cisco Catalyst 6500 Series Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Chapter 9
Configuring Network Address Translation

Configuring NAT or PAT

This section tells how to configure dynamic NAT or dynamic PAT. The configuration for dynamic NAT
and PAT are almost identical; for NAT you specify a range of global addresses, and for PAT you specify
a single address.
Figure 9-14
global address is dynamically assigned from a pool.
Figure 9-14 Dynamic NAT
Figure 9-15
global address is the same for each translation, but the port is dynamically assigned.
Figure 9-15 Dynamic PAT
10.1.1.1:1025
10.1.1.1:1026
10.1.1.2:1025
For more information about dynamic NAT, see the
information about PAT, see the
If you change the NAT configuration, and you do not want to wait for existing translations to time out
Note
before the new NAT information is used, you can clear the translation table using the clear xlate
command. However, clearing the translation table disconnects all current connections.
To configure dynamic NAT or PAT, follow these steps:
To identify the local addresses that you want to translate, enter one of the following commands:
Step 1
OL-6392-01
shows a typical dynamic NAT scenario. Only local traffic can originate connections, and the
FWSM
10.1.1.1
209.165.201.1
10.1.1.2
209.165.201.2
Inside
Outside
shows a typical dynamic PAT scenario. Only local traffic can originate connections, the
FWSM
209.165.201.1:2020
209.165.201.1:2021
209.165.201.1:2022
Inside
Outside
Policy NAT:
FWSM/contexta(config)# nat ( local_interface ) nat_id access-list acl_name [dns]
[outside | [norandomseq] [[tcp] tcp_max_conns [ emb_limit ]] [udp udp_max_conns ]]
You can identify overlapping addresses in other nat statements. For example, you can identify
10.1.1.0 in one statement, but 10.1.1.1 in another. The traffic is matched to a policy NAT statement
in order, until the first match, or for regular NAT, using the best match.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
"Dynamic NAT" section on page
"PAT" section on page
9-4.
Using Dynamic NAT and PAT
9-3. For more
9-23

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents