[c-nsp] Possible to make NAT decisions based on source address, on ASA?

Andy Dills andy at xecu.net
Thu May 17 14:36:08 EDT 2012


Hi there,

I'm looking to do something along the following, and while in my head it 
should be doable, I can't seem to find a mechanism to enable me to 
configure it:

I want users, accessing a public address on the ASA (let's call it 
5.5.5.5) from subnet A out on the "public" side, let's say from a specific 
remote office (20.0.0.0/24), to get NATed to private server 10.0.0.100, 
where everybody else gets NATed to 10.0.0.200.

So:

20.0.0.0/24 -> 5.5.5.5 gets NATed to 10.0.0.100
0.0.0.0/0 -> 5.5.5.5 gets NATed to 10.0.0.200

So, in essence, I want to consider source address when determining which 
server on the private network the traffic is NATed to.

Is this possible?

Thanks,
Andy

---
Andy Dills
Xecunet, Inc.
www.xecu.net
301-682-9972
---


More information about the cisco-nsp mailing list