Professional Documents
Culture Documents
http://hocmang.net/2014/09/07/cau-hinh-nat-tren-cisco-asa/
K t software version 8.3, NAT c thit k li hon ton nhm mc ch n gin v d dng
hn trong vic to ra cc translation rules, chuyn i ng thi c a ch source v destination IP.
Ngoi ra, kh nng ty chnh th t x l cc lnh NAT cng l mt tnh nng ni bt trong m hnh
NAT mi. C 2 NAT mode l:
Trong software version 8.3 tr v sau th ASA s dng mt bng NAT thng nht (unified NAT table).
Bng NAT ny c chia lm 3 section, v cc translation rules s c x l theo th t t trn
xung, nu gi tin tha dng no th s c NAT da theo translation rule . Network Object NAT
lun c t section 2, cn Twice NAT mc nh c t section 1.
Ta xt m hnh sau:
Trong m hnh trn, cu hnh cho cc host thuc mng inside (192.168.2.0/24) c th truy cp
Internet th ta s thc hin nh sau:
Sau khi cho PC1 truy cp mt s trang web (traffic ny mc nh c implicit rules cho php, v i
t cng inside c security level = 100 n cng outside2 c security level = 0), ta kim tra bng NAT
ca ASA bng lnh show xlate:
Trong cu hnh trn, s 80 u tin l port m SERVER1 ang lng nghe, cn s 80 th hai l port
m ta mun cc host bn ngoi s dng truy cp n dch v HTTP ca SERVER1.
Khc vi Auto NAT, Manual NAT c s dng chuyn i c source v destination IP ca gi tin
(mc d vy, Manual NAT cng c th dng ch chuyn i source IP). Gi s ta c yu cu khi
host 192.168.2.5 (thuc cng inside) truy cp n host 192.168.4.99 (thuc cng outside2), th ASA
s chuyn i source IP thnh 192.168.0.250 v destination IP thnh 8.8.8.8. Ta thc hin nh sau:
Nu mun Manual NAT nm sau Auto NAT trong bng NAT th ta thm t kha after-auto vo
lnh nat:
Ngoi ra, khi cu hnh Manual NAT th ta c th dng thm t kha unidirectional cui lnhnat.
Mc ch ca t kha ny l ngn chn a ch destination khi to traffic n a ch source.
Ch :
Khi ASA nhn c traffic vi destination l a ch mapped th n s untranslate a ch da theo
NAT rule v gi gi tin n a ch tht. ASA xc nh cng ra (egress interface) cho gi tin da theo
cc cch sau:
1) transparent mode, ASA xc nh cng ra cho a ch tht bng cch s dng NAT rule, do ta
phi ch nh c source v destination interface trong NAT rule.
2) routed mode, ASA xc nh cng ra da theo cc cch sau:
kha route-lookup vo cui lnh nat buc ASA s dng routing table.
Nu ta khng ch nh r interface (m l any) trong NAT rule th ASA s s dng routing
table xc nh cng ra.
Xem thm:
Cisco ASA All-in-One Next-Generation Firewall, IPS, and VPN Services by Jazib Frahim,
Omar Santos & Andrew Ossipov
Cisco Firewalls by Alexandre de Moraes
Understanding When A Cisco ASA NAT Rule Can Override The ASA Routing Table
Configuring Twice NAT