artofrf.com

Ali's Technology Blog

Menu
  • Home
  • Important Links
  • About Me
  • Tools and Scripts
Menu

Cisco ASA Policy Based Static Source NAT

Posted on July 16, 2012December 16, 2019 by mali

Setting up VPN Connectivity between multiple locations is a pretty common task these days. It is a very simple and straight forward setup unless NAT comes into the play, there are multiple offices with overlapping subnets etc. Usually in that scenario solution is simple both sides will perform NAT and present their internal network as something else to the other location in the VPN Tunnel.

I had a unique situation. I was working on a firewall with multiple VPN’s and they pretty much all had a standard setup. There were couple of VPN’s that needed to be setup with a non standard setup because of the overlap in their network. This was the scenario:

  • Subnets on both sites were same i.e; 192.168.1.0/24
  • Site A had Cisco ASA and Site B had Cisco IOS Router
  • Site B was performing a NAT overload and presenting their internal subnet as another IP via the IPSec Tunnel
  • Site B needed to communicate with couple of hosts located at Site A (192.168.1.10 and 192.168.1.11)
  • Since 192.168.1.0/24 network was also being utilized at Site B, hosts at Site B couldn’t see those two hosts at Site A
  • What we needed was a to perform a static policy based source NAT on Cisco ASA so that hosts from Site B, instead of sending traffic to 192.168.1.10 and 192.168.1.11, they send traffic to other IP’s such as 1.1.1.1 and 2.2.2.2
  • Next issue was since there were multiple VPN’s on Cisco ASA and other remote sites were accessing those 192.168.1.11 and 192.168.1.10 hosts, I needed to setup NAT on my end in a way that it will only apply to this one site and not affect other VPN’s
  • Take a look at the picture below to get an idea and after that I will elaborate a bit more how I accomplished it

I’m not going to go deep into setting up the whole VPN on both ends because that is not the topic here. Basically on the Cisco Router at Site B, NAT Overload was utilized for the IPSec VPN and the whole internal network 192.168.1.0/24 was being NATed as 172.16.1.1 to the Cisco ASA at Site A. Now for the interesting traffic on both ends instead of 192.168.1.10 and 192.168.1.11 (1.1.1.1 and 2.2.2.2) was used.

Here are the Cisco ASA steps that I used to perform Policy Based Static Source NAT:

access-list POLICYNAT1 extended permit ip host 192.168.1.10 host 172.16.1.1
access-list POLICYNAT2 extended permit ip host 192.168.1.11 host 172.16.1.1
!
static (inside,outside) 1.1.1.1 access-list POLICYNAT1
static (inside,outside) 2.2.2.2 access-list POLICYNAT2

Don’t forget the crypto map on the Cisco ASA used the reverse of was setup on the Cisco IOS Router at Site B i.e; 1.1.1.1 to 172.16.1.1 and 2.2.2.2 to 172.16.1.1. So this basically allowed 192.168.1.10 and 192.168.1.11 to be translated into 1.1.1.1 and 2.2.2.2 every time source was 192.168.1.10 or 192.168.1.11 and destination was 172.16.1.1 (ONLY). Similarly when the hosts from Site B communicated with 1.1.1.1 or 2.2.2.2 Cisco ASA translated those IP’s to 192.168.1.10 and 192.168.1.11 and then back to 1.1.1.1 and 2.2.2.2. Hope this will help out some one else out there 🙂

Note: This example is for pre 8.3 code. Please keep in mind that this is a reference point only. There are other configuration options available to tweak this according to your needs. Remember to always backup your work before you make any changes, always test configurations in the lab and never do anything that you can not undo 

Category: Cisco Security, Cisco VPN

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • CLI to UI – Nile Guest APIs
  • Nile Secure Guest – Configuration and Use Case
  • WLAN Pros Toolbox
  • Nile does NAC – Configuring Trust Engine
  • WLAN Validator

Tags

#MFD9 - Juniper Presents AP W318 arista Arista AGNI Arista CV-CUE Arista Hospitality AP Arista NAC Arista presents at MFD9 Arista wall plate AP Arista WIPS Arista WPA3 UPSK Aruba Central Automation CWAP 403 EAP Format MAC Addresses Hamina Network Planner Juniper Mist show cloud-native NAC Juniper SRX300 Marvis MFD8 MFD9 MistAI Mist MPSK Mist Premium Analytics Mist Wireless NaaS Networking Field Day NFD32 Nile APIs NileNav Nile Secure Nile Wi-Fi Tech Field Day Troubleshooting with Marvis Troubleshooting with Mist Troubleshooting with Mist AI Troubleshooting with Wireshark True NaaS Wireless Adjuster Wireless Adjuster Level II Wireless troubleshooting WLPC wlpc2023 Wyebot

Tech Blogs

  • CCNA Wireless
  • Cisco Full Bars
  • Packet Life
  • The ASCII Construct
  • Juniper Port Checker
  • Bad-Fi
  • Gjermund Raaen
  • Havilandweb
  • WiFiTodd
  • BadgerWiFi
  • WiFrizzy
  • Spectrum Chart

Recent Comments

  • Hiten Thakkar on PCAP I/O Graph Analyzer
  • mali on Deploying Nile Secure – My First NSB
  • Larry Farrish on Deploying Nile Secure – My First NSB
  • Courtney on Mist Access Point – CSV
  • ayoub chabrouk on Ubiquiti stealing the show at MFD11

Archives

  • August 2026
  • July 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • May 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • November 2018
  • October 2018
  • September 2018
  • May 2018
  • January 2018
  • December 2017
  • August 2017
  • January 2017
  • September 2014
  • December 2013
  • October 2013
  • May 2013
  • August 2012
  • July 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • AeroHive
  • Arista
  • Arista
  • Aruba
  • Aruba
  • Aruba Central
  • BYoD
  • Certifications
  • Cisco
  • Cisco
  • Cisco EEM Scripting
  • Cisco Routing
  • Cisco Security
  • Cisco VoIP
  • Cisco VPN
  • Cisco Wireless
  • Conferences and Meetings
  • Design
  • Ekahau
  • General
  • Hamina
  • IoT, IIoT, OT
  • Juniper Security
  • Juniper Switching
  • Juniper/Mist
  • Linux
  • Microsoft
  • Mist
  • Mist Wireless
  • Nile
  • Nile Secure
  • Nile Wi-Fi
  • Programming/Automation
  • Python
  • Ruckus
  • Ruckus Wireless
  • Ruckus/Brocade
  • Ruckus/Brocade Scripting
  • Ruckus/Brocade Switching
  • Secure Guest Service
  • Security
  • Switching
  • Tools
  • Troubleshooting
  • Trust Engine
  • Uncategorized
  • Windows
  • Wireless
  • Wireless
  • WLAN Tools
© 2026 artofrf.com | Powered by Minimalist Blog WordPress Theme