SlideShare a Scribd company logo
NAT IN ASA FIREWALL
WWW.NETPROTOCOLXPERT.IN
WHAT IS THE COMMAND TO SWITCH BACK TO SINGLE MODE?
• # MODE SINGLE
WHAT ARE DIFFERENT TYPES OF NAT IN ASA?
• STATIC NAT - A CONSISTENT MAPPING BETWEEN A REAL AND MAPPED IP
ADDRESS. IT ALLOWS BIDIRECTIONAL TRAFFIC INITIATION.
• DYNAMIC NAT - A GROUP OF REAL IP ADDRESSES ARE MAPPED TO A (USUALLY
SMALLER) GROUP OF MAPPED IP ADDRESSES ON A FIRST COME FIRST SERVED
BASIS. IT ALLOWS ONLY UNIDIRECTIONAL TRAFFIC INITIATION.
• DYNAMIC PORT ADDRESS TRANSLATION (PAT) - A GROUP OF REAL IP
ADDRESSES ARE MAPPED TO A SINGLE IP ADDRESS USING A UNIQUE SOURCE
PORT OF THAT IP ADDRESS.
• IDENTITY NAT - A REAL ADDRESS IS STATICALLY TRANSLATED TO ITSELF,
ESSENTIALLY BYPASSING NAT.
WHAT IS POLICY NAT?
• POLICY NAT ALLOWS YOU TO NAT BY SPECIFYING BOTH THE SOURCE AND
DESTINATION ADDRESSES IN AN EXTENDED ACCESS LIST. WE CAN ALSO
OPTIONALLY SPECIFY THE SOURCE AND DESTINATION PORTS. REGULAR NAT
CAN ONLY CONSIDER THE SOURCE ADDRESSES, NOT THE DESTINATION
ADDRESS .
• IN STATIC NAT IT IS CALLED AS STATIC POLICY NAT.
• IN DYNAMIC NAT IT IS CALLED AS DYNAMIC POLICY NAT.
GIVE THE ORDER OF PREFERENCE BETWEEN DIFFERENT TYPES OF
NAT?
1.NAT EXEMPTION.
2.EXISTING TRANSLATION IN XLATE.
3.STATIC NAT
• STATIC IDENTITY NAT
• STATIC POLICY NAT
• STATIC NAT
• STATIC PAT
4.DYNAMIC NAT
• NAT ZERO
• DYNAMIC POLICY NAT
• DYNAMIC NAT
• DYNAMIC PAT
WHAT IS THE DIFFERENCE BETWEEN AUTO NAT & MANUAL NAT?
• AUTO NAT (NETWORK OBJECT NAT) - IT ONLY CONSIDERS THE SOURCE
ADDRESS WHILE PERFORMING NAT. SO, AUTO NAT IS ONLY USED FOR STATIC
OR DYNAMIC NAT. AUTO NAT IS CONFIGURED WITHIN AN OBJECT.
• MANUAL NAT (TWICE NAT) - MANUAL NAT CONSIDERS EITHER ONLY THE
SOURCE ADDRESS OR THE SOURCE AND DESTINATION ADDRESS WHILE
PERFORMING NAT. IT CAN BE USED FOR ALMOST ALL TYPES OF NAT LIKE NAT
EXEMPT, POLICY NAT ETC.
UNLIKE AUTO NAT THAT IS CONFIGURED WITHIN AN OBJECT, MANUAL NAT IS
CONFIGURED DIRECTLY FROM THE GLOBAL CONFIGURATION MODE.
• GIVE NAT ORDER IN TERMS OF AUTO NAT & MANUAL NAT?
• NAT IS ORDERED IN 3 SECTIONS.
SECTION 1 – MANUAL NAT
SECTION 2 – AUTO NAT
SECTION 3 – MANUAL NAT AFTER-AUTO
WHAT ARE THE COMMAND TO SEE NAT TRANSLATIONS?
• # SH XLATE
• # SH NAT
WHAT IS THE COMMAND TO SEE BOTH NAT TABLE AND CONNECTION TABLE?
• # SH LOCAL-HOST

More Related Content

What's hot

CCNA Advanced Routing Protocols
CCNA Advanced Routing ProtocolsCCNA Advanced Routing Protocols
CCNA Advanced Routing Protocols
Dsunte Wilson
 

What's hot (20)

20 palo alto site to site
20 palo alto site to site20 palo alto site to site
20 palo alto site to site
 
17 palo alto threat prevention concept
17 palo alto threat prevention concept17 palo alto threat prevention concept
17 palo alto threat prevention concept
 
CCNA Advanced Routing Protocols
CCNA Advanced Routing ProtocolsCCNA Advanced Routing Protocols
CCNA Advanced Routing Protocols
 
Multiprotocol label switching (mpls) - Networkshop44
Multiprotocol label switching (mpls)  - Networkshop44Multiprotocol label switching (mpls)  - Networkshop44
Multiprotocol label switching (mpls) - Networkshop44
 
Basics of firewall, ebtables, arptables and iptables
Basics of firewall, ebtables, arptables and iptablesBasics of firewall, ebtables, arptables and iptables
Basics of firewall, ebtables, arptables and iptables
 
Vlan
Vlan Vlan
Vlan
 
Ether channel fundamentals
Ether channel fundamentalsEther channel fundamentals
Ether channel fundamentals
 
11 palo alto user-id concepts
11 palo alto user-id concepts11 palo alto user-id concepts
11 palo alto user-id concepts
 
Multiprotocol label switching
Multiprotocol label switchingMultiprotocol label switching
Multiprotocol label switching
 
01- intro to firewall concepts
01- intro to firewall concepts01- intro to firewall concepts
01- intro to firewall concepts
 
Class notes fhrp,hsrp,vrrp
Class notes fhrp,hsrp,vrrpClass notes fhrp,hsrp,vrrp
Class notes fhrp,hsrp,vrrp
 
Asa sslvpn security
Asa sslvpn securityAsa sslvpn security
Asa sslvpn security
 
Basic ASA Configuration, NAT in ASA Firewall
Basic ASA Configuration,NAT in ASA FirewallBasic ASA Configuration,NAT in ASA Firewall
Basic ASA Configuration, NAT in ASA Firewall
 
iSCSI Protocol and Functionality
iSCSI Protocol and FunctionalityiSCSI Protocol and Functionality
iSCSI Protocol and Functionality
 
Nat
NatNat
Nat
 
03 ospf
03 ospf 03 ospf
03 ospf
 
Bgp tutorial for ISP
Bgp tutorial for ISPBgp tutorial for ISP
Bgp tutorial for ISP
 
Nxll26 bgp ii
Nxll26 bgp iiNxll26 bgp ii
Nxll26 bgp ii
 
Configuring RIPv2
Configuring RIPv2Configuring RIPv2
Configuring RIPv2
 
VLAN
VLANVLAN
VLAN
 

Viewers also liked

ASA Multiple Context Training
ASA Multiple Context TrainingASA Multiple Context Training
ASA Multiple Context Training
Tariq Bader
 
Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01
Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01
Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01
Duane Bodle
 
Cisco asa cx firwewall
Cisco asa cx firwewallCisco asa cx firwewall
Cisco asa cx firwewall
Anwesh Dixit
 

Viewers also liked (20)

Understanding and Troubleshooting ASA NAT
Understanding and Troubleshooting ASA NATUnderstanding and Troubleshooting ASA NAT
Understanding and Troubleshooting ASA NAT
 
ASA Multiple Context Training
ASA Multiple Context TrainingASA Multiple Context Training
ASA Multiple Context Training
 
Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01
Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01
Cisco ASA Firewall Interview Question "aka Stump-the-Chump" Question # 01
 
CCNP Security-Firewall
CCNP Security-FirewallCCNP Security-Firewall
CCNP Security-Firewall
 
ASA Firewall Interview- Questions & Answers
ASA Firewall Interview- Questions & AnswersASA Firewall Interview- Questions & Answers
ASA Firewall Interview- Questions & Answers
 
IPSec VPN
IPSec VPNIPSec VPN
IPSec VPN
 
Using packet-tracer, capture and other Cisco ASA tools for network troublesho...
Using packet-tracer, capture and other Cisco ASA tools for network troublesho...Using packet-tracer, capture and other Cisco ASA tools for network troublesho...
Using packet-tracer, capture and other Cisco ASA tools for network troublesho...
 
Cisco ASA Firewall Lab WorkBook
Cisco ASA Firewall Lab WorkBookCisco ASA Firewall Lab WorkBook
Cisco ASA Firewall Lab WorkBook
 
Troubleshooting Firewalls (2012 San Diego)
Troubleshooting Firewalls (2012 San Diego)Troubleshooting Firewalls (2012 San Diego)
Troubleshooting Firewalls (2012 San Diego)
 
CCNP Security-Secure
CCNP Security-SecureCCNP Security-Secure
CCNP Security-Secure
 
CCNP Security-IPS
CCNP Security-IPSCCNP Security-IPS
CCNP Security-IPS
 
Cisco asa cx firwewall
Cisco asa cx firwewallCisco asa cx firwewall
Cisco asa cx firwewall
 
Инфографика. Программы-вымогатели: реальное положение вещей
Инфографика. Программы-вымогатели: реальное положение вещейИнфографика. Программы-вымогатели: реальное положение вещей
Инфографика. Программы-вымогатели: реальное положение вещей
 
Par2 2 0901(1)
Par2 2 0901(1)Par2 2 0901(1)
Par2 2 0901(1)
 
Firewall y nat
Firewall y natFirewall y nat
Firewall y nat
 
CCNP Security-VPN
CCNP Security-VPNCCNP Security-VPN
CCNP Security-VPN
 
Firewall
FirewallFirewall
Firewall
 
Pengertian Firewall, NAT, dan Proxy Server
Pengertian Firewall, NAT, dan  Proxy ServerPengertian Firewall, NAT, dan  Proxy Server
Pengertian Firewall, NAT, dan Proxy Server
 
Cisco ASA Firewalls
Cisco ASA FirewallsCisco ASA Firewalls
Cisco ASA Firewalls
 
Nat pat
Nat patNat pat
Nat pat
 

Similar to NAT in ASA Firewall

AusNOG 2016 - The Trouble with NAT
AusNOG 2016 - The Trouble with NATAusNOG 2016 - The Trouble with NAT
AusNOG 2016 - The Trouble with NAT
Mark Smith
 
Understanding i pv6 2
Understanding i pv6 2Understanding i pv6 2
Understanding i pv6 2
srmanjuskp
 
Module (10) NAT for IPV4.pptx
Module (10) NAT for IPV4.pptxModule (10) NAT for IPV4.pptx
Module (10) NAT for IPV4.pptx
GeorgeThoreJr
 

Similar to NAT in ASA Firewall (20)

Nat cisco
Nat ciscoNat cisco
Nat cisco
 
CCNA (R & S) Module 03 - Routing & Switching Essentials - Chapter 9
CCNA (R & S) Module 03 - Routing & Switching Essentials - Chapter 9CCNA (R & S) Module 03 - Routing & Switching Essentials - Chapter 9
CCNA (R & S) Module 03 - Routing & Switching Essentials - Chapter 9
 
10 palo alto nat policy concepts
10 palo alto nat policy concepts10 palo alto nat policy concepts
10 palo alto nat policy concepts
 
NAT_Final
NAT_FinalNAT_Final
NAT_Final
 
Ccna rse chp9 nat fo i_pv4
Ccna rse chp9 nat fo i_pv4Ccna rse chp9 nat fo i_pv4
Ccna rse chp9 nat fo i_pv4
 
traffic sign detection using deep learning.pptx
traffic sign detection using deep learning.pptxtraffic sign detection using deep learning.pptx
traffic sign detection using deep learning.pptx
 
Day 17 nat and pat
Day 17 nat and patDay 17 nat and pat
Day 17 nat and pat
 
Router.pptx
Router.pptxRouter.pptx
Router.pptx
 
NAT Ccna
NAT CcnaNAT Ccna
NAT Ccna
 
Cyberscout Presentation
Cyberscout PresentationCyberscout Presentation
Cyberscout Presentation
 
Network addresses.pptx
Network addresses.pptxNetwork addresses.pptx
Network addresses.pptx
 
EIGRP Route Summarization
EIGRP Route SummarizationEIGRP Route Summarization
EIGRP Route Summarization
 
AusNOG 2016 - The Trouble with NAT
AusNOG 2016 - The Trouble with NATAusNOG 2016 - The Trouble with NAT
AusNOG 2016 - The Trouble with NAT
 
CCNA2 Verson6 Chapter9
CCNA2 Verson6 Chapter9CCNA2 Verson6 Chapter9
CCNA2 Verson6 Chapter9
 
Understanding i pv6 2
Understanding i pv6 2Understanding i pv6 2
Understanding i pv6 2
 
Module (10) NAT for IPV4.pptx
Module (10) NAT for IPV4.pptxModule (10) NAT for IPV4.pptx
Module (10) NAT for IPV4.pptx
 
IPv6 in Mobile Networks
IPv6 in Mobile NetworksIPv6 in Mobile Networks
IPv6 in Mobile Networks
 
Scylla Summit 2018: Consensus in Eventually Consistent Databases
Scylla Summit 2018: Consensus in Eventually Consistent DatabasesScylla Summit 2018: Consensus in Eventually Consistent Databases
Scylla Summit 2018: Consensus in Eventually Consistent Databases
 
what is Private and publis ip address
what is Private and publis ip addresswhat is Private and publis ip address
what is Private and publis ip address
 
Networking
NetworkingNetworking
Networking
 

More from NetProtocol Xpert

More from NetProtocol Xpert (20)

Basic Cisco ASA 5506-x Configuration (Firepower)
Basic Cisco ASA 5506-x Configuration (Firepower)Basic Cisco ASA 5506-x Configuration (Firepower)
Basic Cisco ASA 5506-x Configuration (Firepower)
 
MPLS Layer 3 VPN
MPLS Layer 3 VPN MPLS Layer 3 VPN
MPLS Layer 3 VPN
 
Common Layer 2 Threats, Attacks & Mitigation
Common Layer 2 Threats, Attacks & MitigationCommon Layer 2 Threats, Attacks & Mitigation
Common Layer 2 Threats, Attacks & Mitigation
 
Storm-Control
Storm-ControlStorm-Control
Storm-Control
 
Dynamic ARP Inspection (DAI)
Dynamic ARP Inspection (DAI)Dynamic ARP Inspection (DAI)
Dynamic ARP Inspection (DAI)
 
IP Source Guard
IP Source Guard IP Source Guard
IP Source Guard
 
DHCP Snooping
DHCP SnoopingDHCP Snooping
DHCP Snooping
 
Password Recovery
Password RecoveryPassword Recovery
Password Recovery
 
Application & Data Center
Application & Data CenterApplication & Data Center
Application & Data Center
 
Cisco ISR 4351 Router
Cisco ISR 4351 RouterCisco ISR 4351 Router
Cisco ISR 4351 Router
 
Cisco ASR 1001-X Router
Cisco ASR 1001-X RouterCisco ASR 1001-X Router
Cisco ASR 1001-X Router
 
Securing management, control & data plane
Securing management, control & data planeSecuring management, control & data plane
Securing management, control & data plane
 
Point to-point protocol (ppp), PAP & CHAP
Point to-point protocol (ppp), PAP & CHAPPoint to-point protocol (ppp), PAP & CHAP
Point to-point protocol (ppp), PAP & CHAP
 
Avoid DNS lookup when mistyping a command
Avoid DNS lookup when mistyping a commandAvoid DNS lookup when mistyping a command
Avoid DNS lookup when mistyping a command
 
TCLSH and Macro Ping Test on Cisco Routers and Switches
TCLSH and Macro Ping Test on Cisco Routers and SwitchesTCLSH and Macro Ping Test on Cisco Routers and Switches
TCLSH and Macro Ping Test on Cisco Routers and Switches
 
Private VLANs
Private VLANsPrivate VLANs
Private VLANs
 
MTU (maximum transmission unit) & MRU (maximum receive unit)
MTU (maximum transmission unit) & MRU (maximum receive unit)MTU (maximum transmission unit) & MRU (maximum receive unit)
MTU (maximum transmission unit) & MRU (maximum receive unit)
 
OTV Configuration
OTV ConfigurationOTV Configuration
OTV Configuration
 
Cisco OTV 
Cisco OTV Cisco OTV 
Cisco OTV 
 
OTV(Overlay Transport Virtualization)
OTV(Overlay  Transport  Virtualization)OTV(Overlay  Transport  Virtualization)
OTV(Overlay Transport Virtualization)
 

Recently uploaded

Hall booking system project report .pdf
Hall booking system project report  .pdfHall booking system project report  .pdf
Hall booking system project report .pdf
Kamal Acharya
 
Automobile Management System Project Report.pdf
Automobile Management System Project Report.pdfAutomobile Management System Project Report.pdf
Automobile Management System Project Report.pdf
Kamal Acharya
 
ONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdf
ONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdfONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdf
ONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdf
Kamal Acharya
 
Digital Signal Processing Lecture notes n.pdf
Digital Signal Processing Lecture notes n.pdfDigital Signal Processing Lecture notes n.pdf
Digital Signal Processing Lecture notes n.pdf
AbrahamGadissa
 

Recently uploaded (20)

Quality defects in TMT Bars, Possible causes and Potential Solutions.
Quality defects in TMT Bars, Possible causes and Potential Solutions.Quality defects in TMT Bars, Possible causes and Potential Solutions.
Quality defects in TMT Bars, Possible causes and Potential Solutions.
 
Pharmacy management system project report..pdf
Pharmacy management system project report..pdfPharmacy management system project report..pdf
Pharmacy management system project report..pdf
 
İTÜ CAD and Reverse Engineering Workshop
İTÜ CAD and Reverse Engineering WorkshopİTÜ CAD and Reverse Engineering Workshop
İTÜ CAD and Reverse Engineering Workshop
 
A case study of cinema management system project report..pdf
A case study of cinema management system project report..pdfA case study of cinema management system project report..pdf
A case study of cinema management system project report..pdf
 
Hall booking system project report .pdf
Hall booking system project report  .pdfHall booking system project report  .pdf
Hall booking system project report .pdf
 
RESORT MANAGEMENT AND RESERVATION SYSTEM PROJECT REPORT.pdf
RESORT MANAGEMENT AND RESERVATION SYSTEM PROJECT REPORT.pdfRESORT MANAGEMENT AND RESERVATION SYSTEM PROJECT REPORT.pdf
RESORT MANAGEMENT AND RESERVATION SYSTEM PROJECT REPORT.pdf
 
Cloud-Computing_CSE311_Computer-Networking CSE GUB BD - Shahidul.pptx
Cloud-Computing_CSE311_Computer-Networking CSE GUB BD - Shahidul.pptxCloud-Computing_CSE311_Computer-Networking CSE GUB BD - Shahidul.pptx
Cloud-Computing_CSE311_Computer-Networking CSE GUB BD - Shahidul.pptx
 
Automobile Management System Project Report.pdf
Automobile Management System Project Report.pdfAutomobile Management System Project Report.pdf
Automobile Management System Project Report.pdf
 
Explosives Industry manufacturing process.pdf
Explosives Industry manufacturing process.pdfExplosives Industry manufacturing process.pdf
Explosives Industry manufacturing process.pdf
 
Introduction to Machine Learning Unit-4 Notes for II-II Mechanical Engineering
Introduction to Machine Learning Unit-4 Notes for II-II Mechanical EngineeringIntroduction to Machine Learning Unit-4 Notes for II-II Mechanical Engineering
Introduction to Machine Learning Unit-4 Notes for II-II Mechanical Engineering
 
fundamentals of drawing and isometric and orthographic projection
fundamentals of drawing and isometric and orthographic projectionfundamentals of drawing and isometric and orthographic projection
fundamentals of drawing and isometric and orthographic projection
 
ONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdf
ONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdfONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdf
ONLINE VEHICLE RENTAL SYSTEM PROJECT REPORT.pdf
 
Democratizing Fuzzing at Scale by Abhishek Arya
Democratizing Fuzzing at Scale by Abhishek AryaDemocratizing Fuzzing at Scale by Abhishek Arya
Democratizing Fuzzing at Scale by Abhishek Arya
 
Digital Signal Processing Lecture notes n.pdf
Digital Signal Processing Lecture notes n.pdfDigital Signal Processing Lecture notes n.pdf
Digital Signal Processing Lecture notes n.pdf
 
Architectural Portfolio Sean Lockwood
Architectural Portfolio Sean LockwoodArchitectural Portfolio Sean Lockwood
Architectural Portfolio Sean Lockwood
 
Construction method of steel structure space frame .pptx
Construction method of steel structure space frame .pptxConstruction method of steel structure space frame .pptx
Construction method of steel structure space frame .pptx
 
KIT-601 Lecture Notes-UNIT-5.pdf Frame Works and Visualization
KIT-601 Lecture Notes-UNIT-5.pdf Frame Works and VisualizationKIT-601 Lecture Notes-UNIT-5.pdf Frame Works and Visualization
KIT-601 Lecture Notes-UNIT-5.pdf Frame Works and Visualization
 
Top 13 Famous Civil Engineering Scientist
Top 13 Famous Civil Engineering ScientistTop 13 Famous Civil Engineering Scientist
Top 13 Famous Civil Engineering Scientist
 
The Ultimate Guide to External Floating Roofs for Oil Storage Tanks.docx
The Ultimate Guide to External Floating Roofs for Oil Storage Tanks.docxThe Ultimate Guide to External Floating Roofs for Oil Storage Tanks.docx
The Ultimate Guide to External Floating Roofs for Oil Storage Tanks.docx
 
ENERGY STORAGE DEVICES INTRODUCTION UNIT-I
ENERGY STORAGE DEVICES  INTRODUCTION UNIT-IENERGY STORAGE DEVICES  INTRODUCTION UNIT-I
ENERGY STORAGE DEVICES INTRODUCTION UNIT-I
 

NAT in ASA Firewall

  • 1. NAT IN ASA FIREWALL WWW.NETPROTOCOLXPERT.IN
  • 2.
  • 3. WHAT IS THE COMMAND TO SWITCH BACK TO SINGLE MODE? • # MODE SINGLE WHAT ARE DIFFERENT TYPES OF NAT IN ASA? • STATIC NAT - A CONSISTENT MAPPING BETWEEN A REAL AND MAPPED IP ADDRESS. IT ALLOWS BIDIRECTIONAL TRAFFIC INITIATION. • DYNAMIC NAT - A GROUP OF REAL IP ADDRESSES ARE MAPPED TO A (USUALLY SMALLER) GROUP OF MAPPED IP ADDRESSES ON A FIRST COME FIRST SERVED BASIS. IT ALLOWS ONLY UNIDIRECTIONAL TRAFFIC INITIATION. • DYNAMIC PORT ADDRESS TRANSLATION (PAT) - A GROUP OF REAL IP ADDRESSES ARE MAPPED TO A SINGLE IP ADDRESS USING A UNIQUE SOURCE PORT OF THAT IP ADDRESS. • IDENTITY NAT - A REAL ADDRESS IS STATICALLY TRANSLATED TO ITSELF, ESSENTIALLY BYPASSING NAT.
  • 4. WHAT IS POLICY NAT? • POLICY NAT ALLOWS YOU TO NAT BY SPECIFYING BOTH THE SOURCE AND DESTINATION ADDRESSES IN AN EXTENDED ACCESS LIST. WE CAN ALSO OPTIONALLY SPECIFY THE SOURCE AND DESTINATION PORTS. REGULAR NAT CAN ONLY CONSIDER THE SOURCE ADDRESSES, NOT THE DESTINATION ADDRESS . • IN STATIC NAT IT IS CALLED AS STATIC POLICY NAT. • IN DYNAMIC NAT IT IS CALLED AS DYNAMIC POLICY NAT.
  • 5. GIVE THE ORDER OF PREFERENCE BETWEEN DIFFERENT TYPES OF NAT? 1.NAT EXEMPTION. 2.EXISTING TRANSLATION IN XLATE. 3.STATIC NAT • STATIC IDENTITY NAT • STATIC POLICY NAT • STATIC NAT • STATIC PAT 4.DYNAMIC NAT • NAT ZERO • DYNAMIC POLICY NAT • DYNAMIC NAT • DYNAMIC PAT
  • 6. WHAT IS THE DIFFERENCE BETWEEN AUTO NAT & MANUAL NAT? • AUTO NAT (NETWORK OBJECT NAT) - IT ONLY CONSIDERS THE SOURCE ADDRESS WHILE PERFORMING NAT. SO, AUTO NAT IS ONLY USED FOR STATIC OR DYNAMIC NAT. AUTO NAT IS CONFIGURED WITHIN AN OBJECT. • MANUAL NAT (TWICE NAT) - MANUAL NAT CONSIDERS EITHER ONLY THE SOURCE ADDRESS OR THE SOURCE AND DESTINATION ADDRESS WHILE PERFORMING NAT. IT CAN BE USED FOR ALMOST ALL TYPES OF NAT LIKE NAT EXEMPT, POLICY NAT ETC. UNLIKE AUTO NAT THAT IS CONFIGURED WITHIN AN OBJECT, MANUAL NAT IS CONFIGURED DIRECTLY FROM THE GLOBAL CONFIGURATION MODE.
  • 7. • GIVE NAT ORDER IN TERMS OF AUTO NAT & MANUAL NAT? • NAT IS ORDERED IN 3 SECTIONS. SECTION 1 – MANUAL NAT SECTION 2 – AUTO NAT SECTION 3 – MANUAL NAT AFTER-AUTO
  • 8. WHAT ARE THE COMMAND TO SEE NAT TRANSLATIONS? • # SH XLATE • # SH NAT WHAT IS THE COMMAND TO SEE BOTH NAT TABLE AND CONNECTION TABLE? • # SH LOCAL-HOST