NAT: Auto NAT, Manual NAT & Twice NAT

Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)

مقصدObjectiveObjective

Inside users کے لیے dynamic PAT (Auto NAT)، DMZ server کے لیے static NAT (Manual NAT)، اور VPN traffic کے لیے twice-NAT identity exemption کنفیگر کریں۔Inside users ke liye dynamic PAT (Auto NAT), DMZ server ke liye static NAT (Manual NAT), aur VPN traffic ke liye twice-NAT identity exemption configure karo.Configure dynamic PAT for inside users (Auto NAT), static NAT for a DMZ server (Manual NAT), and a twice-NAT identity exemption for VPN traffic.

آسان مثالSimple AnalogySimple Analogy

NAT کمپنی کے reception desk جیسا ہے: internal extensions (private IPs) main switchboard number (public IP) سے باہر call کرتے ہیں، اور published number پر آنے والی calls صحیح desk تک route ہوتی ہیں (server تک static NAT)۔NAT company ke reception desk jaisa hai: internal extensions (private IPs) main switchboard number (public IP) se bahar call karte hain, aur published number par ane wali calls sahi desk tak route hoti hain (server tak static NAT).NAT is like a company's reception desk: internal extensions (private IPs) call out through the main switchboard number (public IP), and incoming calls to a published number get routed to the right desk (static NAT to a server).

سیٹ اپLab SetupLab Setup

asa-03 والا ASAv: inside 10.1.1.0/24، dmz 172.16.1.0/24 (web server 172.16.1.10)، outside 203.0.113.2/24۔ Public IP 203.0.113.10 DMZ web server کے لیے reserved ہے۔asa-03 wala ASAv: inside 10.1.1.0/24, dmz 172.16.1.0/24 (web server 172.16.1.10), outside 203.0.113.2/24. Public IP 203.0.113.10 DMZ web server ke liye reserved hai.ASAv from asa-03: inside 10.1.1.0/24, dmz 172.16.1.0/24 (web server 172.16.1.10), outside 203.0.113.2/24. Public IP 203.0.113.10 is reserved for the DMZ web server.

اقداماتStepsSteps

Step 1

Auto NAT: inside network object پر dynamic PAT rule لگائیں تاکہ internet جانے پر سارے inside hosts outside interface IP share کریں۔Auto NAT: inside network object par dynamic PAT rule lagao taake internet jane par sare inside hosts outside interface IP share karen.Auto NAT: attach a dynamic PAT rule to the inside network object so all inside hosts share the outside interface IP when going to the internet.

object network INSIDE_NET
subnet 10.1.1.0 255.255.255.0
nat (inside,outside) dynamic interface
exit

Step 2

Auto NAT static: DMZ web server کے private IP کو public 203.0.113.10 سے map کریں دونوں directions میں (one-to-one)۔Auto NAT static: DMZ web server ke private IP ko public 203.0.113.10 se map karo dono directions mein (one-to-one).Auto NAT static: map the DMZ web server's private IP to public 203.0.113.10 in both directions (one-to-one).

object network DMZ_WEB
host 172.16.1.10
nat (dmz,outside) static 203.0.113.10
exit

Step 3

Twice NAT identity exemption: جب inside traffic VPN pool کی طرف جائے تو source اور destination کو خود سے translate کریں — مطلب VPN traffic پر NAT مت کریں۔Twice NAT identity exemption: jab inside traffic VPN pool ki taraf jaye to source aur destination ko khud se translate karo — matlab VPN traffic par NAT mat karo.Twice NAT identity exemption: when inside traffic is destined for the VPN pool, translate source and destination to themselves — i.e. do not NAT VPN traffic.

object network VPN_POOL
subnet 192.168.200.0 255.255.255.0
exit
nat (inside,outside) source static INSIDE_NET INSIDE_NET destination static VPN_POOL VPN_POOL no-proxy-arp

Step 4

NAT table اور live translations verify کریں۔ `show nat` rules کو processing order میں list کرتا ہے؛ `show xlate` active translations دکھاتا ہے۔NAT table aur live translations verify karo. `show nat` rules ko processing order mein list karta hai; `show xlate` active translations dikhata hai.Verify the NAT table and live translations. `show nat` lists the rules in processing order; `show xlate` shows active translations.

show nat
show xlate

🖱️ ASDM: Configuration > Firewall > NAT Rules — Auto NAT objects کے نیچے، Manual/Twice NAT NAT table میں نظر آتا ہے۔ASDM: Configuration > Firewall > NAT Rules — Auto NAT objects ke neeche, Manual/Twice NAT NAT table mein nazar aata hai.ASDM: Configuration > Firewall > NAT Rules — Auto NAT appears under objects, Manual/Twice NAT in the NAT table.

Step 5

Configuration save کریں۔Configuration save karo.Save the configuration.

write memory

تصدیقVerifyVerify

`show nat` میں PAT، static اور exemption rules order میں list ہوں؛ `show xlate` میں inside hosts outside IP پر translated نظر آئیں، اور DMZ server 203.0.113.10 پر جواب دے۔`show nat` mein PAT, static aur exemption rules order mein list hon; `show xlate` mein inside hosts outside IP par translated nazar aain, aur DMZ server 203.0.113.10 par jawab de.`show nat` lists the PAT, static, and exemption rules in order; `show xlate` shows inside hosts translated to the outside IP, and the DMZ server answers on 203.0.113.10.

show nat
show xlate

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Inside users outside gateway کو ping کر سکتے ہیں لیکن internet پر کچھ نہیں۔Inside users outside gateway ko ping kar sakte hain lekin internet par kuch nahi.Inside users can ping the outside gateway but nothing on the internet.

✅ `show nat` چیک کریں — اگر dynamic PAT rule missing ہے یا interfaces الٹے ہیں (inside,outside)، تو translations کبھی نہیں بنیں گی۔ Ping کے دوران `show xlate` سے confirm کریں۔`show nat` check karo — agar dynamic PAT rule missing hai ya interfaces ulte hain (inside,outside), to translations kabhi nahi banengi. Ping ke doran `show xlate` se confirm karo.Check `show nat` — if the dynamic PAT rule is missing or the interfaces are swapped (inside,outside), translations never form. Confirm with `show xlate` during a ping.

⚠️ DMZ web server اپنے public IP 203.0.113.10 پر reachable نہیں ہے۔DMZ web server apne public IP 203.0.113.10 par reachable nahi hai.The DMZ web server is not reachable on its public IP 203.0.113.10.

✅ Static NAT rule verify کریں (`show nat`) اور یاد رکھیں کہ outside پر 203.0.113.10 تک 80/443 permit کرنے والی ACL بھی چاہیے (asa-03)۔ Public address پر IP conflict بھی check کریں۔Static NAT rule verify karo (`show nat`) aur yaad rakho ke outside par 203.0.113.10 tak 80/443 permit karne wali ACL bhi chahiye (asa-03). Public address par IP conflict bhi check karo.Verify the static NAT rule (`show nat`) and remember you still need an ACL on outside permitting 80/443 to 203.0.113.10 (asa-03). Also check for an IP conflict on the public address.

⚠️ Site-to-site VPN traffic NAT ہو رہا ہے اور tunnel fail ہو رہا ہے۔Site-to-site VPN traffic NAT ho raha hai aur tunnel fail ho raha hai.Site-to-site VPN traffic is being NATed and the tunnel fails.

✅ VPN interesting traffic کے لیے NAT exemption / identity twice-NAT add کریں (یا verify کریں) جو dynamic PAT rule سے پہلے ہو۔ پھر `clear xlate` کریں تاکہ پرانی translations ختم ہوں۔VPN interesting traffic ke liye NAT exemption / identity twice-NAT add karo (ya verify karo) jo dynamic PAT rule se pehle ho. Phir `clear xlate` karo taake purani translations khatam hon.Add (or verify) a NAT exemption / identity twice-NAT for the VPN interesting traffic placed before the dynamic PAT rule. Then `clear xlate` so stale translations drop.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Auto NAT، Manual NAT اور Twice NAT میں کیا فرق ہے؟Auto NAT, Manual NAT aur Twice NAT mein kya farq hai?What is the difference between Auto NAT, Manual NAT, and Twice NAT?

Auto NAT network object پر ہی configured ہوتا ہے اور پڑھنا آسان ہے؛ manual NAT dedicated NAT table section میں لکھا جاتا ہے، top-down process ہوتا ہے، اور complex scenarios کے لیے چاہیے۔ Twice NAT ایک ہی rule میں source اور destination translation configure کرتا ہے۔Auto NAT network object par hi configured hota hai aur parhna asaan hai; manual NAT dedicated NAT table section mein likha jata hai, top-down process hota hai, aur complex scenarios ke liye chahiye. Twice NAT ek hi rule mein source aur destination translation configure karta hai.Auto NAT is configured on the network object itself and is easy to read; manual NAT is written in a dedicated NAT table section, processed top-down, and needed for complex scenarios. Twice NAT configures source and destination translation in a single rule.

❓ ASA پر VPN traffic کو NAT سے translate ہونے سے کیسے روکتے ہیں؟ASA par VPN traffic ko NAT se translate hone se kaise rokte hain?How do you stop NAT from translating VPN traffic on the ASA?

ہاں — ASA NAT exemption support کرتا ہے (nat 0 / identity NAT) تاکہ VPN traffic اپنے original addresses رکھے اور translate نہ ہو۔ Exempt rules regular NAT rules سے پہلے رکھے جاتے ہیں۔Haan — ASA NAT exemption support karta hai (nat 0 / identity NAT) taake VPN traffic apne original addresses rakhe aur translate na ho. Exempt rules regular NAT rules se pehle rakhe jate hain.Yes — ASA supports NAT exemption (nat 0 / identity NAT) so VPN traffic keeps its original addresses and isn't translated. Exempt rules are placed before regular NAT rules.