Cisco ASA Dynamic NAT with DMZ

Hi Asi,

I understand that this might be confusing. It’s best to let the idea of “traffic is initiated” go :slight_smile: The way you should read this is that all traffic from source IP 192.168.3.1 using source TCP 80 has to be translated to source IP 192.168.2.254 with source TCP 80.

It doesn’t matter if the traffic was originated from outside > inside or inside > outside. If it matches this IP/port then we translate, that’s it.

Rene