Cisco ASA Dynamic NAT with DMZ

Hello Bruno

The object network PUBLIC_POOL command is used to define the range of outside IP addresses to be used for NAT. This doesn’t have to be the actual physical address on the outside interface, and actually must be a range of addresses since we are configuring dynamic NAT. Actually, the IP addresses specified here don’t even have to be in the same subnet as the address of the outside interface, as long as there is routing to the configured outside NAT interfaces to reach them.

I’m not sure I understand the syntax of the commands here, but I do understand the error that states that the address overlaps with the outside interface address. It seems that you have another NAT rule (without the object NAT configuration) somewhere that already uses the outside interface address and that is why you have a conflict. A similar such situation can be found at the following Cisco community forum that might help you in your troubleshooting:

In any case, if you would like to duplicate the lesson, follow the configurations and explanations there and let us know your results.

I hope this has been helpful!

Laz