CISCO ASA: How to NAT in both directions?

Hi all,

I am not able to figure out the best method to NAT because there are so many options…
In ASDM > When do I use “add object wth NAT option” and when do I use “add NAT rule”

for example:
I would like to set up an FTP server (DMZ) and give it its own IP on the OUTSIDE + The FTP server needs to see the IP of the FW (and not original source)

thanks in advance,

PS: Which tool do you use to create the topology picture?

testing done.
Please remove my post.

Hello Steven.

From my understanding, you have answered your question. It would be great if you could share your finding on the forum.

I look forward to hearing your solutions.


I have asked this question at my official asa course.
“there is no difference and has the same result, only a different way to set it up”

And NAT seems to be automatically in both directions :s
The FW started listening on the IP and arp replying.


1 Like