實驗目的:
驗證ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序。
拓撲:

一 8.3以前
配置:
access-list acl-outside extended permit tcp any host 202.1.1.10 eq telnet
access-list acl-outside extended permit icmp any any
nat-control
static (inside,outside) 202.1.1.10 192.168.1.1 netmask 255.255.255.255
access-group acl-outside in interface outside
使用的是轉化以後的IP(202.1.1.10)
驗證:
二 8.3以後
配置
access-list acl-outside extended permit tcp any host 192.168.1.1 eq telnet
object network Static-Outside-Address
host 202.1.1.10
object network Static-Inside-Address
host 192.168.1.1
nat (Inside,Outside) static Static-Outside-Address
驗證