<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Andre, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904628#M40035</link>
    <description>&lt;P&gt;Hi Andre,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes you are right LB-TEST9's IP should be 2.2.2.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_112 gr-alert gr_gramm undefined Punctuation multiReplace" id="112" data-gr-id="112"&gt;Also&lt;/G&gt; for WWW &lt;G class="gr_ gr_113 gr-alert gr_gramm undefined Punctuation only-ins replaceWithoutSep" id="113" data-gr-id="113"&gt;service&lt;/G&gt; LB-TEST2 IP should be 1.1.1.2 and not 4.4.4.4&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2016 10:38:22 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2016-03-10T10:38:22Z</dc:date>
    <item>
      <title>Issue with Dynamic and Static Nat</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904627#M40034</link>
      <description>&lt;P&gt;I have the following configuration&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have about 50 internal hosts that have static nats assigned with their respective services defined in the nat statement which I need to remove as I need to use dns-doctoring.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is the config:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;object network LB-TEST1&lt;BR /&gt; host 10.0.0.51&lt;/P&gt;
&lt;P&gt;object network LB-TEST2&lt;BR /&gt; host 10.0.0.52&lt;/P&gt;
&lt;P&gt;object network LB-TEST9&lt;BR /&gt; host 10.0.0.59&lt;/P&gt;
&lt;P&gt;object network LB-TEST1&lt;BR /&gt; nat (any,Wan) static 1.1.1.1&lt;/P&gt;
&lt;P&gt;object network LB-TEST2-HTTP&lt;BR /&gt; nat (any,Wan) static 1.1.1.2 service tcp www www&lt;/P&gt;
&lt;P&gt;object network LB-TEST9&lt;BR /&gt; nat (any,Wan) static 2.2.2.2&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;nat (Lan,Wan) after-auto source dynamic any interface description Allow Internet Access to the Lan Network&lt;BR /&gt;WAN IP: 4.4.4.4&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;LB-TEST1 public ip 1.1.1.1&lt;BR /&gt;LB-TEST2 public ip 4.4.4.4&lt;BR /&gt;LB-TEST9 public ip 4.4.4.4&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I can understand LB-TEST1 and LB-TEST2 but in this case shouldn't LB-TEST9's public ip be 2.2.2.2 ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:33:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904627#M40034</guid>
      <dc:creator>andremagri</dc:creator>
      <dc:date>2019-03-11T06:33:56Z</dc:date>
    </item>
    <item>
      <title>Hi Andre,</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904628#M40035</link>
      <description>&lt;P&gt;Hi Andre,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes you are right LB-TEST9's IP should be 2.2.2.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_112 gr-alert gr_gramm undefined Punctuation multiReplace" id="112" data-gr-id="112"&gt;Also&lt;/G&gt; for WWW &lt;G class="gr_ gr_113 gr-alert gr_gramm undefined Punctuation only-ins replaceWithoutSep" id="113" data-gr-id="113"&gt;service&lt;/G&gt; LB-TEST2 IP should be 1.1.1.2 and not 4.4.4.4&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 10:38:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904628#M40035</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-10T10:38:22Z</dc:date>
    </item>
    <item>
      <title>@Aditya Ganjoo  I'm testing</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904629#M40036</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/adganjoo"&gt;adganjoo&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; I'm testing using whatsmyip.org so since the source port is dynamic in this case LB-TEST2 is returning 4.4.4.4 but replies from source port 80 should be translated to 1.1.1.2 as you said.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How do I make LB-TEST1 translate to 4.4.4.4 like the rest so that I can use the dns keyword?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 10:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904629#M40036</guid>
      <dc:creator>andremagri</dc:creator>
      <dc:date>2016-03-10T10:45:47Z</dc:date>
    </item>
    <item>
      <title>Hi Andre,</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904630#M40037</link>
      <description>&lt;P&gt;Hi Andre,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No the NAT statement for WWW is for the port 80 service.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network LB-TEST2-HTTP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;G class="gr_ gr_84 gr-alert gr_spell undefined ContextualSpelling" id="84" data-gr-id="84"&gt;nat&lt;/G&gt; &lt;G class="gr_ gr_100 gr-alert gr_gramm undefined Punctuation replaceWithoutSep" id="100" data-gr-id="100"&gt;(any,Wan)&lt;/G&gt; static 1.1.1.2 service &lt;G class="gr_ gr_83 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="83" data-gr-id="83"&gt;tcp&lt;/G&gt; &lt;G class="gr_ gr_99 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="99" data-gr-id="99"&gt;www www&lt;/G&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you check what is LB-TEST2-HTTP object &lt;G class="gr_ gr_154 gr-alert gr_gramm undefined Punctuation multiReplace" id="154" data-gr-id="154"&gt;is ?&lt;/G&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Use the command sh run object id&amp;nbsp;LB-TEST2-HTTP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;So &lt;G class="gr_ gr_230 gr-alert gr_spell undefined ContextualSpelling" id="230" data-gr-id="230"&gt;lets&lt;/G&gt; say if &lt;G class="gr_ gr_229 gr-alert gr_tiny gr_spell undefined ContextualSpelling multiReplace" id="229" data-gr-id="229"&gt;i&lt;/G&gt; need to access the web services on any of the internal server I would use the NAT IP on port 80.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 10:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904630#M40037</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-10T10:54:08Z</dc:date>
    </item>
    <item>
      <title>made a mistake earlier, I</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904631#M40038</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;made a mistake earlier, I should have included this one:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network LB-TEST2-TEST&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 10.0.0.52&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I found out what happened though in the meantime, the host LB-TEST9 has 2 ip addresses and the primary interface is set to another nat statement. &amp;nbsp;This explains why the public ip is different.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;So what I would like to do is taking into consideration these 2 nats:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network LB-TEST2-HTTP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nat (any,Wan) static 1.1.1.2 service tcp www www&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network LB-TEST3-HTTP&lt;BR /&gt;&lt;SPAN&gt;nat (any,Wan) static 1.1.1.3 service tcp www www&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;From LB-TEST2 or any other internal host I would like to access each other through HTTP using the internal ip instead of the outside one.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 12:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-dynamic-and-static-nat/m-p/2904631#M40038</guid>
      <dc:creator>andremagri</dc:creator>
      <dc:date>2016-03-10T12:54:44Z</dc:date>
    </item>
  </channel>
</rss>

