<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static for inbound connection to any network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-for-inbound-connection-to-any-network/m-p/804906#M1000536</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could use a nat exemption which is bi-directional although it would need testing against any other translations you have on the firewall ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit ip any any &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way are you the Paul Thomsett that did work for Network Rail. If so, how are you ?. Hope everything is going well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2007 06:40:24 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-09-12T06:40:24Z</dc:date>
    <item>
      <title>Static for inbound connection to any network</title>
      <link>https://community.cisco.com/t5/network-security/static-for-inbound-connection-to-any-network/m-p/804904#M1000534</link>
      <description>&lt;P&gt;I have a strange situation on a clients PIX firewall. We are connected to a partner (via our outside interface) and the partner now wishes to use the internet via our network for just a number of devices in a shared DMZ (i.e. the internet is now residing on the inside network. This means it is hard to declare a static that will allow inbound access to in effect 'any'.&lt;/P&gt;&lt;P&gt;Does anyone know if this is possible, and if so what the static command will look like, is it possible to do a 0.0.0.0 type thing..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-for-inbound-connection-to-any-network/m-p/804904#M1000534</guid>
      <dc:creator>pthomsett</dc:creator>
      <dc:date>2019-03-11T11:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Static for inbound connection to any network</title>
      <link>https://community.cisco.com/t5/network-security/static-for-inbound-connection-to-any-network/m-p/804905#M1000535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think that it is a good idea to have an inbound access to any network. It will be very tough to implement this (as per your scenario) and it can have a big security impact.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2007 20:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-for-inbound-connection-to-any-network/m-p/804905#M1000535</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2007-09-11T20:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Static for inbound connection to any network</title>
      <link>https://community.cisco.com/t5/network-security/static-for-inbound-connection-to-any-network/m-p/804906#M1000536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could use a nat exemption which is bi-directional although it would need testing against any other translations you have on the firewall ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit ip any any &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way are you the Paul Thomsett that did work for Network Rail. If so, how are you ?. Hope everything is going well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2007 06:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-for-inbound-connection-to-any-network/m-p/804906#M1000536</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-12T06:40:24Z</dc:date>
    </item>
  </channel>
</rss>

