<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA NAT Exempt Rule in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726983#M1001719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes as long as the server IP address 2.2.2.2 is routable across your wan and is not used anywhere else this should be no problem at all. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not clear from your diagram what the addressing scheme is but as long as the remote sites route 2.2.2.2 back to HQ you should be fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Jul 2007 16:18:48 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-07-20T16:18:48Z</dc:date>
    <item>
      <title>ASA NAT Exempt Rule</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726982#M1001718</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the attached diagram, i want to allow network monitoring server to monitor the remote branches routers, can i configure the ASA to allow traffic from monitoring server to branches routers without perform NAT ? if not, are there any way for us to achieve the objective ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726982#M1001718</guid>
      <dc:creator>benghock</dc:creator>
      <dc:date>2019-03-26T00:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT Exempt Rule</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726983#M1001719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes as long as the server IP address 2.2.2.2 is routable across your wan and is not used anywhere else this should be no problem at all. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not clear from your diagram what the addressing scheme is but as long as the remote sites route 2.2.2.2 back to HQ you should be fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2007 16:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726983#M1001719</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-20T16:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT Exempt Rule</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726984#M1001720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've tested the configuration with the below command, but it still not working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_nat0_inbound&lt;/P&gt;&lt;P&gt;access-list outside_nat0_inbound extended permit ip host 2.2.2.2 host 1.1.1.1 &lt;/P&gt;&lt;P&gt;access-list outside_nat0_inbound extended permit ip host 2.2.2.2 host 1.1.1.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've check the firewall log and below is the error log,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No translation group found for icmp src outside: 2.2.2.2 dst inside:1.1.1.1 (type 8, code 0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas ?&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Jul 2007 00:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726984#M1001720</guid>
      <dc:creator>benghock</dc:creator>
      <dc:date>2007-07-21T00:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT Exempt Rule</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726985#M1001721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I actually misread your diagram at first. The monitoring server is on the outside. You should not have to worry about a translation for 2.2.2.2. &lt;/P&gt;&lt;P&gt;If you did have to use a nat statement for every host on the outside of an ASA it woudl be very difficult to use it as an internet firewall &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have translations set up for the inside servers eg. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Jul 2007 03:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726985#M1001721</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-21T03:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT Exempt Rule</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726986#M1001722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All for the remote routers are located within "inside" network, the monitoring server is located at "outside" network. I'll test the suggested command, but the command only applicable to one single host/router, how about the rest of the remote routers ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Beng Hock&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Jul 2007 04:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-exempt-rule/m-p/726986#M1001722</guid>
      <dc:creator>benghock</dc:creator>
      <dc:date>2007-07-21T04:03:30Z</dc:date>
    </item>
  </channel>
</rss>

