<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic STATIC NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat/m-p/791694#M1004909</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I working on following scenario. I need some clarification on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 209.165.201.2 255.255.255.248&lt;/P&gt;&lt;P&gt;ip address inside 209.165.201.9 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 209.165.201.5 209.165.201.12 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the above confifuration, what should I enter in the access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 209.165.201.12&lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 209.165.201.5&lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For both what should IP sould I enter to acsess my Inside Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:11:55 GMT</pubDate>
    <dc:creator>jahangeer_abdul</dc:creator>
    <dc:date>2019-03-11T10:11:55Z</dc:date>
    <item>
      <title>STATIC NAT</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/791694#M1004909</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I working on following scenario. I need some clarification on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 209.165.201.2 255.255.255.248&lt;/P&gt;&lt;P&gt;ip address inside 209.165.201.9 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 209.165.201.5 209.165.201.12 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the above confifuration, what should I enter in the access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 209.165.201.12&lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 209.165.201.5&lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For both what should IP sould I enter to acsess my Inside Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/791694#M1004909</guid>
      <dc:creator>jahangeer_abdul</dc:creator>
      <dc:date>2019-03-11T10:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/791695#M1004910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should use the following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 209.165.201.5 &lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 09:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/791695#M1004910</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T09:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/791696#M1004911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you comment. what destination IP slould the end user use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's 209.165.201.5, how the packet will be sent to default Gateway as the destination IP in same LAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 10:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/791696#M1004911</guid>
      <dc:creator>jahangeer_abdul</dc:creator>
      <dc:date>2007-05-10T10:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/791697#M1004912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The destination IP address should be 209.165.201.5 as that is the address you are presenting to the outside. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you configure a static on the ASA/Pix it then becomes responsible for that IP address so it will respond to arp requests. So when the router receives the packet it will arp out for 209.165.201.5 and the ASA/pix will respond with the mac address of it's external interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this makes sense &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 10:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/791697#M1004912</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T10:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/791698#M1004913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 209.165.X.X 209.165.201.12 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out permit tcp any host 209.165.X.X &lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shall I configure any no in the place of X irrespective of the Subnet.&lt;/P&gt;&lt;P&gt;or should I configure only 209.165.201.5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 10:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/791698#M1004913</guid>
      <dc:creator>jahangeer_abdul</dc:creator>
      <dc:date>2007-05-10T10:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/791699#M1004914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only configure one ip address in your static statement so it could be any spare ip address from your 209.165.201.0/29 subnet so you may as well use .5 if that is free. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 11:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/791699#M1004914</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T11:01:47Z</dc:date>
    </item>
  </channel>
</rss>

