<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Object based NAT - Natting two public IP to one private IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3346833#M1033535</link>
    <description>&lt;P&gt;It will work partially at best, but not as intended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Simplest solution for you, add a secondary IP on that 1&lt;SPAN&gt;0.53.19.8 server keep this config&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network SIP3&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.92&lt;BR /&gt;exit&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;then map&amp;nbsp;8.xxx.xx.90 to the secondary local IP&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Mar 2018 15:22:45 GMT</pubDate>
    <dc:creator>Florin Barhala</dc:creator>
    <dc:date>2018-03-12T15:22:45Z</dc:date>
    <item>
      <title>Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3344208#M1033527</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need your help with a configuration bit for Object based NAT - Natting two public IP to one private IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am asked to nat two public IP to one private IP&amp;nbsp;&lt;SPAN&gt;8.xxx.xx.90 and 8.xxx.xx.92 to nat to 10.53.19.8.&amp;nbsp; 8.xxx.xx.92 nats to&amp;nbsp;10.53.19.8 (Already in place)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Below is the configuration we&amp;nbsp;currently have&amp;nbsp;8.xxx.xx.90 nats to&amp;nbsp;10.53.12.14 and&amp;nbsp;8.xxx.xx.92 nats to&amp;nbsp;10.53.19.8.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Need configuration bits to achieve&amp;nbsp;8.xxx.xx.90 and 8.xxx.xx.92 to nat to 10.53.19.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP1&lt;BR /&gt; nat (INSIDE,OUTSIDE) static 8.xxx.xx.90&lt;BR /&gt;object network SIP3&lt;BR /&gt; nat (INSIDE,OUTSIDE) static 8.xxx.xx.92&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP1&lt;BR /&gt; host 10.53.12.14&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP3&lt;BR /&gt; host 10.53.19.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Raghav.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3344208#M1033527</guid>
      <dc:creator>raghavendrasomiyani</dc:creator>
      <dc:date>2020-02-21T15:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3344573#M1033528</link>
      <description>&lt;P&gt;Hi Raghav,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Translating multiple mapped IP to one real IP address is not possible in static NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the real IP address is running multiple services then you may use static PAT to translate one service of the real IP to each mapped IP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in static NAT you cannot map multiple mapped IPs to 1 real IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Narayana Rao.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 05:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3344573#M1033528</guid>
      <dc:creator>V S Narayana Chivukula</dc:creator>
      <dc:date>2018-03-08T05:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3345051#M1033529</link>
      <description>Hi Narayana,&lt;BR /&gt;&lt;BR /&gt;Thanks for your response. &lt;BR /&gt;&lt;BR /&gt;So what is the best method to have 2 public IP's nat to one Private address. I am not restricted to object based nat only, I am looking/open for other options as well.&lt;BR /&gt;&lt;BR /&gt;Key is to make it work.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Raghav.</description>
      <pubDate>Thu, 08 Mar 2018 18:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3345051#M1033529</guid>
      <dc:creator>raghavendrasomiyani</dc:creator>
      <dc:date>2018-03-08T18:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3345431#M1033530</link>
      <description>Just do service based nat, instead of 1:1 nat aka Static NAT. &lt;BR /&gt;&lt;BR /&gt;It doesn't matter if it's a rule nat or an object NAT, Static NAT doesn't work on your scenario requirements.</description>
      <pubDate>Fri, 09 Mar 2018 09:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3345431#M1033530</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-09T09:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3346416#M1033532</link>
      <description>&lt;P&gt;I created a new object SIP 4 with same private host IP of SIP3 (SIP3 and SIP4 has same private IP), but natting each of them independently (SIP3 to 8.xxx.xx.92) and (SIP4 to 8.xxx.xx.90). Let me know if below should work or will run into any (what) problems.&lt;BR /&gt;object network SIP3&lt;BR /&gt; host 10.53.19.8&lt;BR /&gt;exit&lt;BR /&gt;object network SIP4&lt;BR /&gt;host 10.53.19.8&lt;BR /&gt;exit&lt;BR /&gt;object network SIP3&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.92&lt;BR /&gt;exit&lt;BR /&gt;object network SIP4&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.90&lt;BR /&gt;exit&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Raghav&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 01:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3346416#M1033532</guid>
      <dc:creator>raghavendrasomiyani</dc:creator>
      <dc:date>2018-03-12T01:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3346833#M1033535</link>
      <description>&lt;P&gt;It will work partially at best, but not as intended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Simplest solution for you, add a secondary IP on that 1&lt;SPAN&gt;0.53.19.8 server keep this config&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network SIP3&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.92&lt;BR /&gt;exit&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;then map&amp;nbsp;8.xxx.xx.90 to the secondary local IP&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 15:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3346833#M1033535</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-12T15:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3347256#M1033538</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the description, you need to NAT 2 public ip addresses to point to a single real ip address for inbound access, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then I see you have a mapping for 2 inside servers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP1&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.90&lt;BR /&gt;object network SIP3&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.92&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP1&lt;BR /&gt;host 10.53.12.14&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP3&lt;BR /&gt;host 10.53.19.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you wish to remove the NAT for&amp;nbsp;10.53.12.14 and point both public ip addresses to&amp;nbsp;10.53.12.8?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If yes, this should be possible, but there are some catches. If you confirm my understanding above, I can suggest few steps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mulitple public ip address can be very well mapped to a single real server ip address and its a valid design.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;BR /&gt;AJ&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 04:32:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3347256#M1033538</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-03-13T04:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3347499#M1033540</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible to do a static NAT for a real IP with multiple NAT IPs.&lt;/P&gt;
&lt;P&gt;It's called one to many static NAT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example, if the real IP would be 10.10.10.10 and your 'public' IPs would be 5.5.5.5 and 5.5.5.7, you would have to configure something like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;object-group network MY_PUBLIC_IPs&lt;BR /&gt;&amp;nbsp;network-object host 5.5.5.5&lt;BR /&gt;&amp;nbsp;network-object host 5.5.5.7&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;object network HOST_10.10.10.10&lt;BR /&gt;&amp;nbsp;host 10.10.10.10&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source static HOST_10.10.10.10 MY_PUBLIC_IPs&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Take into account what whenver the real host connects to the outside world (outbound session) it would always use the first IP configured inside the NAT object (5.5.5.5).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still, anyone from the outside (inbound) can connect to the real host using any NAT IP (both 5.5.5.5 and 5.5.5.7).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:01:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3347499#M1033540</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2018-03-13T12:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3348568#M1033542</link>
      <description>Hi Ajay,&lt;BR /&gt;&lt;BR /&gt;Sorry, I got caught up with priority issues and couldn't keep a check here. &lt;BR /&gt;&lt;BR /&gt;Yes, your understanding is correct.&lt;BR /&gt;&lt;BR /&gt;We wish to remove the NAT for 10.53.12.14 (this will get decom) and point both public ip addresses (8.xxx.xx.90 and 8.xxx.xx.92) to 10.53.12.8.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Raghav.</description>
      <pubDate>Wed, 14 Mar 2018 15:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3348568#M1033542</guid>
      <dc:creator>raghavendrasomiyani</dc:creator>
      <dc:date>2018-03-14T15:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Object based NAT - Natting two public IP to one private IP</title>
      <link>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3348926#M1033544</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should be feasible, all we have to do is to create 2 NAT statements. Inbound, both public ip address will work, but for inbound, the first in order will work when the server will initiate traffic towards internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With object NAT, your config should look like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP1&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.90&lt;BR /&gt;object network SIP3&lt;BR /&gt;nat (INSIDE,OUTSIDE) static 8.xxx.xx.92&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP1&lt;BR /&gt;host 10.53.12.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SIP3&lt;BR /&gt;host 10.53.19.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 04:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-based-nat-natting-two-public-ip-to-one-private-ip/m-p/3348926#M1033544</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-03-15T04:49:37Z</dc:date>
    </item>
  </channel>
</rss>

