<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Dynamic NAT Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651075#M1034510</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Diagaram&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Feb 2007 13:27:32 GMT</pubDate>
    <dc:creator>astanislaus</dc:creator>
    <dc:date>2007-02-07T13:27:32Z</dc:date>
    <item>
      <title>PIX Dynamic NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651074#M1034495</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The network 1.1.1.0/23 is dynamically translated to 5.5.5.5 when accessing the resources 7.7.7.7 and 8.8.8.8 on port 443. This has been working for months, then last week it stopped working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. To resolve the problem on scenario A, host within the 1.1.1.0/23 network were statically translated to individual IP addresses. This is now working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another solution for scenario A is scenario C, the network 1.1.1.0/23 is translated to 5.5.5.5 upon reaching PIX, Identity NAT is applied and this setup is working. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What caused the dynamic NAT to stopped working? &lt;/P&gt;&lt;P&gt;How can we restore dynamic NAT from working again? &lt;/P&gt;&lt;P&gt;Isolation shows that Static and Identity NAT are working. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: IP addresses here are not the actual IP Addresses in production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651074#M1034495</guid>
      <dc:creator>astanislaus</dc:creator>
      <dc:date>2019-03-11T09:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Dynamic NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651075#M1034510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Diagaram&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2007 13:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651075#M1034510</guid>
      <dc:creator>astanislaus</dc:creator>
      <dc:date>2007-02-07T13:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Dynamic NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651076#M1034524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry. I thought the attaching file was not working and hence by mistake attached same diagram thrice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2007 13:28:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651076#M1034524</guid>
      <dc:creator>astanislaus</dc:creator>
      <dc:date>2007-02-07T13:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Dynamic NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651077#M1034537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you send the config of the pix. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also could you let us know which scenario you are currently running so the pix config makes sense. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2007 13:33:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dynamic-nat-issue/m-p/651077#M1034537</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-02-07T13:33:55Z</dc:date>
    </item>
  </channel>
</rss>

