<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding new subnet to ASA5512 issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039451#M1067243</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What exactly did you configure?&lt;/P&gt;&lt;P&gt;Below is an example of what I assume you require, this will NAT the local network behind the outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;object network NET1&lt;BR /&gt; subnet 192.168.10.0 255.255.255.0&lt;BR /&gt; nat (inside,outside) dynamic interface&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which should appear as below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;ASA-DC-1/pri/act(config-network-object)# &lt;STRONG&gt;show nat detail&lt;/STRONG&gt;&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;&lt;BR /&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;&lt;STRONG&gt;1 (INSIDE) to (OUTSIDE) source dynamic NET1 interface&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;translate_hits = 0, untranslate_hits = 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Source - Origin: 192.168.10.0/24, Translated: 1.1.1.1/24&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2020 17:03:37 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2020-03-03T17:03:37Z</dc:date>
    <item>
      <title>Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039444#M1067242</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im trying to get a new subnet setup on my ASA5512. I've created the object group and put in the subnet. But when sitting up the NAT rule- nat (inside,outside) dynamic NAT+PAT -&amp;nbsp; its not showing up on the new objects I created.&lt;/P&gt;&lt;P&gt;Is there something missing? Any help would be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 16:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039444#M1067242</guid>
      <dc:creator>KCMM14457</dc:creator>
      <dc:date>2020-03-03T16:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039451#M1067243</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What exactly did you configure?&lt;/P&gt;&lt;P&gt;Below is an example of what I assume you require, this will NAT the local network behind the outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;object network NET1&lt;BR /&gt; subnet 192.168.10.0 255.255.255.0&lt;BR /&gt; nat (inside,outside) dynamic interface&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which should appear as below:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;ASA-DC-1/pri/act(config-network-object)# &lt;STRONG&gt;show nat detail&lt;/STRONG&gt;&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;&lt;BR /&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;&lt;STRONG&gt;1 (INSIDE) to (OUTSIDE) source dynamic NET1 interface&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;translate_hits = 0, untranslate_hits = 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Source - Origin: 192.168.10.0/24, Translated: 1.1.1.1/24&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 17:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039451#M1067243</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-03T17:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039462#M1067244</link>
      <description>Yes I have something like that already:&lt;BR /&gt;object network NET1&lt;BR /&gt;subnet 192.168.10.0 255.255.255.0&lt;BR /&gt;nat (inside,outside) dynamic NAT+PAT&lt;BR /&gt;&lt;BR /&gt;when I try to add:&lt;BR /&gt;object network NET5&lt;BR /&gt;subnet 10.10.130.0 255.255.254.0&lt;BR /&gt;nat (inside,outside) dynamic NAT+PAT&lt;BR /&gt;&lt;BR /&gt;the nat rule doesnt work. It just not there for the Obj NET5</description>
      <pubDate>Tue, 03 Mar 2020 17:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039462#M1067244</guid>
      <dc:creator>KCMM14457</dc:creator>
      <dc:date>2020-03-03T17:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039463#M1067245</link>
      <description>Ok, so what is the configuration of NAT+PAT?&lt;BR /&gt;I assume you meant it doesn't show up under "show nat detail"?</description>
      <pubDate>Tue, 03 Mar 2020 17:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039463#M1067245</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-03T17:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039472#M1067247</link>
      <description>Here is what we have for the NAT+PAT right now:&lt;BR /&gt;object network NAT_POOL&lt;BR /&gt;range 66.76.8.100 66.76.8.124&lt;BR /&gt;object network PAT&lt;BR /&gt;host 66.76.8.125&lt;BR /&gt;object-group network NAT+PAT&lt;BR /&gt;network-object object NAT_POOL&lt;BR /&gt;network-object object PAT&lt;BR /&gt;&lt;BR /&gt;Correct when I enter cmd:&lt;BR /&gt;nat (inside,outside) dynamic NAT+PAT&lt;BR /&gt;It doesnt show up in the "show nat detail"</description>
      <pubDate>Tue, 03 Mar 2020 17:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039472#M1067247</guid>
      <dc:creator>KCMM14457</dc:creator>
      <dc:date>2020-03-03T17:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039476#M1067248</link>
      <description>&lt;P&gt;Ok, I copied and pasted your configuration, that worked in my lab using ASA 9.12(3).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (INSIDE) to (OUTSIDE) source dynamic NET1 NAT+PAT&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.10.0/24, Translated: 66.76.8.100/30, 66.76.8.104/29, 66.76.8.112/29, 66.76.8.120/30&lt;BR /&gt;66.76.8.124/32, 66.76.8.125/32&lt;/PRE&gt;&lt;P&gt;What ASA code are you using? Potentially a bug&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 17:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039476#M1067248</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-03T17:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039480#M1067250</link>
      <description>Yea im not sure its something im doing wrong on my config or is there a limit to how many subnets I can add to a obj group for nat.&lt;BR /&gt;&lt;BR /&gt;Where would i find ASA code?</description>
      <pubDate>Tue, 03 Mar 2020 17:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039480#M1067250</guid>
      <dc:creator>KCMM14457</dc:creator>
      <dc:date>2020-03-03T17:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039483#M1067251</link>
      <description>"show version"</description>
      <pubDate>Tue, 03 Mar 2020 17:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039483#M1067251</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-03T17:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039490#M1067252</link>
      <description>Cisco Adaptive Security Appliance Software Version 8.6(1)2&lt;BR /&gt;Device Manager Version 6.6(1)&lt;BR /&gt;&lt;BR /&gt;Compiled on Fri 01-Jun-12 02:16 by builders&lt;BR /&gt;System image file is "disk0:/asa861-2-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hardware: ASA5512, 4096 MB RAM, CPU Clarkdale 2793 MHz, 1 CPU (2 cores)&lt;BR /&gt;ASA: 2048 MB RAM, 1 CPU (1 core)&lt;BR /&gt;Internal ATA Compact Flash, 4096MB&lt;BR /&gt;BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB&lt;BR /&gt;&lt;BR /&gt;Encryption hardware device : Cisco ASA-55xx on-board accelerator (revision 0x1)&lt;BR /&gt;Boot microcode : CNPx-MC-BOOT-2.00&lt;BR /&gt;SSL/IKE microcode : CNPx-MC-SSL-PLUS-0014&lt;BR /&gt;IPSec microcode : CNPx-MC-IPSEC-MAIN-0014&lt;BR /&gt;Number of accelerators: 1&lt;BR /&gt;Baseboard Management Controller (revision 0x1) Firmware Version: 2.4&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;0: Int: Internal-Data0/0 : address is 4c00.821d.e2aa, irq 11&lt;BR /&gt;1: Ext: GigabitEthernet0/0 : address is 4c00.821d.e2ae, irq 10&lt;BR /&gt;2: Ext: GigabitEthernet0/1 : address is 4c00.821d.e2ab, irq 10&lt;BR /&gt;3: Ext: GigabitEthernet0/2 : address is 4c00.821d.e2af, irq 5&lt;BR /&gt;4: Ext: GigabitEthernet0/3 : address is 4c00.821d.e2ac, irq 5&lt;BR /&gt;5: Ext: GigabitEthernet0/4 : address is 4c00.821d.e2b0, irq 10&lt;BR /&gt;6: Ext: GigabitEthernet0/5 : address is 4c00.821d.e2ad, irq 10&lt;BR /&gt;7: Int: Internal-Data0/1 : address is 0000.0001.0002, irq 0&lt;BR /&gt;8: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0&lt;BR /&gt;9: Int: Internal-Data0/2 : address is 0000.0001.0003, irq 0&lt;BR /&gt;10: Ext: Management0/0 : address is 4c00.821d.e2aa, irq 0&lt;BR /&gt;&lt;BR /&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : Unlimited perpetual&lt;BR /&gt;Maximum VLANs : 50 perpetual&lt;BR /&gt;Inside Hosts : Unlimited perpetual&lt;BR /&gt;Failover : Disabled perpetual&lt;BR /&gt;VPN-DES : Enabled perpetual&lt;BR /&gt;VPN-3DES-AES : Enabled perpetual&lt;BR /&gt;Security Contexts : 0 perpetual&lt;BR /&gt;GTP/GPRS : Disabled perpetual&lt;BR /&gt;AnyConnect Premium Peers : 2 perpetual&lt;BR /&gt;AnyConnect Essentials : 250 perpetual&lt;BR /&gt;Other VPN Peers : 250 perpetual&lt;BR /&gt;Total VPN Peers : 250 perpetual&lt;BR /&gt;Shared License : Disabled perpetual&lt;BR /&gt;AnyConnect for Mobile : Enabled perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone : Disabled perpetual&lt;BR /&gt;Advanced Endpoint Assessment : Disabled perpetual&lt;BR /&gt;UC Phone Proxy Sessions : 2 perpetual&lt;BR /&gt;Total UC Proxy Sessions : 2 perpetual&lt;BR /&gt;Botnet Traffic Filter : Disabled perpetual&lt;BR /&gt;Intercompany Media Engine : Disabled perpetual&lt;BR /&gt;IPS Module : Disabled perpetual&lt;BR /&gt;&lt;BR /&gt;This platform has a Base license.</description>
      <pubDate>Tue, 03 Mar 2020 17:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039490#M1067252</guid>
      <dc:creator>KCMM14457</dc:creator>
      <dc:date>2020-03-03T17:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039494#M1067253</link>
      <description>Well you are running a really old version - v8.6(1)2.&lt;BR /&gt;&lt;BR /&gt;Are you already using this nat+pat configuration? If not it may not support it on such an old version, I'd consider upgrading regardless. Your ASA 5512 hardware will support up to the latest version.</description>
      <pubDate>Tue, 03 Mar 2020 17:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039494#M1067253</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-03T17:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039498#M1067254</link>
      <description>Yes i am on at least 7 other subnets. The new ones im adding just wont accept the nat rule.&lt;BR /&gt;&lt;BR /&gt;Im working on upgrading to a new ASA.</description>
      <pubDate>Tue, 03 Mar 2020 17:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039498#M1067254</guid>
      <dc:creator>KCMM14457</dc:creator>
      <dc:date>2020-03-03T17:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039504#M1067255</link>
      <description>Ok, if you are configuring exactly the same as your existing objects, then it should work on that version.&lt;BR /&gt;You should consider logging a call with TAC...but they will probably recommend you upgrade to a supported version though. So I suggest you do that.&lt;BR /&gt;&lt;BR /&gt;In the meantime, consider modifying your nat rule to nat behind a single IP address.</description>
      <pubDate>Tue, 03 Mar 2020 17:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039504#M1067255</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-03T17:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet to ASA5512 issues</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039505#M1067256</link>
      <description>okay so I deleted one of the nat rules on a obj its working on and adding to the one its not and it took it. So it looks like there is a limit to how many I can add&lt;BR /&gt;</description>
      <pubDate>Tue, 03 Mar 2020 17:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-to-asa5512-issues/m-p/4039505#M1067256</guid>
      <dc:creator>KCMM14457</dc:creator>
      <dc:date>2020-03-03T17:57:35Z</dc:date>
    </item>
  </channel>
</rss>

