<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT 1:1 and access to translated host using global IP address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4061624#M1068972</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an ASA 5515, config looks like this:&lt;/P&gt;&lt;P&gt;All inside IP'a are translated to outside. I'm able to ping everything in the Internet and also the host located in DMZ 111.111.111.11 but I'm unable to ping&amp;nbsp; host translated in DMZ (111.111.111.111)&lt;/P&gt;&lt;P&gt;Nat statement looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;object network obj-10.10.10.10
 nat (any,any) static 111.111.111.111&lt;/PRE&gt;&lt;P&gt;I have tried to change it to DMZ, etc but with no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled Diagram.png" style="width: 579px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/71107i62ADE4C550CC7B72/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled Diagram.png" alt="Untitled Diagram.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2020 11:33:33 GMT</pubDate>
    <dc:creator>JohnRambo87365</dc:creator>
    <dc:date>2020-04-08T11:33:33Z</dc:date>
    <item>
      <title>NAT 1:1 and access to translated host using global IP address</title>
      <link>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4061624#M1068972</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an ASA 5515, config looks like this:&lt;/P&gt;&lt;P&gt;All inside IP'a are translated to outside. I'm able to ping everything in the Internet and also the host located in DMZ 111.111.111.11 but I'm unable to ping&amp;nbsp; host translated in DMZ (111.111.111.111)&lt;/P&gt;&lt;P&gt;Nat statement looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;object network obj-10.10.10.10
 nat (any,any) static 111.111.111.111&lt;/PRE&gt;&lt;P&gt;I have tried to change it to DMZ, etc but with no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled Diagram.png" style="width: 579px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/71107i62ADE4C550CC7B72/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled Diagram.png" alt="Untitled Diagram.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 11:33:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4061624#M1068972</guid>
      <dc:creator>JohnRambo87365</dc:creator>
      <dc:date>2020-04-08T11:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAT 1:1 and access to translated host using global IP address</title>
      <link>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4061736#M1068980</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1. Can you confirm that the object of "obj-10.10.10.10" contains a host entry of 10.10.10.10? From where do you want to access 10.10.10.10 as 111.111.111.111, from outside or from DMZ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2. Optimize your NAT config, as (this makes 10.10.10.10 reachable via 111.111.111.111 from the DMZ, but nor from the outside):&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; nat (inside,dmz) static 111.111.111.111&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 13:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4061736#M1068980</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-04-08T13:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT 1:1 and access to translated host using global IP address</title>
      <link>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062458#M1069021</link>
      <description>&lt;P&gt;Yes, the entry obj-10.10.10.10 contains a host entry of 10.10.10.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i would like to do: host 10.10.10.15 to be able reach 111.111.111.111, not 10.10.10.10&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 07:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062458#M1069021</guid>
      <dc:creator>JohnRambo87365</dc:creator>
      <dc:date>2020-04-09T07:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT 1:1 and access to translated host using global IP address</title>
      <link>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062502#M1069026</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Clearly the recommended way would be to place 10.10.10.10 in the DMZ VLAN. As long as 10.10.10.10 and 10.10.10.15 are within same VLAN, even if you fall them into not speaking directly by doing NAT, if they initiate a direct session it will work. To make wha you want happen, you would have to make both 10.10.10.10 and 10.10.10.15 be visible as something else on the inside, and traffic will be hair-pinned by the FW. This is clearly not recommended as you make the configuration complex in the end hosts could still talk directly. Ensure that except the below config, if there is ingress ACL applied on the inside interface, to global ACL, the traffic between 111.111.111.111 and 111.111.111.115 is allowed:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network FIRST&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;host 10.10.10.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;nat (inside,inside) static 111.111.111.111&lt;/P&gt;&lt;P&gt;object network SECOND&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; host 10.10.10.15&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; nat (inside,inside) static 111.111.111.115&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 08:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062502#M1069026</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-04-09T08:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAT 1:1 and access to translated host using global IP address</title>
      <link>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062514#M1069029</link>
      <description>&lt;P&gt;I know that best option will be to put 10.10.10.10 in DMZ vlan, but then traffic will flow throught FW. I have couple servers that has been done this way, cos in the past I had only 300 Mbps FW.&lt;/P&gt;&lt;P&gt;I will try what u have recomended.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 08:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062514#M1069029</guid>
      <dc:creator>JohnRambo87365</dc:creator>
      <dc:date>2020-04-09T08:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: NAT 1:1 and access to translated host using global IP address</title>
      <link>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062932#M1069049</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;If you want to NAT a host, traffic has to go through the NATing device, which in your case is the firewall. If you want traffic between 10.10.10.10 and 10.10.10.15 to bypass the firewall, just leave it as it is, they can speak directly without NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 17:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-1-1-and-access-to-translated-host-using-global-ip-address/m-p/4062932#M1069049</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-04-09T17:01:37Z</dc:date>
    </item>
  </channel>
</rss>

