<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet working without nat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484591#M1084320</link>
    <description>&lt;P&gt;NAT isn't required on the ASA per se.&lt;/P&gt;
&lt;P&gt;There could be an upstream device performing NAT for the clients behind the ASA.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Oct 2021 16:05:14 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-10-12T16:05:14Z</dc:date>
    <item>
      <title>Internet working without nat</title>
      <link>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484554#M1084319</link>
      <description>&lt;P&gt;We are on Cisco ASA 5516.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an interface 10.50.70.0/23 on the firewall and it has outbound access list set to 'permit any'. But there is no NAT configured for this interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yet, systems behind this interface are able to access internet, how is that possible? I thought NAT was mandatory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet tracer:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: INPUT-ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found next-hop X.X.X.X (gateway) using egress ifc outside&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;(Access list permit ip any any snipped)&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: SFR&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map sfr&lt;BR /&gt;match access-list sfr_redirect&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class sfr&lt;BR /&gt;sfr fail-open&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 9&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 386155607, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: XXXXX&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 15:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484554#M1084319</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2021-10-12T15:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Internet working without nat</title>
      <link>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484591#M1084320</link>
      <description>&lt;P&gt;NAT isn't required on the ASA per se.&lt;/P&gt;
&lt;P&gt;There could be an upstream device performing NAT for the clients behind the ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 16:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484591#M1084320</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-10-12T16:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Internet working without nat</title>
      <link>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484601#M1084321</link>
      <description>&lt;P&gt;Our ASA is the only device that does all the NAT.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 16:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484601#M1084321</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2021-10-12T16:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Internet working without nat</title>
      <link>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484609#M1084322</link>
      <description>&lt;P&gt;What does traceroute show you?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 16:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4484609#M1084322</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-10-12T16:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Internet working without nat</title>
      <link>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4485103#M1084329</link>
      <description>&lt;P&gt;I jumped the gun!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked at the asdm logs and assumed the packets are going through. ACL allowed everything, hence the logs, but on the end host interent access didn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 08:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-working-without-nat/m-p/4485103#M1084329</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2021-10-13T08:53:53Z</dc:date>
    </item>
  </channel>
</rss>

