<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem doing PAT to a range of public IPs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-doing-pat-to-a-range-of-public-ips/m-p/4730630#M1095537</link>
    <description>&lt;P&gt;We currently have a Firepower 4110 running 7.0.4 managed by an FMCv also running 7.0.4. We've been experiencing some asp-drops because of NAT exhaustion, so I tried to change the dynamic Auto NAT rule from a single IP address to a range of IP addresses as they unfortunately don't fall on a subnet boundary. As soon as the change is deployed, only one system could get out on each public IP address in the pool. The response to "sh xlate | in &amp;lt;public_IP&amp;gt;" was a single xlate entry for each public IP in the pool. I change it back to the single IP, and there are thousands of entries. I repeated this 3 times and verified all objects just to make sure nothing was fat fingered. I also cleared the connection and translation tables, which didn't help. I'm missing something pretty basic, I guess, but can anyone point me to the issue? The object for Public_NAT is #.#.#.6, while the object for Public_NAT_pool is a *range of #.#.#.6-#.#.#.9. For the below, the source and destination zones are inside and outside. Thanks for your help.&lt;/P&gt;&lt;P&gt;Existing rule (works):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ABaker94985_0-1669850637556.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169584iB28A83F1A988AFCA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ABaker94985_0-1669850637556.png" alt="ABaker94985_0-1669850637556.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;New rule (doesn't work):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ABaker94985_1-1669850676403.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169585i209157C5FE31C0D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ABaker94985_1-1669850676403.png" alt="ABaker94985_1-1669850676403.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2022 23:35:46 GMT</pubDate>
    <dc:creator>ABaker94985</dc:creator>
    <dc:date>2022-11-30T23:35:46Z</dc:date>
    <item>
      <title>Problem doing PAT to a range of public IPs</title>
      <link>https://community.cisco.com/t5/network-security/problem-doing-pat-to-a-range-of-public-ips/m-p/4730630#M1095537</link>
      <description>&lt;P&gt;We currently have a Firepower 4110 running 7.0.4 managed by an FMCv also running 7.0.4. We've been experiencing some asp-drops because of NAT exhaustion, so I tried to change the dynamic Auto NAT rule from a single IP address to a range of IP addresses as they unfortunately don't fall on a subnet boundary. As soon as the change is deployed, only one system could get out on each public IP address in the pool. The response to "sh xlate | in &amp;lt;public_IP&amp;gt;" was a single xlate entry for each public IP in the pool. I change it back to the single IP, and there are thousands of entries. I repeated this 3 times and verified all objects just to make sure nothing was fat fingered. I also cleared the connection and translation tables, which didn't help. I'm missing something pretty basic, I guess, but can anyone point me to the issue? The object for Public_NAT is #.#.#.6, while the object for Public_NAT_pool is a *range of #.#.#.6-#.#.#.9. For the below, the source and destination zones are inside and outside. Thanks for your help.&lt;/P&gt;&lt;P&gt;Existing rule (works):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ABaker94985_0-1669850637556.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169584iB28A83F1A988AFCA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ABaker94985_0-1669850637556.png" alt="ABaker94985_0-1669850637556.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;New rule (doesn't work):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ABaker94985_1-1669850676403.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/169585i209157C5FE31C0D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ABaker94985_1-1669850676403.png" alt="ABaker94985_1-1669850676403.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 23:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-doing-pat-to-a-range-of-public-ips/m-p/4730630#M1095537</guid>
      <dc:creator>ABaker94985</dc:creator>
      <dc:date>2022-11-30T23:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problem doing PAT to a range of public IPs</title>
      <link>https://community.cisco.com/t5/network-security/problem-doing-pat-to-a-range-of-public-ips/m-p/4730968#M1095552</link>
      <description>&lt;P&gt;Use the PAT Pool tab instead. That will work.&lt;/P&gt;
&lt;P&gt;Reference Step 6 here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/network_address_translation_nat_for_firepower_threat_defense.html#task_5368FCFF9B8949628F3C3205C945E34D" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/network_address_translation_nat_for_firepower_threat_defense.html#task_5368FCFF9B8949628F3C3205C945E34D&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 14:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-doing-pat-to-a-range-of-public-ips/m-p/4730968#M1095552</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-12-01T14:08:55Z</dc:date>
    </item>
  </channel>
</rss>

