<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Policy Based Routing on NAT interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761150#M1097138</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;is it possible on the ASA to apply PBR on a NAT interface? PBR is matched by port that is not changed by NAT.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 17:32:18 GMT</pubDate>
    <dc:creator>NazgulNr5</dc:creator>
    <dc:date>2023-01-24T17:32:18Z</dc:date>
    <item>
      <title>ASA Policy Based Routing on NAT interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761150#M1097138</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;is it possible on the ASA to apply PBR on a NAT interface? PBR is matched by port that is not changed by NAT.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 17:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761150#M1097138</guid>
      <dc:creator>NazgulNr5</dc:creator>
      <dc:date>2023-01-24T17:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Policy Based Routing on NAT interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761168#M1097142</link>
      <description>&lt;P&gt;can you more elaborate ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 17:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761168#M1097142</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-01-24T17:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Policy Based Routing on NAT interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761322#M1097157</link>
      <description>&lt;P&gt;what is the ASA Model and what Code running on it, check PBR and NAT guidelines - if you looking more support provide example and config and routes you have :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-based.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/general/asa-94-general-config/route-policy-based.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 20:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761322#M1097157</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-24T20:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Policy Based Routing on NAT interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761883#M1097163</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;Sorry for the **bleep**post...&lt;/P&gt;&lt;P&gt;Here is some more info.&lt;/P&gt;&lt;P&gt;NAT rules:&lt;/P&gt;&lt;P&gt;nat (inside_2,outside) source dynamic LAN_SUBNET PUBLIC_IP2 description NAT to server x&lt;BR /&gt;nat (inside_1,outside) source dynamic LAN_SUBNET PUBLIC_IP1&lt;/P&gt;&lt;P&gt;Planned PBR:&lt;/P&gt;&lt;P&gt;object-group services server-x-port tcp&lt;BR /&gt;port-object eq 8443&lt;/P&gt;&lt;P&gt;access-list PBR_ACL extended permit tcp object-group LAN_NET any object-group server-x-port&lt;/P&gt;&lt;P&gt;route-map PBR permit 1&lt;BR /&gt;match ip address PBR_ACL&lt;BR /&gt;set ip next-hop x.x.x.x (shove out interface inside2)&lt;/P&gt;&lt;P&gt;Story behind this:&lt;/P&gt;&lt;P&gt;Traffic to the external server x comes in on interface inside2. As the static route to the internal subnets is going out interface inside1 and need to use PBR to return traffic the way it came in.&lt;/P&gt;&lt;P&gt;Would that work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 09:23:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-policy-based-routing-on-nat-interface/m-p/4761883#M1097163</guid>
      <dc:creator>NazgulNr5</dc:creator>
      <dc:date>2023-01-25T09:23:57Z</dc:date>
    </item>
  </channel>
</rss>

