<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Object NAT on ASA 5525 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005913#M1108423</link>
    <description>&lt;P&gt;Can I see&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show run nat&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jan 2024 20:40:55 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-01-25T20:40:55Z</dc:date>
    <item>
      <title>Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005865#M1108415</link>
      <description>&lt;P&gt;Good Morning All,&lt;/P&gt;&lt;P&gt;Not sure why this isn't working but I have a ASA 5525 running&amp;nbsp;Version 9.2(2)4.&amp;nbsp; What I am trying to do is add an Object Static NAT.&amp;nbsp; Now on the firewall I see how similar policies are configured and I copied the config, minus the IPs and name of course but still not working.&amp;nbsp; &amp;nbsp;This is what I have&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network ext-data4&lt;BR /&gt;host 210.10.197.74 &amp;lt;-- Public IP&lt;BR /&gt;object network vip-data4&lt;BR /&gt;host 10.3.10.44 &amp;lt;-- DMZ IP&lt;/P&gt;&lt;P&gt;I have an ACL that the VIP goes into so now the NAT, when I attempt to do the following Object NAT it looks like it works but when I search for it in the config or do a show xlate for the name/IP nothing shows up&lt;/P&gt;&lt;P&gt;object network vip-data4&lt;BR /&gt;nat (any,any) static ext-data4 net-to-net&lt;/P&gt;&lt;P&gt;When I input the config, looks like it works:&lt;/P&gt;&lt;P&gt;OmedaColoASA(config)# object network vip-data4&lt;BR /&gt;OmedaColoASA(config-network-object)# nat (any,any) static ext-data4&lt;BR /&gt;OmedaColoASA(config-network-object)#&lt;BR /&gt;OmedaColoASA(config-network-object)#&lt;/P&gt;&lt;P&gt;But when I check the config its not even in there.&lt;/P&gt;&lt;P&gt;What am I missing?&amp;nbsp; Thank you in advance!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 19:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005865#M1108415</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-01-25T19:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005870#M1108416</link>
      <description>&lt;P&gt;&lt;SPAN&gt;object network ext-data4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 210.10.197.74 &amp;lt;-- Public IP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network vip-data4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 10.3.10.44 &amp;lt;-- DMZ IP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (DMZ,OUT ) static ext-data4 net-to-net no route-lookup&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This must work&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 19:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005870#M1108416</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-25T19:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005912#M1108422</link>
      <description>&lt;P&gt;Bummer didn't work, it didn't like the&amp;nbsp; "no route-lookup" so I left that out but I put in what you suggested&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;object network vip-data4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 10.3.10.44&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;nat (DMZ,OUT) static ext-data4&amp;nbsp;net-to-net&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;still doesn't show up in the config, probably something silly I am missing...still looking&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 20:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005912#M1108422</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-01-25T20:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005913#M1108423</link>
      <description>&lt;P&gt;Can I see&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show run nat&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 20:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005913#M1108423</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-25T20:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005916#M1108424</link>
      <description>&lt;P&gt;Its kind of long but here here it is I don't see any of the NAT statements we put in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005916#M1108424</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-01-25T21:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005917#M1108425</link>
      <description>&lt;PRE&gt;object network dmz
 nat (dmz,outside) dynamic interface&lt;/PRE&gt;
&lt;P&gt;This come before static NAT so we need to change NAT type to manaul NAT and not use object NAT.&lt;/P&gt;
&lt;P&gt;NAT (DMZ'Outside) &lt;STRONG&gt;source&lt;/STRONG&gt; static object real IP object mapped IP&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005917#M1108425</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-25T21:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005923#M1108426</link>
      <description>&lt;P&gt;Oh ok I see so I need to build it as&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) static vip-datad4 destination static ext-data4&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;object network ext-data4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 210.10.197.74 &amp;lt;-- Public IP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;object network vip-data4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 10.3.10.44 &amp;lt;-- DMZ IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ok will try that then...thank you sir!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005923#M1108426</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-01-25T21:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005928#M1108427</link>
      <description>&lt;P&gt;You are welcome&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:24:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005928#M1108427</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-25T21:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005934#M1108428</link>
      <description>&lt;P&gt;Hmm it didn't like the "static" had to enter "source static" also had to change it up a little it doesn't like what I have below:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;nat (dmz,outside) static vip-data4 destination static ext-data4&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;WORD Specify object or object-group name for real source&lt;BR /&gt;any Abbreviation for source address and mask of 0.0.0.0&lt;BR /&gt;OmedaColoASA(config)# $ ext-data4 ?&lt;BR /&gt;ERROR: % Unrecognized command&lt;BR /&gt;OmedaColoASA(config)# $ vip-data4 ?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;WORD Specify object or object-group name for mapped source&lt;BR /&gt;interface Specify interface NAT&lt;/P&gt;&lt;P&gt;So now my nat statement looks like this:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;nat (dmz,outside) source static vip-data4 vip-data4 destination static ext-data4 ext-data4&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;So at first I thought I did something wrong when i saw this&amp;nbsp;&lt;/P&gt;&lt;P&gt;OmedaColoASA# sh xlate | inc&amp;nbsp;&lt;SPAN&gt;210.10.197.74&lt;/SPAN&gt;&lt;BR /&gt;NAT from outside:&lt;SPAN&gt;210.10.197.74&lt;/SPAN&gt; to dmz:&lt;SPAN&gt;210.10.197.74&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OmedaColoASA# sh xlate | inc 10.3.10.44&lt;BR /&gt;NAT from dmz:10.3.10.44 to outside:10.3.10.44&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but I believe this is ok as those are the IPs we want to see when they hit the interfaces.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I am wrong please let me know otherwise I believe I am good now.&amp;nbsp; Thank you for your help!!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;One more thing if I put this statement at the bottom, then we would of be able to do the object NAT?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;object network dmz nat (dmz,outside) dynamic interface&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:39:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005934#M1108428</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-01-25T21:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005936#M1108429</link>
      <description>&lt;P&gt;NAT (DMZ'Outside)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;source&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;static object real IP object mapped IP &amp;lt;&amp;lt;- this correct one, NO need to add destination&amp;nbsp;&lt;BR /&gt;MHM&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005936#M1108429</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-25T21:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005962#M1108430</link>
      <description>&lt;P&gt;Thank you sir looks good&lt;/P&gt;&lt;P&gt;OmedaColoASA# sh xlate | inc&amp;nbsp;&lt;SPAN&gt;210.10.197.74&lt;/SPAN&gt;&lt;BR /&gt;NAT from dmz:10.3.10.44 to outside:&lt;SPAN&gt;210.10.197.74&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005962#M1108430</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-01-25T21:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005963#M1108431</link>
      <description>&lt;P&gt;please clean your config, delete all other &lt;STRONG&gt;NOT&lt;/STRONG&gt; work NAT we add during troubleshooting&amp;nbsp;&lt;BR /&gt;thanks a lot&amp;nbsp;&lt;BR /&gt;have a nice day&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:57:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005963#M1108431</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-25T21:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005975#M1108432</link>
      <description>&lt;P&gt;You have entered correct commands for object NAT to work correctly (though I would suggest using specific interfaces rather than any). If the commands look to be accepted but do not show up in the configuration then this ASA is not in a healthy state. Perhaps it needs a reboot, and definately needs an upgrade if it is running 9.2.&lt;/P&gt;
&lt;P&gt;This configuration was correct and should have been present in the configuration:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object network ext-data4&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;host 210.10.197.74&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;object network vip-data4&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;host 10.3.10.44&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;nat (any,any) static ext-data4&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Now, just for clarification: &lt;EM&gt;&lt;STRONG&gt;Manual NAT&lt;/STRONG&gt;&lt;/EM&gt;, which is when you define NAT (any,any) source static..., is a top down match. &lt;STRONG&gt;&lt;EM&gt;Auto-NAT&lt;/EM&gt;&lt;/STRONG&gt; will be matched after manual NAT but it is matched in a longest prefix manner and there for not top down. So if you have a default NAT located above a more specific NAT in this section it will still match on the more specifc NAT rule. And then you have &lt;STRONG&gt;&lt;EM&gt;After-auto NAT&lt;/EM&gt;&lt;/STRONG&gt;, which is similar to manual NAT as it is a top down match but will only be matched if there have been no other match in manual NAT or Auto-NAT. So keep this in mind when configuring the ASA.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 22:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5005975#M1108432</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-01-25T22:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: Object NAT on ASA 5525</title>
      <link>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5006491#M1108459</link>
      <description>&lt;P&gt;H Marius,&lt;/P&gt;&lt;P&gt;Thank you for the info, yes it is actually 9.2 and needs a reboot badly as from my understanding hasn't been reboot in a few years. As far as the NAT goes thank you for the information!! I will keep that in mind next time and thank you for taking the time to explain!!!&lt;/P&gt;&lt;P&gt;Thank you sir!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-nat-on-asa-5525/m-p/5006491#M1108459</guid>
      <dc:creator>gurowar</dc:creator>
      <dc:date>2024-01-26T14:39:49Z</dc:date>
    </item>
  </channel>
</rss>

