<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Interface to Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3707260#M12304</link>
    <description>Also, security levels only matter if you don’t have an access-list assigned to the interface.&lt;BR /&gt;</description>
    <pubDate>Fri, 14 Sep 2018 16:53:44 GMT</pubDate>
    <dc:creator>gbekmezi-DD</dc:creator>
    <dc:date>2018-09-14T16:53:44Z</dc:date>
    <item>
      <title>ASA Interface to Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3706824#M12300</link>
      <description>&lt;P&gt;I have an ASA 5512 with 9.2 as its image.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am wondering, even from just interface to interface, are these NAT'd?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have my Inside interface LAN of 172.16.0.0/16 on port 1, Security Level of 100 and my DMZ interface&amp;nbsp;LAN 10.10.10.0 /24 on port 2, Security Level of 50. is port 1 NAT'd to and from port 2?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT: If they are indeed NAT'd to each other, what is the way around this? How could I see this in what troubleshooting/diagnostics tool?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3706824#M12300</guid>
      <dc:creator>Skawilly1</dc:creator>
      <dc:date>2020-02-21T16:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Interface to Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3706832#M12302</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you wish to know if the NAT is configured for access between inside and dmz interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If yes, then you can run some commands to see what NAT is being used for communication. FYI, since 8.3 onwards, NAT-control feature has been taken off, which means that hosts behind any 2 interfaces can communicate with each other even without NAT provided access rules are configured properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run nat&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;packet-tracer command is one feature where you can see all the process flow the ASA will follow for processing the packet including the NAT:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/troubleshooting-access-problems-using-packet-tracer/ta-p/3114976" target="_blank"&gt;https://community.cisco.com/t5/security-documents/troubleshooting-access-problems-using-packet-tracer/ta-p/3114976&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it answered your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 03:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3706832#M12302</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-09-14T03:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Interface to Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3707260#M12304</link>
      <description>Also, security levels only matter if you don’t have an access-list assigned to the interface.&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Sep 2018 16:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3707260#M12304</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2018-09-14T16:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Interface to Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3738606#M12305</link>
      <description>&lt;P&gt;to add to this - sh nat would show the order of nat rules and you could ping from lan to dmz &amp;amp; do sh xlate on the asa - to see if source address is translated.&lt;/P&gt;
&lt;P&gt;hope that helps&lt;/P&gt;
&lt;P&gt;azam&lt;/P&gt;</description>
      <pubDate>Sun, 04 Nov 2018 00:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-to-interface/m-p/3738606#M12305</guid>
      <dc:creator>mkazam001</dc:creator>
      <dc:date>2018-11-04T00:43:43Z</dc:date>
    </item>
  </channel>
</rss>

