<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-help/m-p/3025483#M134490</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create 2 nat exemption for that.&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Object network obj-192.168.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Host 192.168.1.1&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;Object network obj-192.168.1.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Host 192.168.1.2&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;nat (Inside,DMZ) source static obj-10.10.1.1 obj-10.10.1.1 destination static obj-192.168.1.1 obj-192.168.1.1 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;nat (Inside,DMZ) source static obj-10.10.1.1 obj-10.10.1.1 destination static obj-192.168.1.2 obj-192.168.1.2 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;hope that helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2017 05:04:02 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2017-06-28T05:04:02Z</dc:date>
    <item>
      <title>NAT help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/3025482#M134484</link>
      <description>&lt;P&gt;Have an ASA5520 running 9.17 code. It currently has the following NAT statement in it:&lt;/P&gt;
&lt;P&gt;object network obj-10.10.1.1&lt;BR /&gt;&amp;nbsp;nat (inside,DMZ) static 172.252.252.252&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a need where I need this 10.10.1.1 host to be able to communicate with 2 specific hosts on the DMZ, but NOT get translated when doing so. The 2 hosts have IP's of 192.168.1.1 and 192.168.1.2. Not sure the config or type of NAT&amp;nbsp;to do this nor am I sure the order of operations on which will take place first. I only want it not to translate going to the 2 hosts, the rest of the time I want it to keep getting translated to 172.252.252.252. Help appreciated. thank you&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/3025482#M134484</guid>
      <dc:creator>mjsully</dc:creator>
      <dc:date>2019-03-12T09:38:00Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/3025483#M134490</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create 2 nat exemption for that.&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Object network obj-192.168.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Host 192.168.1.1&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;Object network obj-192.168.1.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Host 192.168.1.2&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;nat (Inside,DMZ) source static obj-10.10.1.1 obj-10.10.1.1 destination static obj-192.168.1.1 obj-192.168.1.1 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;nat (Inside,DMZ) source static obj-10.10.1.1 obj-10.10.1.1 destination static obj-192.168.1.2 obj-192.168.1.2 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;hope that helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 05:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/3025483#M134490</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-28T05:04:02Z</dc:date>
    </item>
    <item>
      <title>Thank you. That helps. One</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/3025484#M134498</link>
      <description>&lt;P&gt;Thank you. That helps. One more follow up, I can do that same NAT and use a source subnet also, right? meaning if I decided I wanted everything on 10.10.1.0/24 subnet to NOT get translated when talking to 192.168.1.1 and 192.168.1.2, could I just change the statements to the following:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object network obj-10.1.1.0&lt;BR /&gt;&amp;nbsp;subnet 10.10.1.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;nat (Inside,DMZ) source static obj-10.10.1.0 obj-10.10.1.0 destination static obj-192.168.1.1 obj-192.168.1.1 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (Inside,DMZ) source static obj-10.10.1.0 obj-10.10.1.0 destination static obj-192.168.1.2 obj-192.168.1.2 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 14:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/3025484#M134498</guid>
      <dc:creator>mjsully</dc:creator>
      <dc:date>2017-06-28T14:15:45Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/3025485#M134501</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes you can.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 15:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/3025485#M134501</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-28T15:16:22Z</dc:date>
    </item>
    <item>
      <title>And this is what we call</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/3025486#M134509</link>
      <description>&lt;P&gt;And this is what we call Identity NAT. Please further informations on this link: http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/nat_bypassing.html&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 12:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/3025486#M134509</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-07-03T12:41:59Z</dc:date>
    </item>
  </channel>
</rss>

