<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Query in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-query/m-p/3681752#M14288</link>
    <description>Dear Dennis,&lt;BR /&gt;I didnt understood fully. can you please elaborate more please.?&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 06 Aug 2018 06:29:00 GMT</pubDate>
    <dc:creator>rocky2024</dc:creator>
    <dc:date>2018-08-06T06:29:00Z</dc:date>
    <item>
      <title>NAT Query</title>
      <link>https://community.cisco.com/t5/network-security/nat-query/m-p/3681505#M14279</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide me on below query&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Server 10.1.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | dmz&lt;/P&gt;
&lt;P&gt;R3-----outside----ASA-inside--------PC-B&lt;/P&gt;
&lt;P&gt;Internet&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in above scenario, i am configuring object-nat to nat traffic from server 10.1.1.1 with outside interface to go to internet but why we need to permit real server IP 10.1.1.1 in ACL on outside interface ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network REAL-SERVER&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; host 10.1.1.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; nat (DMZ,OUTSIDE)&amp;nbsp;static 97.1.1.1&amp;nbsp;service tcp https https&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list OUTSIDE-IN permit tcp any&amp;nbsp;object REAL-SERVER eq 443&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;access-group&amp;nbsp;&lt;SPAN&gt;OUTSIDE-IN in interface &lt;STRONG&gt;OUTSIDE&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;why we need to permit above statement where we are defining real ip address for server ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:03:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-query/m-p/3681505#M14279</guid>
      <dc:creator>rocky2024</dc:creator>
      <dc:date>2020-02-21T16:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Query</title>
      <link>https://community.cisco.com/t5/network-security/nat-query/m-p/3681600#M14283</link>
      <description>&lt;P&gt;because your NAT will be processed before an ACL will be processed&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 00:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-query/m-p/3681600#M14283</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-08-06T00:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Query</title>
      <link>https://community.cisco.com/t5/network-security/nat-query/m-p/3681752#M14288</link>
      <description>Dear Dennis,&lt;BR /&gt;I didnt understood fully. can you please elaborate more please.?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 06 Aug 2018 06:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-query/m-p/3681752#M14288</guid>
      <dc:creator>rocky2024</dc:creator>
      <dc:date>2018-08-06T06:29:00Z</dc:date>
    </item>
  </channel>
</rss>

