<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT and ACL clarification. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-and-acl-clarification/m-p/3076486#M145159</link>
    <description>&lt;P&gt;Hello, I have&amp;nbsp;a small &amp;nbsp;quick question on ASA&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Object-group test&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 10.10.10.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static 1.1.1.1 service tcp 1683 1683&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;and if I have a ACL entry from outside in into inside as below, will protocol 80 will work? or just only 1683&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;permit ip any host 10.10.10.10 service eq 1683&lt;/P&gt;
&lt;P&gt;permit ip any host 10.10.10.10 service eq 80&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:10:54 GMT</pubDate>
    <dc:creator>Anthonize Rajaratne</dc:creator>
    <dc:date>2019-03-12T09:10:54Z</dc:date>
    <item>
      <title>NAT and ACL clarification.</title>
      <link>https://community.cisco.com/t5/network-security/nat-and-acl-clarification/m-p/3076486#M145159</link>
      <description>&lt;P&gt;Hello, I have&amp;nbsp;a small &amp;nbsp;quick question on ASA&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Object-group test&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 10.10.10.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static 1.1.1.1 service tcp 1683 1683&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;and if I have a ACL entry from outside in into inside as below, will protocol 80 will work? or just only 1683&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;permit ip any host 10.10.10.10 service eq 1683&lt;/P&gt;
&lt;P&gt;permit ip any host 10.10.10.10 service eq 80&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-and-acl-clarification/m-p/3076486#M145159</guid>
      <dc:creator>Anthonize Rajaratne</dc:creator>
      <dc:date>2019-03-12T09:10:54Z</dc:date>
    </item>
    <item>
      <title>It will only allow the port</title>
      <link>https://community.cisco.com/t5/network-security/nat-and-acl-clarification/m-p/3076487#M145160</link>
      <description>&lt;P&gt;It will only allow the port you have specified in the NAT statement so no it won't work assuming you have no other NAT statements for that host.&lt;/P&gt;
&lt;P&gt;If you want to allow other ports you need further NAT statements.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 18:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-and-acl-clarification/m-p/3076487#M145160</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2017-04-05T18:27:54Z</dc:date>
    </item>
  </channel>
</rss>

