<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT &amp; Routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042149#M145342</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;i have a perimeter firewall which is connecting to ISP router, ISP provided to me 2 public subnets, one is of /30 and the other of /29 both of different subnets,&lt;/P&gt;
&lt;P&gt;I have used /30 subnet between the isp router and the firewall outside interface, i want to use /29 public ip subnet for my servers which will be static natted&amp;nbsp; so here the challenge is how the routing will take place for my /29 public ip address,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ISP will throw the packet on my firewall and how the firewall will come to know that /29 subnet is static natted when no interface is configured with the /29 subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:08:49 GMT</pubDate>
    <dc:creator>adamgibs7</dc:creator>
    <dc:date>2019-03-12T09:08:49Z</dc:date>
    <item>
      <title>NAT &amp; Routing</title>
      <link>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042149#M145342</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;i have a perimeter firewall which is connecting to ISP router, ISP provided to me 2 public subnets, one is of /30 and the other of /29 both of different subnets,&lt;/P&gt;
&lt;P&gt;I have used /30 subnet between the isp router and the firewall outside interface, i want to use /29 public ip subnet for my servers which will be static natted&amp;nbsp; so here the challenge is how the routing will take place for my /29 public ip address,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ISP will throw the packet on my firewall and how the firewall will come to know that /29 subnet is static natted when no interface is configured with the /29 subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042149#M145342</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2019-03-12T09:08:49Z</dc:date>
    </item>
    <item>
      <title>When you configure NAT the</title>
      <link>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042150#M145343</link>
      <description>&lt;P&gt;When you configure NAT the firewall takes ownership of the IP. So if a packet arrives with an IP from that block and you have a static NAT statement on your firewall then the firewall will simply translate to the real IP and forward on the traffic,assuming it is allowed.&lt;/P&gt;
&lt;P&gt;This is how all L3 devices handle NAT.&lt;/P&gt;
&lt;P&gt;Note the above assumes the ISP is routing the /29 to your firewall. There is another way the ISP could do it and you might need additional configuration but the more common way is to route.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 16:55:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042150#M145343</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2017-03-29T16:55:34Z</dc:date>
    </item>
    <item>
      <title>Dear Jon,</title>
      <link>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042151#M145344</link>
      <description>&lt;P&gt;Dear Jon,&lt;/P&gt;
&lt;P&gt;is it proxy arp takes place here.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 05:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042151#M145344</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2017-03-31T05:17:25Z</dc:date>
    </item>
    <item>
      <title>Adam</title>
      <link>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042152#M145345</link>
      <description>&lt;P&gt;Adam&lt;/P&gt;
&lt;P&gt;Not when the traffic is routed to your firewall. The other way of doing it that I mentioned however does use proxy arp and that is when the ISP instead of having a route for that subnet pointing to your firewall have a secondary IP address from the new subnet on their router.&lt;/P&gt;
&lt;P&gt;So then they would arp for any of the new IPs and your firewall would answer ie. be a proxy for the arp requests.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 12:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-routing/m-p/3042152#M145345</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2017-03-31T12:50:07Z</dc:date>
    </item>
  </channel>
</rss>

