<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network Address Translation on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951267#M150475</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a network existing like this:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/drawing1_31.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now, I have a domain name called "reg.mydomain.com" and will be resolved to 139.254.10.84.&lt;/P&gt;
&lt;P&gt;I need that domain name pointing to Captive Portal Server (10.241.2.11:38080), so when I access reg.mydomain.com:38080, it will show up the web page from 10.241.2.11:38080.&lt;/P&gt;
&lt;P&gt;I did the static NAT from Cisco ASA:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture_94.jpg" class="migrated-markup-image" /&gt;&amp;nbsp;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture_95.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;With the configuration of Static NAT, I can access the 139.255.10.84:38080 which will be translated to 10.241.2.11:38080 from other internet access (with different IP Public of 139.255.10.80/29).&lt;/P&gt;
&lt;P&gt;But when I tried to access 139.255.10.84:38080 from the user inside firewall (10.241.2.10, which will be NAT PAT to 139.255.10.83 when access to internet), it always timed out. What is configuration that I missing in the Cisco ASA?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:11:07 GMT</pubDate>
    <dc:creator>Arie --</dc:creator>
    <dc:date>2019-03-12T08:11:07Z</dc:date>
    <item>
      <title>Network Address Translation on ASA</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951267#M150475</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a network existing like this:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/drawing1_31.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now, I have a domain name called "reg.mydomain.com" and will be resolved to 139.254.10.84.&lt;/P&gt;
&lt;P&gt;I need that domain name pointing to Captive Portal Server (10.241.2.11:38080), so when I access reg.mydomain.com:38080, it will show up the web page from 10.241.2.11:38080.&lt;/P&gt;
&lt;P&gt;I did the static NAT from Cisco ASA:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture_94.jpg" class="migrated-markup-image" /&gt;&amp;nbsp;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture_95.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;With the configuration of Static NAT, I can access the 139.255.10.84:38080 which will be translated to 10.241.2.11:38080 from other internet access (with different IP Public of 139.255.10.80/29).&lt;/P&gt;
&lt;P&gt;But when I tried to access 139.255.10.84:38080 from the user inside firewall (10.241.2.10, which will be NAT PAT to 139.255.10.83 when access to internet), it always timed out. What is configuration that I missing in the Cisco ASA?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951267#M150475</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2019-03-12T08:11:07Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951268#M150476</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;DNS is UDP port 53.&lt;/P&gt;
&lt;P&gt;could you change the protocol to UDP instead?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 07:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951268#M150476</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-08-25T07:20:21Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951269#M150477</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thanks for your reply. But, if I'm not using DNS, when I access 139.255.10.84:38080 from inside host (10.241.2.10), it's also not working.&lt;/P&gt;
&lt;P&gt;If I access&amp;nbsp;&lt;SPAN&gt;139.255.10.84:38080 from other IP public or other outside host, then it's working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Do you have any idea how to solve it first?&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 10:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951269#M150477</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2016-08-25T10:29:58Z</dc:date>
    </item>
    <item>
      <title>Hello Arie,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951270#M150478</link>
      <description>&lt;P&gt;Hello Arie,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There is a couple of things you can do and some of them depend on the version and what you want to achieve. You can configure dns inspection so that the ASA would change the dns reply so that when the end host resolves the URL he gets the real (private) IP of the server.&lt;/P&gt;
&lt;P&gt;Also you can configure the ASA to do a twice NAT which would basically make the ASA change the destinations from 139.254.10.84 ----&amp;gt; 10.241.2.11 but the configuations for this would depend on the version you are currently running.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Care to tell us what is the version?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;DIV id="profile-userpic" class="span2"&gt;&lt;/DIV&gt;
&lt;DIV id="profile-user-header"&gt;
&lt;DIV id="profile-user-membership"&gt;
&lt;H1 class="fullname"&gt;&lt;/H1&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Aug 2016 20:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951270#M150478</guid>
      <dc:creator>ccorreap</dc:creator>
      <dc:date>2016-08-25T20:09:16Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951271#M150479</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The ASA Version is 9.4(2)11.&lt;/P&gt;
&lt;P&gt;About twice NAT, so the first NAT is 10.241.2.11 ---&amp;gt; 139.254.10.84 and then the second NAT is from 139.254.10.84 ---&amp;gt; 10.241.2.11, is this correct?&lt;/P&gt;
&lt;P&gt;If I do a twice NAT, what configuration do I need to do?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 01:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951271#M150479</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2016-08-26T01:41:25Z</dc:date>
    </item>
    <item>
      <title>Hello Arie,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951272#M150480</link>
      <description>&lt;P&gt;Hello Arie,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A twice NAT, basically speaking would change both the source AND destination of the packet for example:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Original Pkt: Src:10.241.2.2 // Dst:139.254.10.84&lt;/P&gt;
&lt;P&gt;NATed Pkt:&amp;nbsp;&amp;nbsp; Src: ASA "inside interface IP" // Dst: 10.241.2.11&lt;/P&gt;
&lt;P&gt;The source change is necessary as this type of scenarios generally cause asymmetric routing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In this case and if I understand correctly both the Client and the server would be located behind the inside interface; so the command "same-security-traffic permit intrainterface" is required as the traffic would be coming in and out the same interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hence the NAT would look something like this:&lt;/P&gt;
&lt;P&gt;object network obj-10.241.2.0_24&lt;/P&gt;
&lt;P&gt;subnet 10.241.2.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;object network obj-10.241.2.11&lt;/P&gt;
&lt;P&gt;host 10.241.2.11&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;object network obj-139.254.10.84&lt;/P&gt;
&lt;P&gt;host 139.254.10.84&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;Nat (inside,inside) source dynamic obj-10.241.2.0_24 interface destination obj-139.254.10.84 obj-10.241.2.11&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;same-security-traffic permit intrainterface&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 16:58:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951272#M150480</guid>
      <dc:creator>ccorreap</dc:creator>
      <dc:date>2016-08-29T16:58:22Z</dc:date>
    </item>
    <item>
      <title>Hi ccorreap,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951273#M150481</link>
      <description>&lt;P&gt;Hi &lt;A href="https://supportforums.cisco.com/users/ccorreap" title="View user profile." class="username" lang="" about="/users/ccorreap" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;ccorreap&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;It's work! Thank you very much for your guidance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2016 03:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951273#M150481</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2016-08-31T03:09:07Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951274#M150482</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have implemented that configuration this morning and the afternoon I found out that the CPU utilization of ASA increase till 97%. Does that twice-NAT consume high CPU resource?&lt;/P&gt;
&lt;P&gt;I have removed the configuration to see the CPU utilization and I found out the CPU utilization about 27%.&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2016 09:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951274#M150482</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2016-08-31T09:05:15Z</dc:date>
    </item>
    <item>
      <title>Hi Arie,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951275#M150483</link>
      <description>&lt;P&gt;Hi Arie,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are you currently having the high CPU with the config in place? U turning can cause high CPU, but that would depend on what type of inspections is the ASA doing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let me know,&lt;/P&gt;
&lt;P&gt;Carlos&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2016 21:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951275#M150483</guid>
      <dc:creator>ccorreap</dc:creator>
      <dc:date>2016-08-31T21:16:52Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951276#M150484</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, I'm having the high CPU with the config in place. When I delete the config, it becomes normal.&lt;/P&gt;
&lt;P&gt;I use the default inspection in the ASA:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/inspection1.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/inspection2.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/inspection3.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2016 02:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-address-translation-on-asa/m-p/2951276#M150484</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2016-09-01T02:39:41Z</dc:date>
    </item>
  </channel>
</rss>

