<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Yes, it looks like they are in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909532#M154430</link>
    <description>&lt;P&gt;Yes, it looks like&amp;nbsp;they&amp;nbsp;are the mapped port numbers according to the syntax from the Cisco guide. Thanks for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;static &lt;/STRONG&gt;(&lt;EM class="cEmphasis" style="font-style: italic;"&gt;real_interface&lt;/EM&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;,&lt;/SPAN&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;mapped_interface&lt;/SPAN&gt;) &lt;BR /&gt;{&lt;B class="cBold"&gt;tcp&amp;nbsp;&lt;/B&gt;|&lt;B class="cBold"&gt;&amp;nbsp;udp&lt;/B&gt;}&lt;B class="cBold"&gt; &lt;/B&gt;{&lt;EM class="cEmphasis" style="font-style: italic;"&gt;mapped_ip&lt;/EM&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;B class="cBold"&gt;&amp;nbsp;interface&lt;/B&gt;}&lt;B class="cBold" style="font-weight: bold;"&gt; &lt;/B&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;mapped_port &lt;/SPAN&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;access-list&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;acl_name&lt;/SPAN&gt; [&lt;B class="cBold"&gt;dns&lt;/B&gt;]&lt;B class="cBold"&gt; &lt;/B&gt;[&lt;B class="cBold"&gt;norandomseq&lt;/B&gt;]&lt;B class="cBold"&gt; &lt;/B&gt;[[&lt;B class="cBold"&gt;tcp&lt;/B&gt;]&amp;nbsp;&lt;EM class="cEmphasis"&gt;tcp_max_conns&lt;/EM&gt; &lt;BR /&gt;[&lt;EM class="cEmphasis"&gt;emb_limit&lt;/EM&gt;]] [&lt;B class="cBold"&gt;udp&lt;/B&gt; &lt;EM class="cEmphasis"&gt;udp_max_conns&lt;/EM&gt;]&lt;/P&gt;</description>
    <pubDate>Mon, 02 May 2016 18:57:17 GMT</pubDate>
    <dc:creator>adityan404</dc:creator>
    <dc:date>2016-05-02T18:57:17Z</dc:date>
    <item>
      <title>NAT overlap</title>
      <link>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909528#M154425</link>
      <description>&lt;P&gt;object service inside-src-dest-port-9100&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; service tcp source eq 9100 destination range 0 65535&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;64 nat (inside,outside) source static OBJ-ipB OBJ-ipA destination static OBJGRP OBJGRP service inside-src-dest-port-9100 inside-src-dest-port-9100&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;65 nat (inside,outside) source static OBJ-ipC OBJ-ipA destination static OBJGRP OBJGRP service inside-src-dest-port-9100 inside-src-dest-port-9100&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;After configuring rule 65, why do I get the following warning. &lt;BR /&gt;WARNING: mapped-address ipA/9100-0 overlaps with existing static NAT in Section 1, rule 64.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can&amp;nbsp;anyone please&amp;nbsp;help explain the reason behind the warning message and what can be done to avoid it?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909528#M154425</guid>
      <dc:creator>adityan404</dc:creator>
      <dc:date>2019-03-12T07:40:17Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909529#M154426</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;The reason is that you can't have an overlap in the NAT statement when doing static NAT. Both OBJ-ipB and OBJ-ipC are being NATed to OBJ-ipA on tcp/9100, which is not allowed.&lt;/P&gt;
&lt;P&gt;Think of this; if a user is on the internet is connecting to the IP of OBJ-ipA on TCP/9100, which server should it be directed to OBJ-ipB or OBJ-ipC? There is no way to differentiate the two.&lt;/P&gt;
&lt;P&gt;To correct it you could either use another NATed IP on the outside, like OBJ-ipD, or you could NAT the port number. Then users coming from the outside that wants to connect to TCP/9100 on OBJ-ipB needs to connect to OBJ-ipA on TCP/9101.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;object service tcp-eq-9100&lt;BR /&gt;&amp;nbsp;service tcp source eq 9100&lt;BR /&gt;object service tcp-eq-9101&lt;BR /&gt; service tcp source eq 9101&lt;BR /&gt;&lt;BR /&gt;nat (inside,outside) source static OBJ-ipB OBJ-ipA destination static OBJGRP OBJGRP service tcp-eq-9100 tcp-eq-9101&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 19:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909529#M154426</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2016-04-26T19:49:13Z</dc:date>
    </item>
    <item>
      <title>I see. Well, these are the</title>
      <link>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909530#M154427</link>
      <description>&lt;P&gt;I see. Well, these are the original 8.2 NAT statements I was trying to convert to 9.4 code.&lt;/P&gt;
&lt;P&gt;static (inside,outside) tcp ipA 1025 access-list inside_nat_static_131 &lt;BR /&gt;static (inside,outside) tcp ipA 1026 access-list inside_nat_static_132&lt;/P&gt;
&lt;P&gt;Are 1025 and 1026 here the mapped port numbers?&lt;/P&gt;
&lt;P&gt;So would I be correct in modifying the NAT rules to:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="pln"&gt;nat &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;inside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;outside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; OBJ&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ipB OBJ&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ipA destination &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; OBJGRP OBJGRP service tcp&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;eq&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;9100&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; tcp&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;eq&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;1025&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lit"&gt;&lt;SPAN class="pln"&gt;nat &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;inside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;outside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; OBJ&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ipB OBJ&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ipA destination &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; OBJGRP OBJGRP service tcp&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;eq&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;9100&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; tcp&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;eq&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;1026&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 15:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909530#M154427</guid>
      <dc:creator>adityan404</dc:creator>
      <dc:date>2016-04-27T15:39:47Z</dc:date>
    </item>
    <item>
      <title>I'm not really sure about the</title>
      <link>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909531#M154428</link>
      <description>&lt;P&gt;I'm not really sure about the pre-8.3 syntax, but the other configuration looks correct.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2016 07:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909531#M154428</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2016-04-30T07:35:47Z</dc:date>
    </item>
    <item>
      <title>Yes, it looks like they are</title>
      <link>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909532#M154430</link>
      <description>&lt;P&gt;Yes, it looks like&amp;nbsp;they&amp;nbsp;are the mapped port numbers according to the syntax from the Cisco guide. Thanks for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;static &lt;/STRONG&gt;(&lt;EM class="cEmphasis" style="font-style: italic;"&gt;real_interface&lt;/EM&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;,&lt;/SPAN&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;mapped_interface&lt;/SPAN&gt;) &lt;BR /&gt;{&lt;B class="cBold"&gt;tcp&amp;nbsp;&lt;/B&gt;|&lt;B class="cBold"&gt;&amp;nbsp;udp&lt;/B&gt;}&lt;B class="cBold"&gt; &lt;/B&gt;{&lt;EM class="cEmphasis" style="font-style: italic;"&gt;mapped_ip&lt;/EM&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;B class="cBold"&gt;&amp;nbsp;interface&lt;/B&gt;}&lt;B class="cBold" style="font-weight: bold;"&gt; &lt;/B&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;mapped_port &lt;/SPAN&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;access-list&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;acl_name&lt;/SPAN&gt; [&lt;B class="cBold"&gt;dns&lt;/B&gt;]&lt;B class="cBold"&gt; &lt;/B&gt;[&lt;B class="cBold"&gt;norandomseq&lt;/B&gt;]&lt;B class="cBold"&gt; &lt;/B&gt;[[&lt;B class="cBold"&gt;tcp&lt;/B&gt;]&amp;nbsp;&lt;EM class="cEmphasis"&gt;tcp_max_conns&lt;/EM&gt; &lt;BR /&gt;[&lt;EM class="cEmphasis"&gt;emb_limit&lt;/EM&gt;]] [&lt;B class="cBold"&gt;udp&lt;/B&gt; &lt;EM class="cEmphasis"&gt;udp_max_conns&lt;/EM&gt;]&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 18:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-overlap/m-p/2909532#M154430</guid>
      <dc:creator>adityan404</dc:creator>
      <dc:date>2016-05-02T18:57:17Z</dc:date>
    </item>
  </channel>
</rss>

