<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844335#M160127</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your answer! It could be a good solution, let me try it and come back with feedback.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2016 13:01:25 GMT</pubDate>
    <dc:creator>ciscolunero</dc:creator>
    <dc:date>2016-02-01T13:01:25Z</dc:date>
    <item>
      <title>TWICE NAT CONFIGURATION</title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844333#M160106</link>
      <description>&lt;P style="text-autospace: none;"&gt;Hi,&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;I have an issue with my CISCO ASA. I need to publish some ports to one server in my DMZ subnet (80, 555 and two range ports (TCP 20100-21999 and UDP 20100-21999) I dont know what I´m doing wrong with the range ports but NAT is not working. For 80 and 555 ports I have used Network Object NAT and it works perfectly. However, I cant do the same with the range ports, so I have to use 'standard NAT'&amp;nbsp; rules, and its not working.&amp;nbsp; I have even tried to remove network object nat rules and use&amp;nbsp; 'standard NAT' for 80 and 555 tcp ports as well. But if do this, 80 and 555 stop working.&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;Any clues?&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;Many, many thanks in advance.&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;: Serial Number: JAD19220344&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;: Hardware: ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;:&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ASA Version 9.4(1)&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;hostname ciscoasa&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;enable password WmlxhdtfAnw9XbcA encrypted&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;passwd ta.qizy4R//ChqQH encrypted&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;names&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ip local pool Pool_139 139.16.1.50-139.16.1.80 mask 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ip local pool Pool_172 172.16.1.100-172.16.1.130 mask 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nameif outside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;security-level 0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ip address 192.168.1.100 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/2&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nameif inside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;security-level 100&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ip address 139.16.1.1 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/3&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nameif DMZ&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;security-level 50&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ip address 172.16.1.1 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/4&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;shutdown&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no nameif&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no security-level&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no ip address&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;shutdown&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no nameif&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no security-level&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no ip address&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/6&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;shutdown&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no nameif&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no security-level&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no ip address&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/7&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;shutdown&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no nameif&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no security-level&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no ip address&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface GigabitEthernet1/8&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;shutdown&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no nameif&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no security-level&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no ip address&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;interface Management1/1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;management-only&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nameif management&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;security-level 100&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ip address 11.11.11.11 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ftp mode passive&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;clock timezone CEST 1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;clock summer-time CEDT recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network obj_any&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network inside-subnet&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;subnet 139.16.1.0 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network dmz-subnet&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;subnet 172.16.1.0 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network wialon-server-external-ip&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;host 192.168.1.132&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network wialon-server&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;host 172.16.1.69&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object service Wialon-services-TCP&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service tcp source range 20100 21999 destination range 20100 21999&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object service Wialon-services-UDP&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service udp source range 20100 21999 destination range 20100 21999&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network NETWORK_OBJ_139.16.1.0_25&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;subnet 139.16.1.0 255.255.255.128&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network wialon-server-ssl&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;host 172.16.1.69&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object service wialon-ssl&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service tcp source range 1 65535 destination eq 555&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object-group service DM_INLINE_SERVICE_1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service-object tcp destination eq www&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service-object udp destination eq domain&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service-object tcp destination eq https&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-list outside_acl extended permit tcp any object wialon-server eq www&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-list outside_acl extended permit object Wialon-services-TCP any object wialon-server&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-list outside_acl extended permit object Wialon-services-UDP any object wialon-server&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-list outside_acl extended permit object wialon-ssl any object wialon-server&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-list DMZ_access_in extended permit ip object wialon-server 139.16.1.0 255.255.255.0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-list DMZ_access_in extended permit object-group DM_INLINE_SERVICE_1 any any&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;pager lines 24&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;logging asdm informational&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;mtu outside 1500&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;mtu inside 1500&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;mtu DMZ 1500&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;mtu management 1500&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no asdm history enable&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;arp timeout 14400&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no arp permit-nonconnected&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nat (DMZ,outside) source static any any destination static NETWORK_OBJ_139.16.1.0_25 NETWORK_OBJ_139.16.1.0_25 route-lookup&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nat (DMZ,outside) source static wialon-server wialon-server-external-ip service Wialon-services-TCP Wialon-services-TCP&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network obj_any&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nat (any,outside) dynamic interface&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network inside-subnet&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nat (inside,outside) dynamic interface&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network wialon-server&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nat (DMZ,outside) static wialon-server-external-ip service tcp www www&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;object network wialon-server-ssl&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;nat (DMZ,outside) static wialon-server-external-ip service tcp 555 555&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-group outside_acl in interface outside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout xlate 3:00:00&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout pat-xlate 0:00:30&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;timeout floating-conn 0:00:00&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;user-identity default-domain LOCAL&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;http server enable&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;http 11.11.11.0 255.255.255.0 management&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;http 139.16.1.0 255.255.255.0 inside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no snmp-server location&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no snmp-server contact&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service sw-reset-button&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp encryption des&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp integrity sha-1 md5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp encryption 3des&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp integrity sha-1 md5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp encryption aes&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp integrity sha-1 md5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp encryption aes-192&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp integrity sha-1 md5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp encryption aes-256&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;protocol esp integrity sha-1 md5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto map outside_map interface outside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;enrollment self&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;fqdn ciscoasa.xxxxxx.null&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;email xxxx@gmail.com&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;subject-name CN=xxxxxx&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;serial-number&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;proxy-ldc-issuer&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crl configure&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;enrollment self&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;fqdn none&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;subject-name CN=139.16.1.1,CN=ciscoasa&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;keypair ASDM_LAUNCHER&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crl configure&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ca trustpool policy&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ca certificate chain ASDM_TrustPoint0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;certificate 09836256&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;30820381 30820269 a0030201 02020409 83625630 0d06092a 864886f7 0d010105&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;05003050 31123010 06035504 03130973 72646f6e 6761746f 313a3012 06035504&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;05130b4a 41443139 32323033 34343024 06092a86 4886f70d 01090216 17636973&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;636f6173 612e7372 646f6e67 61746f2e 6e756c6c 301e170d 31353132 30353036&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;33333535 5a170d32 35313230 32303633 3335355a 30503112 30100603 55040313&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;09737264 6f6e6761 746f313a 30120603 55040513 0b4a4144 31393232 30333434&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;30240609 2a864886 f70d0109 02161763 6973636f 6173612e 7372646f 6e676174&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;6f2e6e75 6c6c3082 0122300d 06092a86 4886f70d 01010105 00038201 0f003082&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;010a0282 010100d2 295e679c 153e8b6a d3f6131d 8ea646e3 aa0a5fa9 20e49259&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ca895563 7e818047 033a4e8f 57f619e9 fa93bfd5 6c44141f b0abf2c0 8b86334e&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;bac63f41 99e6d676 c689dcf7 080f2715 038a8e1b 694a00de 7124565e a1948f09&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;8dbeffab c7c8a028 741c5b10 d0ede5e9 599f38fe 5b88f678 4decdc4b 353b6708&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;cfa2fbce f58be06e 18feba56 4b2b04a1 77773ec6 5c58d2ed d7ca4f17 980f0353&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;138bfe65 1b1165e6 7b6f94bb ab4d4286 e900178c 147a6dba 2427f38e e225030f&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;0a66d1eb 5075c57e 6d77e5bb 247f5bc3 8d3530f0 49dedf2d 21a24b5f daa08d98&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;690183cf e82a6b8d 5e489956 c5eecdbc 7fc2365c b629a52b 126b51e2 18590ed5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;c9da8503 a639f102 03010001 a3633061 300f0603 551d1301 01ff0405 30030101&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ff300e06 03551d0f 0101ff04 04030201 86301f06 03551d23 04183016 80143468&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dec79103 0a91b530 1ada7e47 7e27b16d 4186301d 0603551d 0e041604 143468de&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;c791030a 91b5301a da7e477e 27b16d41 86300d06 092a8648 86f70d01 01050500&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;03820101 003cdb04 8ef5ed31 c05c684b ad2b0062 96bfd39a ecb0a3fe 547aebe5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;14b753e7 89f55827 3d4e0aa8 b8674e45 80d4c023 8e99a7b4 0907d347 060a2fe4&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;fa6e0c2f 3b9cd708 a539c09f 7022d2ee fb6e2cf6 82b0e861 a2839a71 1512b3ec&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;e28664e9 732270c9 d1c679d9 1eaf2ad5 007b5699 31c3ff97 09aae869 88677a3d&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ecb3032e 2dd0f74f 81f9a8fb 79f30809 723bbdbf dfef4154 5ad6b012 a8f37093&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;481fa678 23390036 b44b0290 042828f3 5eefdc43 78934455 ebe52d26 9b4234a9&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;bfeebc43 731c4146 166e5adc b431f12f 8d0fbf16 46306228 34d76984 d2e6ebbc&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;96838694 88ca120a d4f32884 963e7385 987ec6b0 dfa28d49 05ba5fa8 641bcfc7&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ff92ac3c 52&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;quit&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;certificate 0a836256&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;308202cc 308201b4 a0030201 0202040a 83625630 0d06092a 864886f7 0d010105&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;05003028 3111300f 06035504 03130863 6973636f 61736131 13301106 03550403&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;130a3133 392e3136 2e312e31 301e170d 31353132 30353036 35363236 5a170d32&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;35313230 32303635 3632365a 30283111 300f0603 55040313 08636973 636f6173&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;61311330 11060355 0403130a 3133392e 31362e31 2e313082 0122300d 06092a86&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;4886f70d 01010105 00038201 0f003082 010a0282 010100e7 a5c16e86 16c15a10&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;e018b868 bac7271a 30f1a3f8 ecb9c6b8 3ed4b1ad c9468f5e 287f2a7a 644f1496&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;c43a061e da927d09 a755b53e ed7c6a66 f2f1fb1e f944345c 86e08ce0 891c99b3&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;13101ab3 04963fad f91f987f 99f22a89 cd1e8c5a 5e4c026d 2cadd7b7 6620bbd1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;b4a5135b 24ec886f fa061a06 dd536e96 1e483730 756c4101 23f83a8d 944a7fbe&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;93c51d56 32ac0d17 ceb75f63 0ae24f07 f2c54e83 5b84ff00 16b0b899 c925c737&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;1765b066 23b54645 bc419684 d09dd130 c1479949 68b0a779 df39b078 6fb0deb9&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;758b14c3 f0801faf f0ad60e1 a018ffba d769f867 3fe8e5fc 88ccc5b2 2319f5d4&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;617a78c4 74e7a64b 5c68276c 06ea57c1 d0ffce4b 358c4d02 03010001 300d0609&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;2a864886 f70d0101 05050003 82010100 dff97c9f 4256fd47 8eb661fd d22ecea4&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;589eff09 958e01f1 a435a20e 5ed1cf19 af42e54d d61fc0ab cb2ee7ac 7fcb4513&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;1a44cc86 1e020d72 3a3f78d2 4d225177 857093d9 f5fcf3c7 6e656d2b 54a0c522&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;f636b8cf 33c5ae34 ea340f32 85dff4c1 50165e7a e94de10b ced15752 0b3a76c1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;20291106 2a50777b a1a8a214 8a003716 680c15d4 ac3f7cc7 378f8f5f 38e3403f&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;f958c095 e549c8ed 4baf8cc5 bdcd230e 260754ea 953c3a4c eb01fef5 62b97e01&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;9f82ce6b f479dbdd 000c45af 8758b35f b4a958ee 32c4db3f 2ddc7385 dc05b0e3&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;78b609ba a9280841 2433ae87 5dd7a7c2 d5691068 1dc0eddc c23f99c5 3df8b1a5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;aadbd82a 423f4ba8 563142bf 742771c3&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;quit&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ikev2 policy 1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;encryption aes-256&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;integrity sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group 5 2&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;prf sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;lifetime seconds 86400&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ikev2 policy 10&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;encryption aes-192&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;integrity sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group 5 2&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;prf sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;lifetime seconds 86400&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ikev2 policy 20&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;encryption aes&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;integrity sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group 5 2&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;prf sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;lifetime seconds 86400&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ikev2 policy 30&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;encryption 3des&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;integrity sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group 5 2&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;prf sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;lifetime seconds 86400&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ikev2 policy 40&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;encryption des&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;integrity sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group 5 2&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;prf sha&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;lifetime seconds 86400&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ikev2 enable outside client-services port 443&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;telnet 139.16.1.0 255.255.255.0 inside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;telnet 11.11.11.0 255.255.255.0 management&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;telnet timeout 5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no ssh stricthostkeycheck&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ssh timeout 5&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;console timeout 0&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dhcpd auto_config outside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dhcpd address 172.16.1.69-172.16.1.69 DMZ&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dhcpd dns 87.216.1.65 87.216.1.66 interface DMZ&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dhcpd option 3 ip 172.16.1.1 interface DMZ&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dhcpd enable DMZ&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;threat-detection basic-threat&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;threat-detection statistics access-list&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_0 outside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_0 inside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_0 inside vpnlb-ip&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;webvpn&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;enable outside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;enable inside&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;enable DMZ&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;anyconnect image disk0:/anyconnect-win-3.1.12020-k9.pkg 1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;anyconnect profiles Wialon_client_profile disk0:/Wialon_client_profile.xml&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;anyconnect enable&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;tunnel-group-list enable&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;error-recovery disable&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group-policy GroupPolicy_Wialon internal&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group-policy GroupPolicy_Wialon attributes&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;wins-server none&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dns-server value 192.168.1.1&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;vpn-tunnel-protocol ikev2 ssl-client ssl-clientless&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;default-domain none&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;webvpn&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;anyconnect profiles value Wialon_client_profile type user&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;username wialon_1 password Wy2aFpAQTXQavfJD encrypted&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service-type remote-access&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;tunnel-group Wialon type remote-access&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;tunnel-group Wialon general-attributes&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;address-pool Pool_139&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;default-group-policy GroupPolicy_Wialon&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;tunnel-group Wialon webvpn-attributes&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;group-alias Wialon enable&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;class-map inspection_default&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;match default-inspection-traffic&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;parameters&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;message-length maximum client auto&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;message-length maximum 512&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;policy-map global_policy&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;class inspection_default&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect dns preset_dns_map&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect ftp&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect h323 h225&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect h323 ras&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect rsh&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect rtsp&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect esmtp&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect sqlnet&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect skinny&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect sunrpc&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect xdmcp&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect sip&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect netbios&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect tftp&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;inspect ip-options&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;!&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;service-policy global_policy global&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;prompt hostname context&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;no call-home reporting anonymous&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;Cryptochecksum:0cc4df99103b3939601f2604ddda8585&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;: end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844333#M160106</guid>
      <dc:creator>ciscolunero</dc:creator>
      <dc:date>2019-03-12T07:13:20Z</dc:date>
    </item>
    <item>
      <title>Could you not just do a 1:1</title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844334#M160115</link>
      <description>&lt;P&gt;Could you not just do a 1:1 NAT and use the access-list to control what ports are allowed in?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Something more like:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;object network wialon-server&lt;BR /&gt;&amp;nbsp; nat (DMZ,outside) static wialon-server-external-ip&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Feb 2016 10:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844334#M160115</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-02-01T10:40:55Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844335#M160127</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your answer! It could be a good solution, let me try it and come back with feedback.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 13:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844335#M160127</guid>
      <dc:creator>ciscolunero</dc:creator>
      <dc:date>2016-02-01T13:01:25Z</dc:date>
    </item>
    <item>
      <title>It works! Many Thanks!!  </title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844336#M160134</link>
      <description>&lt;P&gt;It works! Many Thanks!! &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 22:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-configuration/m-p/2844336#M160134</guid>
      <dc:creator>ciscolunero</dc:creator>
      <dc:date>2016-02-01T22:21:46Z</dc:date>
    </item>
  </channel>
</rss>

