<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Christian, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954679#M161391</link>
    <description>&lt;P&gt;Hi Christian,&lt;/P&gt;
&lt;P&gt;This command worked without destination any any.&lt;/P&gt;
&lt;P&gt;Can you let me know why the&amp;nbsp;&lt;SPAN&gt;destination any any wasn't included?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you said, "remember they are always bi-directional unless specified not to"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How can i make it unidirectional.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What happens when it is unidirectional?&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;GS id="addf65a9-0a76-4b32-aba8-1351435a8b05" ginger_software_uiphraseguid="9b9eee5a-acab-4e13-b1ba-5e50520dc8d0" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;&lt;GS id="fccb7a1c-7d28-4f9b-9642-b83ecd4155ec" ginger_software_uiphraseguid="9b9eee5a-acab-4e13-b1ba-5e50520dc8d0" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;GS id="63054473-4f9b-4cf8-a3d6-ca00bc52b278" ginger_software_uiphraseguid="9b9eee5a-acab-4e13-b1ba-5e50520dc8d0" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; service SOURCE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 05 Aug 2016 06:27:10 GMT</pubDate>
    <dc:creator>diwakar410</dc:creator>
    <dc:date>2016-08-05T06:27:10Z</dc:date>
    <item>
      <title>Auto Nat and Manual Nat in cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954669#M161367</link>
      <description>&lt;P&gt;I have a public IP of&amp;nbsp;201.202.203.204.&lt;/P&gt;
&lt;P&gt;And then, &lt;G class="gr_ gr_20 gr-alert gr_tiny gr_spell gr_run_anim ContextualSpelling multiReplace" id="20" data-gr-id="20"&gt;i&lt;/G&gt; have &lt;GS id="749f91dd-6c98-4d23-8431-e4586b9f54b5" ginger_software_uiphraseguid="e38883d1-3266-4b01-93d8-8d0ccf712ad1" class="GINGER_SOFTWARE_mark"&gt;pool IP&lt;/GS&gt; of 205.206.207.208 which is &lt;GS id="80908e85-3f22-4f67-8179-b8796727cd25" ginger_software_uiphraseguid="e38883d1-3266-4b01-93d8-8d0ccf712ad1" class="GINGER_SOFTWARE_mark"&gt;routable&lt;/GS&gt; to&amp;nbsp;&lt;SPAN&gt;201.202.203.204.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have a service running on my server which opens locally on&amp;nbsp;port 3456. &lt;GS id="f9f7547f-8fb6-48d2-be0a-a88c9319f6af" ginger_software_uiphraseguid="1d778a63-1e09-447c-a350-44ab96c11c08" class="GINGER_SOFTWARE_mark"&gt;ie&lt;/GS&gt;, &lt;G class="gr_ gr_22 gr-alert gr_tiny gr_spell gr_run_anim ContextualSpelling multiReplace" id="22" data-gr-id="22"&gt;i&lt;/G&gt; get the access of server from inside network using 172.16.32.45:3456.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I want this service to be opened from outside &lt;GS id="4585f0d2-7b9e-4171-97b7-7821089fe5f3" ginger_software_uiphraseguid="b838607b-5f62-4944-b1bd-44220fd68233" class="GINGER_SOFTWARE_mark"&gt;too and&lt;/GS&gt; for &lt;G class="gr_ gr_24 gr-alert gr_gramm gr_run_anim Punctuation only-ins replaceWithoutSep" id="24" data-gr-id="24"&gt;this&lt;/G&gt; we need to do the port forwarding. I want this service to be opened on port 7890 &lt;GS id="a2b1f216-4988-4211-9523-3b66baa582e1" ginger_software_uiphraseguid="3dddf732-b77e-4a76-8d69-e8da112282d8" class="GINGER_SOFTWARE_mark"&gt;ie&lt;/GS&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;G class="gr_ gr_27 gr-alert gr_tiny gr_spell gr_run_anim ContextualSpelling multiReplace" id="27" data-gr-id="27"&gt;i&lt;/G&gt; want to be accessed from outside using&amp;nbsp;205.206.207.208:7890.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How can &lt;G class="gr_ gr_19 gr-alert gr_tiny gr_spell gr_run_anim ContextualSpelling multiReplace" id="19" data-gr-id="19"&gt;i&lt;/G&gt; achieve this using:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;GS id="0bf12171-9fcd-457e-ac52-b09071c3b035" ginger_software_uiphraseguid="4ebb6afe-1c74-4d66-8f6f-7516daae1101" class="GINGER_SOFTWARE_mark"&gt;1.&lt;/GS&gt;Auto NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;GS id="e36b254e-fe3b-473a-b2d8-b41754ae7b7d" ginger_software_uiphraseguid="9ff680f6-0e7d-4f30-8f72-f0307f479928" class="GINGER_SOFTWARE_mark"&gt;2.&lt;/GS&gt;Manual NAT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I had asked this type of question &lt;GS id="69d4fdf0-f02b-4c34-8314-5e5d25e16068" ginger_software_uiphraseguid="6d6c06c5-8521-447f-856e-7a56211b0b92" class="GINGER_SOFTWARE_mark"&gt;before but&lt;/GS&gt; it was regarding it was regarding manual NAT. I want to know the clear difference between them and please specify the ports to be used as source/destination.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help me with the command lines.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954669#M161367</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2019-03-12T08:03:14Z</dc:date>
    </item>
    <item>
      <title>Here is something to get you</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954670#M161370</link>
      <description>&lt;P&gt;Here is something to get you started: (I hope i understood you correctly).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object network PUBLIC-IP&lt;BR /&gt; host 201.202.203.204&lt;/P&gt;
&lt;P&gt;object network IP-POOL&lt;BR /&gt; host 205.206.207.208&lt;/P&gt;
&lt;P&gt;object service DESTINATION-TCP-3456&lt;BR /&gt; service tcp destination eq 3456&lt;/P&gt;
&lt;P&gt;object service DESTINATION-TCP-7890&lt;BR /&gt; service tcp destination eq 7890&lt;/P&gt;
&lt;P&gt;nat (OUTSIDE,INSIDE) source static any any destination static PUBLIC-IP IP-POOL service DESTINATION-TCP-7890 DESTINATION-TCP-3456&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Cristian&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 10:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954670#M161370</guid>
      <dc:creator>Cristian Nilsson</dc:creator>
      <dc:date>2016-07-28T10:54:39Z</dc:date>
    </item>
    <item>
      <title>Hello there,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954671#M161372</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;
&lt;P&gt;I don't know if this command works or not. Haven't tried it.&lt;/P&gt;
&lt;P&gt;&lt;GS id="cf4ba5cc-0385-4e65-8d67-aac112eb07fb" ginger_software_uiphraseguid="df1fe785-f75a-4dd8-8669-5296401ccfa1" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; (OUTSIDE&lt;GS id="e23d77d3-2800-480b-9065-b33d2b4d3ed3" ginger_software_uiphraseguid="df1fe785-f75a-4dd8-8669-5296401ccfa1" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;INSIDE) source static any any destination static PUBLIC-IP IP-POOL service DESTINATION-TCP-7890 DESTINATION-TCP-3456&lt;/P&gt;
&lt;P&gt;I used to do manual NAT this way:&lt;/P&gt;
&lt;P&gt;&lt;GS id="abb9eb2d-37dd-46f1-b7f0-4fc04f16ab64" ginger_software_uiphraseguid="3e980690-dbaf-4957-95cd-0c3ebda5685a" class="GINGER_SOFTWARE_mark"&gt;object network&lt;/GS&gt; &lt;GS id="6b7414c3-5f4f-4f74-93c7-d16cff9891c5" ginger_software_uiphraseguid="3e980690-dbaf-4957-95cd-0c3ebda5685a" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;-&lt;SPAN&gt;172.16.32.45&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;GS id="a542ebad-ee3f-4aae-9b8b-3110c252ebdd" ginger_software_uiphraseguid="b89d36a7-0d3a-479e-bc93-38948f22b466" class="GINGER_SOFTWARE_mark"&gt;host&lt;/GS&gt;&amp;nbsp;172.16.32.45&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;GS id="1bca58b5-dd65-4916-92ea-a5cf209de453" ginger_software_uiphraseguid="8ad8c5fa-1c60-4f62-9e44-e79181ff84c4" class="GINGER_SOFTWARE_mark"&gt;bject&lt;/GS&gt; network PUBLIC-IP&lt;BR /&gt;&lt;GS id="eb14a6f1-6d00-4f03-b906-dd5ade0e233f" ginger_software_uiphraseguid="c039c26c-bb80-4f79-bfd7-9fcab5769a9d" class="GINGER_SOFTWARE_mark"&gt;host&lt;/GS&gt; 201.202.203.204&lt;/P&gt;
&lt;P&gt;&lt;GS id="2feff9d3-21d4-42d1-ad39-0d224e3d6359" ginger_software_uiphraseguid="9d07c788-15d7-48a8-a58d-9a081cb33c24" class="GINGER_SOFTWARE_mark"&gt;object&lt;/GS&gt; network IP-POOL&lt;BR /&gt;&lt;GS id="29443b23-5127-4969-a882-7430321c9ba1" ginger_software_uiphraseguid="e56aa41e-b9f5-4793-89c0-0ba9cba4ebfc" class="GINGER_SOFTWARE_mark"&gt;host&lt;/GS&gt; 205.206.207.208&lt;/P&gt;
&lt;P&gt;object service SOURCE-TCP-3456&lt;BR /&gt;&lt;GS id="d10f58d1-1ea4-4e39-89e6-b66ee67bc9fa" ginger_software_uiphraseguid="83385334-a6cb-44e9-93ad-a5f2b205ac62" class="GINGER_SOFTWARE_mark"&gt;service&lt;/GS&gt; &lt;GS id="6fe51032-702b-474f-afff-6e45c6a97717" ginger_software_uiphraseguid="83385334-a6cb-44e9-93ad-a5f2b205ac62" class="GINGER_SOFTWARE_mark"&gt;tcp&lt;/GS&gt;&amp;nbsp;source&amp;nbsp;&lt;GS id="15d3e28b-ae98-426d-9613-9db3278d9d31" ginger_software_uiphraseguid="83385334-a6cb-44e9-93ad-a5f2b205ac62" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 3456&lt;/P&gt;
&lt;P&gt;&lt;GS id="71803135-60b6-4d17-b87c-5a0bee2640d3" ginger_software_uiphraseguid="6fa855e1-d4e2-4a66-966a-79590eda2d55" class="GINGER_SOFTWARE_mark"&gt;object&lt;/GS&gt; service DESTINATION-TCP-7890&lt;BR /&gt;&lt;GS id="3458b7e3-a2f0-4ae4-9c78-484ee237449b" ginger_software_uiphraseguid="a94baaf1-2990-4f2b-a02a-4a13a6d5b368" class="GINGER_SOFTWARE_mark"&gt;service&lt;/GS&gt; &lt;GS id="70c8d380-9859-4a6b-b5c9-70c36079b09b" ginger_software_uiphraseguid="a94baaf1-2990-4f2b-a02a-4a13a6d5b368" class="GINGER_SOFTWARE_mark"&gt;tcp&lt;/GS&gt; destination &lt;GS id="ee947e27-5f26-4fb0-83e9-feb592d49773" ginger_software_uiphraseguid="a94baaf1-2990-4f2b-a02a-4a13a6d5b368" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 7890&lt;/P&gt;
&lt;P&gt;&lt;GS id="a9ff4383-03b0-4b6f-90f6-ab7a32d690a4" ginger_software_uiphraseguid="857021cb-872f-464d-a767-39901e2ac71d" class="GINGER_SOFTWARE_mark"&gt;and&lt;/GS&gt; the command would be:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nat(inside,outside)&amp;nbsp;source&amp;nbsp;static &amp;nbsp;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;obj&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;172.16.32.45&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;IP-POOL service SOURCE-TCP-3456&amp;nbsp;DESTINATION-TCP-7890&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I believe port 3456 should be &lt;GS id="2dd15a2a-8b2e-4eaf-ac89-a951d6d181b9" ginger_software_uiphraseguid="884dba1d-e221-43da-9a21-ea9f780c9c9c" class="GINGER_SOFTWARE_mark"&gt;source&lt;/GS&gt;, isn't it?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is manual NAT.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How can the same thing be achieved using auto NAT?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If possible, please &lt;GS id="36e83b34-c94e-4614-b6bc-3c0583049345" ginger_software_uiphraseguid="fd7871da-0fe7-464b-9e40-3c1da25372b5" class="GINGER_SOFTWARE_mark"&gt;clearify&lt;/GS&gt; this command line&lt;GS id="9d9cdde5-c918-4116-a29a-379f8270d846" ginger_software_uiphraseguid="fd7871da-0fe7-464b-9e40-3c1da25372b5" class="GINGER_SOFTWARE_mark"&gt; :&lt;/GS&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;GS id="091ae4ac-6796-495d-a382-ddcd24e512cf" ginger_software_uiphraseguid="1e4cff15-7c49-46d9-bc63-66168692f294" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt;&lt;/SPAN&gt;&lt;SPAN&gt; (OUTSIDE&lt;/SPAN&gt;&lt;SPAN&gt;&lt;GS id="057718f9-b6fd-43e4-b4fd-1ff2282ea787" ginger_software_uiphraseguid="1e4cff15-7c49-46d9-bc63-66168692f294" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;&lt;/SPAN&gt;&lt;SPAN&gt;INSIDE) source static any any destination static PUBLIC-IP IP-POOL service DESTINATION-TCP-7890 DESTINATION-TCP-3456&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 04:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954671#M161372</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2016-07-30T04:27:22Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954672#M161374</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I never use auto-nat myself but this should be the correct NAT rule:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;object network obj-172.16.32.45&lt;BR /&gt;&amp;nbsp;nat (INSIDE,OUTSIDE) static IP-POOL service tcp 3456 7890&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regarding manual-nat you have the wrong idea about source and destination.&lt;/P&gt;
&lt;P&gt;You have to think of it in&amp;nbsp;nat rule direction - and keep in mind its always both ways unless specefied not to be.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;nat (OUTSIDE,INSIDE) source static any any destination static PUBLIC-IP IP-POOL service DESTINATION-TCP-7890 DESTINATION-TCP-3456&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could have been writen as:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;nat (INSIDE,OUTSIDE) source static&amp;nbsp;IP-&lt;SPAN&gt;POOL&amp;nbsp;PUBLIC-IP service SOURCE-TCP-3456 SOURCE-TCP-7890 destination any any&amp;nbsp;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I hope i´m not confusing you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;//Cristian&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 06:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954672#M161374</guid>
      <dc:creator>Cristian Nilsson</dc:creator>
      <dc:date>2016-08-02T06:06:20Z</dc:date>
    </item>
    <item>
      <title>Hi Cristain, </title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954673#M161375</link>
      <description>&lt;P&gt;Hi &lt;GS id="69d5377e-fef4-4f6d-9562-2f96ca08becb" ginger_software_uiphraseguid="962107bd-53c3-4468-a721-af3701675347" class="GINGER_SOFTWARE_mark"&gt;Cristain&lt;/GS&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Finally, &lt;GS id="2bd369eb-366a-4a7b-9e53-a70abaa7f40d" ginger_software_uiphraseguid="b310465f-4b59-4124-9602-d9a55705f54a" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; guess, &lt;GS id="e4aa3b1b-c105-4405-ac02-0e7beac93754" ginger_software_uiphraseguid="b310465f-4b59-4124-9602-d9a55705f54a" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; am trying to get the real meaning.&lt;/P&gt;
&lt;P&gt;Let me &lt;GS id="c50b45a9-3b82-47e9-8347-580d1c5b9f6e" ginger_software_uiphraseguid="3f0ca83f-5ac1-481b-98d6-bec3358d1b7b" class="GINGER_SOFTWARE_mark"&gt;ellaborate&lt;/GS&gt; what &lt;GS id="d84a7b1f-ac37-4298-ac8a-ee7615ddae66" ginger_software_uiphraseguid="3f0ca83f-5ac1-481b-98d6-bec3358d1b7b" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; understood.&lt;/P&gt;
&lt;P&gt;My WLC opens at port 80. I&amp;nbsp;want the request on 80 to be opened &lt;GS id="2561747f-016d-4934-90d9-b8e101dfea54" ginger_software_uiphraseguid="cbb80c59-55e4-4b36-9edb-187d618371a5" class="GINGER_SOFTWARE_mark"&gt;at&lt;/GS&gt; 8080 when someone accesses it from outside.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in &amp;nbsp;manual NAT:&lt;/P&gt;
&lt;P&gt;In this case, from what &lt;GS id="ee891da5-3539-46dd-8926-2ebea135d3f6" ginger_software_uiphraseguid="5b3318b1-d033-4c37-89db-339c13cea814" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; got from your help, when going to &lt;GS id="22df1492-42ac-4177-9e39-7771d2d32e03" ginger_software_uiphraseguid="5b3318b1-d033-4c37-89db-339c13cea814" class="GINGER_SOFTWARE_mark"&gt;internet&lt;/GS&gt; &lt;GS id="d7976c67-7081-4a3c-ae3f-aab6e27d2cb9" ginger_software_uiphraseguid="5b3318b1-d033-4c37-89db-339c13cea814" class="GINGER_SOFTWARE_mark"&gt;ie&lt;/GS&gt;,&amp;nbsp;inside to outside, my source port is 80 and destination port is still 80.&lt;/P&gt;
&lt;P&gt;But if someone tries to get in my WLC from remote side, &lt;GS id="25aab3c3-8c10-48c0-b5d9-7675ae8574b9" ginger_software_uiphraseguid="924c7097-0bf3-4047-bf02-48855829cf48" class="GINGER_SOFTWARE_mark"&gt;ie&lt;/GS&gt;,&amp;nbsp;outside to inside,&amp;nbsp;then for them 8080 becomes source and 80 becomes &lt;GS id="c46af5c7-ff58-42bc-a2d0-dbceac9d64d2" ginger_software_uiphraseguid="924c7097-0bf3-4047-bf02-48855829cf48" class="GINGER_SOFTWARE_mark"&gt;destination&lt;/GS&gt;.&lt;/P&gt;
&lt;P&gt;Am &lt;GS id="b2e4419b-a64a-4fcf-a2dc-304af6d656c4" ginger_software_uiphraseguid="84f5aaa5-d4d9-49fd-87bd-ecd8ba80d1a7" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; right?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 08:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954673#M161375</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2016-08-02T08:51:13Z</dc:date>
    </item>
    <item>
      <title>Hello again,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954674#M161379</link>
      <description>&lt;P&gt;Hello again,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You are correct.&lt;/P&gt;
&lt;P&gt;But to help you a bit more, think of the NAT (depending on direction nat rule is) from the source perspective.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;INSIDE &amp;gt; OUTSIDE, inside host perspective (deal with SOURCE IP/ports)&lt;/P&gt;
&lt;P&gt;OUTSIDE &amp;gt; INSIDE, outside host perspective (deal with DESTINATION IP/ports)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A quote from course leader regarding manual/twice-NAT-thinking:&lt;/P&gt;
&lt;P&gt;"REAL-NAT-NAT-REAL". This&amp;nbsp;has helped me many times when i started with NAT.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And i my opinion, manual NAT is much easier to read and get a quick view of.&lt;/P&gt;
&lt;P&gt;//Cristian&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2016 10:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954674#M161379</guid>
      <dc:creator>Cristian Nilsson</dc:creator>
      <dc:date>2016-08-02T10:01:53Z</dc:date>
    </item>
    <item>
      <title>Hi Christian,Thank you for</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954675#M161382</link>
      <description>&lt;P&gt;Hi Christian,&lt;BR /&gt;Thank you for your help so far. &lt;BR /&gt;Still not clear regarding some issues.&lt;BR /&gt;Today &lt;GS id="fd1f8b66-8c8c-470a-bbb2-ba91ce7649a1" ginger_software_uiphraseguid="8f3ec7dc-916e-4f4a-a43f-bacedec0776f" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; was asked to do the port forwarding in IP 192.168.10.100:3389 to be opened as 201.202.203.204:2234 for RDP.&lt;BR /&gt;As i am used to auto NAT,i did this:&lt;BR /&gt;object network obj-192.168.10.100&lt;BR /&gt;&lt;GS id="89c3ec12-dba7-4115-b777-2f4cd3fcb3be" ginger_software_uiphraseguid="4c7ae465-d82c-439e-b320-d44ff1029b16" class="GINGER_SOFTWARE_mark"&gt;host&lt;/GS&gt; 192.168.10.100&lt;BR /&gt;nat (private,public) static interface service tcp 3389 3334 &lt;BR /&gt;Then i had this access list:&lt;BR /&gt;&lt;GS id="001845c0-eef4-4b39-998a-34f99b4a19d9" ginger_software_uiphraseguid="57c9a8c1-78b1-4a54-9cd5-4db873486914" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list access-list-name extended permit tcp any host 11192.168.10.100 &lt;GS id="da5acd32-87b2-46c5-8bbb-77b911f929be" ginger_software_uiphraseguid="57c9a8c1-78b1-4a54-9cd5-4db873486914" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 3389 and it was fine. The port was &lt;BR /&gt;&lt;GS id="30d4ee06-1ed0-4337-97b7-acb41bcef23b" ginger_software_uiphraseguid="12da6b8c-8833-47b6-ae37-d39859902374" class="GINGER_SOFTWARE_mark"&gt;opened&lt;/GS&gt; and everything worked.&lt;BR /&gt;Later, &lt;GS id="6e056540-e367-4530-8c27-c1dee148d42d" ginger_software_uiphraseguid="d223c7fa-280a-4d32-b3b2-22dbadd9b560" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; decided to do this using manual NAT, using your help.&lt;BR /&gt;As per your command line, &lt;BR /&gt;&lt;GS id="c1a72975-a3cd-4efb-a0b1-ba977ff4b947" ginger_software_uiphraseguid="75baf29a-957f-4bba-a411-ff7585fee2db" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; (INSIDE&lt;GS id="d3115738-4f89-4152-a88c-1cacdc76c9f5" ginger_software_uiphraseguid="75baf29a-957f-4bba-a411-ff7585fee2db" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;OUTSIDE) source static IP-&lt;GS id="f0e88390-b12e-4d86-8aec-f2457d861fd1" ginger_software_uiphraseguid="75baf29a-957f-4bba-a411-ff7585fee2db" class="GINGER_SOFTWARE_mark"&gt;POOL PUBLIC&lt;/GS&gt;-IP service SOURCE-TCP-3456 SOURCE-TCP-7890 destination any any&lt;/P&gt;
&lt;P&gt;&lt;GS id="13e89d17-6260-4df3-aa0b-a8df9b196bcf" ginger_software_uiphraseguid="86c1da8f-77e2-455d-804b-370a54a91c3e" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; modified this way:&lt;BR /&gt;&lt;GS id="3061cde1-b64b-4150-9a9c-986c5b0b168a" ginger_software_uiphraseguid="1fe6cf62-d6d8-405d-9fb5-15ea0588e42c" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; (private&lt;GS id="96a22578-c3dc-4094-9da3-4c374dd73b93" ginger_software_uiphraseguid="1fe6cf62-d6d8-405d-9fb5-15ea0588e42c" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;public) source static &lt;GS id="e71b454a-73d0-49d4-97cf-4d9e0fb71941" ginger_software_uiphraseguid="1fe6cf62-d6d8-405d-9fb5-15ea0588e42c" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;-192.168.10.100 &lt;GS id="a4fbcb4a-6d5a-4bfd-b8f6-f9dd30b55ec9" ginger_software_uiphraseguid="1fe6cf62-d6d8-405d-9fb5-15ea0588e42c" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;-201.202.203.204 service SOURCE-TCP-3389 SOURCE-TCP-2234 destination any any &lt;BR /&gt;&lt;GS id="76592236-9e85-4af0-bf10-858998e266f5" ginger_software_uiphraseguid="e55349d2-7e10-42f3-9127-4fb2fa3f6214" class="GINGER_SOFTWARE_mark"&gt;and&lt;/GS&gt; &lt;GS id="1291b675-dd17-44fc-affd-57b86ecdaf1c" ginger_software_uiphraseguid="e55349d2-7e10-42f3-9127-4fb2fa3f6214" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; had &lt;GS id="7c3536e9-49be-4b45-a9f7-b1abd84576c7" ginger_software_uiphraseguid="e55349d2-7e10-42f3-9127-4fb2fa3f6214" class="GINGER_SOFTWARE_mark"&gt;this issues&lt;/GS&gt;:&lt;BR /&gt;1. &lt;GS id="b7696d21-1324-4202-81ee-7416bc53f274" ginger_software_uiphraseguid="8624db7c-1270-48e4-b9ee-4acd6ca1b92c" class="GINGER_SOFTWARE_mark"&gt;the&lt;/GS&gt; command after destination any any didn't work&lt;BR /&gt;2. &lt;GS id="e05ca8d2-1b57-481c-b079-6246db08716c" ginger_software_uiphraseguid="719afeb2-cf51-478f-a13a-ac21d331385f" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; removed command after destination any any then there was this error that &lt;GS id="cbc42324-c4fb-47ec-b36e-57fdcadfd5db" ginger_software_uiphraseguid="719afeb2-cf51-478f-a13a-ac21d331385f" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;-201.202.203.204 &lt;GS id="fa5e6c59-634e-4f50-a575-36ca3f95989e" ginger_software_uiphraseguid="719afeb2-cf51-478f-a13a-ac21d331385f" class="GINGER_SOFTWARE_mark"&gt;overlaps&lt;/GS&gt; with public IP.&lt;/P&gt;
&lt;P&gt;So &lt;GS id="21251d94-911c-4928-b515-4fedf237d632" ginger_software_uiphraseguid="6a84a03a-c73a-43de-9990-13a6b1d06ed0" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; used the second command&lt;GS id="ebda7c39-bcf7-4d65-8dca-306b6be10d18" ginger_software_uiphraseguid="6a84a03a-c73a-43de-9990-13a6b1d06ed0" class="GINGER_SOFTWARE_mark"&gt; :&lt;/GS&gt;&lt;BR /&gt;nat (OUTSIDE,INSIDE) source static any any destination static PUBLIC-IP IP-POOL service DESTINATION-TCP-7890 DESTINATION-TCP-3456&lt;BR /&gt;&lt;GS id="803a3a42-8e74-4698-b969-260fb1c396bb" ginger_software_uiphraseguid="323b63b7-6ca0-4b99-b475-ce1c10f81539" class="GINGER_SOFTWARE_mark"&gt;and&lt;/GS&gt; modified as:&lt;BR /&gt;&lt;GS id="cf34c68c-55ac-4243-8a2a-dd6ae29127bf" ginger_software_uiphraseguid="3ea494ec-8de4-470b-b78e-6d8115ef6f67" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; (OUTSIDE&lt;GS id="f64f3fc2-6ff1-4b19-81fc-3cb2377f4bc3" ginger_software_uiphraseguid="3ea494ec-8de4-470b-b78e-6d8115ef6f67" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;INSIDE) source static any any destination static &lt;GS id="9f5914b0-bec2-4635-ae19-96b3939314fc" ginger_software_uiphraseguid="3ea494ec-8de4-470b-b78e-6d8115ef6f67" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;-192.168.10.100 &lt;GS id="1efb69f5-818a-4600-9f15-5f91bc306b89" ginger_software_uiphraseguid="3ea494ec-8de4-470b-b78e-6d8115ef6f67" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;-201.202.203.204 service DESTINATION-TCP-2234 DESTINATION-TCP-3389&lt;/P&gt;
&lt;P&gt;&lt;GS id="d668e767-f322-43a3-afad-a3c79ec3cd02" ginger_software_uiphraseguid="419918da-ba83-4b5d-90c8-de6799ce4a89" class="GINGER_SOFTWARE_mark"&gt;then&lt;/GS&gt; the command was &lt;GS id="a6b5d8dc-b791-4ca4-922d-f5b23842fa90" ginger_software_uiphraseguid="419918da-ba83-4b5d-90c8-de6799ce4a89" class="GINGER_SOFTWARE_mark"&gt;accepted but&lt;/GS&gt; the port failed to open. &lt;BR /&gt;I tried using the packet tracer command and it indicated the port failed to open because &lt;GS id="76067e96-ebac-4d74-94a6-311319c5fb0c" ginger_software_uiphraseguid="45422a7e-0793-4cdb-8393-9f222dae975b" class="GINGER_SOFTWARE_mark"&gt;flow&lt;/GS&gt; was denied by the configured rule.&lt;BR /&gt;But there was already this command:&lt;BR /&gt;access-list access-list-name extended permit tcp any host 11192.168.10.100 eq 3389&lt;/P&gt;
&lt;P&gt;What could be the reason for that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it because &lt;GS id="95e1145c-9e06-42fe-86d5-b1ad0bcfbe20" ginger_software_uiphraseguid="313b2a50-b4c4-43ce-9dab-72315592bf6e" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; am using version 9.2?&lt;/P&gt;
&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 15:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954675#M161382</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2016-08-03T15:09:09Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954676#M161385</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You forgot destination STATIC any any, that is why command was rejected.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;nat (private,public) source static obj-192.168.10.100 obj-201.202.203.204 service SOURCE-TCP-3389 SOURCE-TCP-2234 destination any any &lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is reversed as you NAT&amp;nbsp;in direction private to public.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;nat &lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)&amp;nbsp;&lt;/SPAN&gt;source static any any destination static obj-192.168.10.100 obj-201.202.203.204 service DESTINATION-TCP-2234 DESTINATION-TCP-3389&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Try this&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;nat &lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)&amp;nbsp;&lt;/SPAN&gt;source static obj-192.168.10.100 obj-201.202.203.204 destination static any any service SOURCE-TCP-3389 SOURCE-TCP-2234&lt;/PRE&gt;
&lt;P&gt;Dont forget to create the service objects accordingly.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;//Cristian&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 16:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954676#M161385</guid>
      <dc:creator>Cristian Nilsson</dc:creator>
      <dc:date>2016-08-03T16:30:55Z</dc:date>
    </item>
    <item>
      <title>Hello Christian,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954677#M161387</link>
      <description>&lt;P&gt;Hello Christian,&lt;/P&gt;
&lt;P&gt;Thank you for your help. But there are some issues still not solved.&lt;/P&gt;
&lt;P&gt;According to your command:&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="pln"&gt;&lt;GS id="3ace5108-3ce0-48fb-a4ef-64256b12a95d" ginger_software_uiphraseguid="b58607d1-a447-40c3-a4c2-4a80db14631c" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; &lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;&lt;GS id="c81b904f-fa80-4933-b41b-c62234dfc837" ginger_software_uiphraseguid="b58607d1-a447-40c3-a4c2-4a80db14631c" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;source &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;GS id="520fa8e0-bfd5-43b8-a7ca-000af7da6d63" ginger_software_uiphraseguid="b58607d1-a447-40c3-a4c2-4a80db14631c" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;GS id="19587c5b-1ab0-46bf-bf43-c8cf6a1371f0" ginger_software_uiphraseguid="b58607d1-a447-40c3-a4c2-4a80db14631c" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;201.202&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;203.204&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; destination &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; any any service SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;I get this error:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ERROR: any doesn't match an existing object or object-group&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;GS id="affd1aa0-48bf-4764-ba4d-43282c70fae1" ginger_software_uiphraseguid="e5688cff-5c9a-42a1-9c6e-f23f8db39ffb" class="GINGER_SOFTWARE_mark"&gt;similarly&lt;/GS&gt;, using the first command:&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="pln"&gt;&lt;GS id="93f23918-5c7a-4839-9d9d-97f7394db9f8" ginger_software_uiphraseguid="b6ddd356-2e81-46e7-85ad-7d59b82af78c" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;&lt;GS id="e58e6c76-1a9b-44d0-8eb7-4518cecb83d6" ginger_software_uiphraseguid="b6ddd356-2e81-46e7-85ad-7d59b82af78c" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;&lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;GS id="eb120031-9737-49f8-b59f-e69086822b4f" ginger_software_uiphraseguid="b6ddd356-2e81-46e7-85ad-7d59b82af78c" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;GS id="146346c0-5c31-43fc-b1d1-376615b12da6" ginger_software_uiphraseguid="b6ddd356-2e81-46e7-85ad-7d59b82af78c" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;201.202&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;203.204&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; service SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; destination any any &lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;I get this error:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ERROR: Address 201.202.203.204 &lt;/STRONG&gt;&lt;GS id="c60a6efa-eb54-49b1-aa76-8940be039d0a" ginger_software_uiphraseguid="5fd8d36b-170a-48e8-b235-02703ea4bedd" class="GINGER_SOFTWARE_mark"&gt;overlaps&lt;/GS&gt;&lt;STRONG&gt; with Public-IP interface address.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ERROR: &lt;/STRONG&gt;&lt;GS id="1b0170dd-87a5-441a-9e3f-898f1f33d5e5" ginger_software_uiphraseguid="0bf8f230-c752-44ac-9ef3-0c159e49015c" class="GINGER_SOFTWARE_mark"&gt;NAT Policy&lt;/GS&gt;&lt;STRONG&gt; is not downloaded.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;GS id="a527de90-8f9e-499a-9eb1-2b3d5f8765ad" ginger_software_uiphraseguid="06f090b1-bc76-4a98-9bad-00880d1cf638" class="GINGER_SOFTWARE_mark"&gt;Actually things&lt;/GS&gt; are working fine using Auto NAT, but as you suggested Manual NAT is better that Auto NAT, &lt;GS id="231309f3-8ab5-4473-af97-faa2ddcef3fe" ginger_software_uiphraseguid="06f090b1-bc76-4a98-9bad-00880d1cf638" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; am trying to learn that one. If you are not irritated, then please help me.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 05:54:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954677#M161387</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2016-08-05T05:54:13Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954678#M161389</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;No worries :). Manual NAT is not by nature better in any way, i just find it "cleaner" to read.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So lets see,&amp;nbsp;&lt;STRONG&gt;ERROR: any doesn't match an existing object or object-group.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H5&gt;One or more objects doesn't exist, check that you have all objects created.&lt;/H5&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ERROR: Address 201.202.203.204 &lt;/STRONG&gt;&lt;SPAN&gt;overlaps&lt;/SPAN&gt;&lt;STRONG&gt; with Public-IP interface address.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ERROR: &lt;/STRONG&gt;&lt;SPAN&gt;NAT Policy&lt;/SPAN&gt;&lt;STRONG&gt; is not downloaded.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H5&gt;Is this the same IP that is assigned to your outside/public interface?&lt;/H5&gt;
&lt;H5&gt;If so, use the interface command instead.&lt;/H5&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;nat &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; obj&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; service SOURCE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; destination any any &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;This should NAT:&lt;/P&gt;
&lt;P&gt;Host 192.168.10.100 tcp 3389 to public interface IP tcp 2234.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Or maybe clearer (remember they are always bi-directional unless specified not to):&lt;/P&gt;
&lt;P&gt;When any outside host access public interface IP at tcp 2234 NAT&amp;nbsp;to private host 192.168.10.100 tcp 3389&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;//Cristian&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 06:08:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954678#M161389</guid>
      <dc:creator>Cristian Nilsson</dc:creator>
      <dc:date>2016-08-05T06:08:31Z</dc:date>
    </item>
    <item>
      <title>Hi Christian,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954679#M161391</link>
      <description>&lt;P&gt;Hi Christian,&lt;/P&gt;
&lt;P&gt;This command worked without destination any any.&lt;/P&gt;
&lt;P&gt;Can you let me know why the&amp;nbsp;&lt;SPAN&gt;destination any any wasn't included?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you said, "remember they are always bi-directional unless specified not to"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How can i make it unidirectional.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What happens when it is unidirectional?&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;GS id="addf65a9-0a76-4b32-aba8-1351435a8b05" ginger_software_uiphraseguid="9b9eee5a-acab-4e13-b1ba-5e50520dc8d0" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;&lt;GS id="fccb7a1c-7d28-4f9b-9642-b83ecd4155ec" ginger_software_uiphraseguid="9b9eee5a-acab-4e13-b1ba-5e50520dc8d0" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;GS id="63054473-4f9b-4cf8-a3d6-ca00bc52b278" ginger_software_uiphraseguid="9b9eee5a-acab-4e13-b1ba-5e50520dc8d0" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; service SOURCE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 05 Aug 2016 06:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954679#M161391</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2016-08-05T06:27:10Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954680#M161392</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sorry i totally mixed that line up and also forgot&amp;nbsp;the static command.&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;nat &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; obj&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; destination static any any service SOURCE&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;You can apply the unidirectional at the end.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;nat &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; obj&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; destination static any any service SOURCE&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;TCP&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt; SOURCE&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;TCP&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;2234 unidirectional&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;Now the rule only applies in one direction, i have yet to see a use for this thou (multicast/udp traffic?)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;//Cristian&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 06:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954680#M161392</guid>
      <dc:creator>Cristian Nilsson</dc:creator>
      <dc:date>2016-08-05T06:42:07Z</dc:date>
    </item>
    <item>
      <title>Christian,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954681#M161394</link>
      <description>&lt;P&gt;Christian,&lt;/P&gt;
&lt;P&gt;Noted. Thanks a lot.&lt;/P&gt;
&lt;P&gt;This command doesn't &lt;GS id="dc2d53e6-ff41-4bf8-b8c2-efc302bec234" ginger_software_uiphraseguid="c10d7266-d590-46e6-bc0f-b67fb2e6c3c7" class="GINGER_SOFTWARE_mark"&gt;need any any&lt;/GS&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;GS id="194187de-c9a6-4cc9-a309-daa0e9e47af3" ginger_software_uiphraseguid="0579e098-2dda-425f-8489-97e53c60756a" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;&lt;GS id="3fca52ba-61db-4979-826d-06ce04521e4e" ginger_software_uiphraseguid="0579e098-2dda-425f-8489-97e53c60756a" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;GS id="32403f0a-02d2-409c-a6c4-df9b8d0b8faf" ginger_software_uiphraseguid="0579e098-2dda-425f-8489-97e53c60756a" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; destination &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; any any service SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;If we use any any then there will be this error:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ERROR: any doesn't match an existing object or object-group&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;GS id="269f9030-9771-40eb-8a4b-f34702a9f878" ginger_software_uiphraseguid="51eb5752-e1b8-4d17-aaf1-f428ed5cda60" class="GINGER_SOFTWARE_mark"&gt;we&lt;/GS&gt; can simply use&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;GS id="7e401d4a-66c1-49cc-bee1-97605b19187a" ginger_software_uiphraseguid="1ab11698-b5a6-4883-860c-930a481d3a37" class="GINGER_SOFTWARE_mark"&gt;nat&lt;/GS&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;private&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;&lt;GS id="dadf1a17-0666-4894-8b34-4c3c036ed90c" ginger_software_uiphraseguid="1ab11698-b5a6-4883-860c-930a481d3a37" class="GINGER_SOFTWARE_mark"&gt;,&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;&lt;GS id="ea5fe1bb-633f-4801-a318-d31d230f863f" ginger_software_uiphraseguid="1ab11698-b5a6-4883-860c-930a481d3a37" class="GINGER_SOFTWARE_mark"&gt;obj&lt;/GS&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;192.168&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;10.100&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="lit"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="pln"&gt;&amp;nbsp;service SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;3389&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; SOURCE&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;TCP&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;2234&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This helped me and solved my issue too. So thanks a lot&lt;GS id="1ce447c9-715f-4f93-ae6d-902d31205181" ginger_software_uiphraseguid="5a6ec010-07a8-4439-9b73-ae5166a9e0b7" class="GINGER_SOFTWARE_mark"&gt;.&lt;/GS&gt;I am marking your recent answer as &lt;GS id="bbad546e-dbe6-42ea-87e7-c48d7d4266fc" ginger_software_uiphraseguid="5a6ec010-07a8-4439-9b73-ae5166a9e0b7" class="GINGER_SOFTWARE_mark"&gt;correct answer&lt;/GS&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 07:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954681#M161394</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2016-08-05T07:07:37Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954682#M161395</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Happy to help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;//Cristian&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 07:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auto-nat-and-manual-nat-in-cisco-asa/m-p/2954682#M161395</guid>
      <dc:creator>Cristian Nilsson</dc:creator>
      <dc:date>2016-08-05T07:36:36Z</dc:date>
    </item>
  </channel>
</rss>

