<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks a lot for your in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-nat-change-destination-ip-and-port/m-p/2924838#M166974</link>
    <description>&lt;P&gt;Thanks a lot for your feedback, appreciate your input. I will try it in our&amp;nbsp;network and post an update.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks again&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jun 2016 05:24:03 GMT</pubDate>
    <dc:creator>mo shea</dc:creator>
    <dc:date>2016-06-15T05:24:03Z</dc:date>
    <item>
      <title>How to NAT/Change destination IP and Port</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-change-destination-ip-and-port/m-p/2924836#M166972</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a scenario where a Server A&amp;nbsp;(IP x.x.x.x) on the outside interface of ASA (5525x IOS 9.6) is configured to send TCP and UDP traffic to Server B (IP y.y.y.y) on the inside. Using static routes I am able to successfully test connectivity between Servers A and B (no static NAT for server B currently)&lt;/P&gt;
&lt;P&gt;I want (but not sure how) to achieve the following,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;- Intercept the incoming TCP / UDP stream from Server A&lt;/P&gt;
&lt;P&gt;- change (or NAT) the source IP x.x.x.x of Server A to an IP (a.a.a.a) in the same subnet as the ASA's inside subnet&lt;/P&gt;
&lt;P&gt;- Manipulate the original packet destination address. I want the TCP stream to retain the destination as&amp;nbsp;Server B (y.y.y.y) but send UDP traffic to a Server C (c.c.c.c) on the inside&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So at the end I would expect Server B to receive TCP traffic from source IP a.a.a.a and Server C to receive UDP traffice from source a.a.a.a&lt;/P&gt;
&lt;P&gt;I was reading about Twice NAT but could not grasp the concept properly.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All help is appreciated&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Moe Shea&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-change-destination-ip-and-port/m-p/2924836#M166972</guid>
      <dc:creator>mo shea</dc:creator>
      <dc:date>2019-03-12T07:53:13Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-change-destination-ip-and-port/m-p/2924837#M166973</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Based on your input/requirements, below nat commands and object groups. I keep same name as your example:(IP are ones used on my lab)&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;object network SERVER-C&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; host 172.16.0.3&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;object service TCP&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; service tcp &lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;object service UDP&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; service udp &lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;object network SERVER-A&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; host 11.0.0.1&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;object network IP-NAT-INTERNAL&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; host 172.16.0.5&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;object network SERVER-B&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; host 172.16.0.2&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;nat (outside,inside) source static SERVER-A IP-NAT-INTERNAL destination static SERVER-B SERVER-B service TCP TCP&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;nat (outside,inside) source static SERVER-A IP-NAT-INTERNAL destination static SERVER-B SERVER-C service UDP UDP&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below some output of TCP connection from SERVER-A going to SERVER-B:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;*Jun 14 18:08:20.481: IP: s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.2, len 44, input feature&lt;BR /&gt;*Jun 14 18:08:20.483: TCP src=33705, dst=23, seq=3896161050, ack=0, win=4128 SYN, MCI Check(109), rtype 0, forus FALSE, sendself FALSE, mtu 0, fwdchk FALSE&lt;BR /&gt;*Jun 14 18:08:20.486: FIBipv4-packet-proc: route packet from GigabitEthernet0/1 src 172.16.0.5 dst 172.16.0.2&lt;BR /&gt;*Jun 14 18:08:20.486: FIBfwd-proc: Default:172.16.0.2/32 receive entry&lt;BR /&gt;*Jun 14 18:08:20.489: FIBipv4-packet-proc: packet routing failed&lt;BR /&gt;*Jun 14 18:08:20.489: IP: tableid=0, s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.2 (GigabitEthernet0/1), routed via RIB&lt;BR /&gt;*Jun 14 18:08:20.491: IP: s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.2 (GigabitEthernet0/1), len 44, rcvd 3&lt;BR /&gt;*Jun 14 18:08:20.491: TCP src=33705, dst=23, seq=3896161050, ack=0, win=4128 SYN&lt;BR /&gt;*Jun 14 18:08:20.493: IP: s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.2, len 44, stop process pak for forus packet&lt;BR /&gt;*Jun 14 18:08:20.493: TCP src=33705, dst=23, seq=3896161050, ack=0, win=4128 SYN&lt;BR /&gt;*Jun 14 18:08:20.502: FIBipv4-packet-proc: route packet from (local) src 172.16.0.2 dst 172.16.0.5&lt;BR /&gt;*Jun 14 18:08:20.502: FIBfwd-proc: packet routed by adj to GigabitEthernet0/1 172.16.0.5&lt;BR /&gt;*Jun 14 18:08:20.502: FIBipv4-packet-proc: packet routing succeeded&lt;BR /&gt;*Jun 14 18:08:20.503: IP: s=172.16.0.2 (local), d=172.16.0.5 (GigabitEthernet0/1), len 44, sending&lt;BR /&gt;*Jun 14 18:08:20.503: TCP src=23, dst=33705, seq=943713372, ack=3896161051, win=4128 ACK SYN&lt;BR /&gt;*Jun 14 18:08:20.505: IP: s=172.16.0.2 (local), d=172.16.0.5 (GigabitEthernet0/1), len 44, sending full packet&lt;BR /&gt;*Jun 14 18:08:20.506: TCP src=23, dst=33705, seq=943713372, ack=3896161051, win=4128 ACK SYN&lt;BR /&gt;*Jun 14 18:08:20.519: IP: s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.2, len 40, input feature&lt;BR /&gt;*Jun 14 18:08:20.521: TCP src=33705, dst=23, seq=3896161051, ack=943713373, win=4128 ACK, MCI Check(109), rtype 0, forus FALSE, sendself FALSE, mtu 0, fwdchk FALSE&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below some output of UDP&amp;nbsp;connection from SERVER-A going to SERVER-B but forwarded on SERVER-C:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;*Jun 14 18:13:17.663: FIBfwd-proc: sending link IP ip_pak_table 0 ip_nh_table 65535 if GigabitEthernet0/1 nh none uhp 1 deag 0 chgif 0 ttlexp 0 rec 0&lt;BR /&gt;*Jun 14 18:13:17.663: IP: s=172.16.0.3 (local), d=172.16.0.5 (GigabitEthernet0/1), len 56, sending&lt;BR /&gt;*Jun 14 18:13:17.665: ICMP type=3, code=3&lt;BR /&gt;*Jun 14 18:13:17.667: IP: s=172.16.0.3 (local), d=172.16.0.5 (GigabitEthernet0/1), len 56, encapsulation failed&lt;BR /&gt;*Jun 14 18:13:17.668: ICMP type=3, code=3&lt;BR /&gt;*Jun 14 18:13:17.669: IP: s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.3, len 28, input feature&lt;BR /&gt;*Jun 14 18:13:17.670: UDP src=49172, dst=33434, packet consumed, MCI Check(109), rtype 0, forus FALSE, sendself FALSE, mtu 0, fwdchk FALSE&lt;BR /&gt;*Jun 14 18:13:20.244: IP: s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.3, len 28, rcvd 0&lt;BR /&gt;*Jun 14 18:13:20.244: UDP src=49173, dst=33435&lt;BR /&gt;*Jun 14 18:13:20.245: FIBipv4-packet-proc: route packet from GigabitEthernet0/1 src 172.16.0.5 dst 172.16.0.3&lt;BR /&gt;*Jun 14 18:13:20.245: FIBfwd-proc: Default:172.16.0.3/32 receive entry&lt;BR /&gt;*Jun 14 18:13:20.247: FIBipv4-packet-proc: packet routing failed&lt;BR /&gt;*Jun 14 18:13:20.248: IP: tableid=0, s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.3 (GigabitEthernet0/1), routed via RIB&lt;BR /&gt;*Jun 14 18:13:20.248: FIBipv4-packet-proc: route packet from (local) src 172.16.0.3 dst 172.16.0.5&lt;BR /&gt;*Jun 14 18:13:20.249: FIBfwd-proc: packet routed by adj to GigabitEthernet0/1 172.16.0.5&lt;BR /&gt;*Jun 14 18:13:20.250: FIBipv4-packet-proc: packet routing succeeded&lt;BR /&gt;*Jun 14 18:13:20.250: IP: s=172.16.0.3 (local), d=172.16.0.5 (GigabitEthernet0/1), len 56, sending&lt;BR /&gt;*Jun 14 18:13:20.251: ICMP type=3, code=3&lt;BR /&gt;*Jun 14 18:13:20.252: IP: s=172.16.0.3 (local), d=172.16.0.5 (GigabitEthernet0/1), len 56, sending full packet&lt;BR /&gt;*Jun 14 18:13:20.253: ICMP type=3, code=3&lt;BR /&gt;*Jun 14 18:13:20.255: IP: s=172.16.0.5 (GigabitEthernet0/1), d=172.16.0.3, len 28, input feature&lt;BR /&gt;*Jun 14 18:13:20.256: UDP src=49173, dst=33435, packet consumed, MCI Check(109), rtype 0, forus FALSE, sendself FALSE, mtu 0, fwdchk FALSE&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hope this help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;PS: don't forget to rate and mark as correct answer if this solves your issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 22:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-change-destination-ip-and-port/m-p/2924837#M166973</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-14T22:45:33Z</dc:date>
    </item>
    <item>
      <title>Thanks a lot for your</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-change-destination-ip-and-port/m-p/2924838#M166974</link>
      <description>&lt;P&gt;Thanks a lot for your feedback, appreciate your input. I will try it in our&amp;nbsp;network and post an update.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 05:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-change-destination-ip-and-port/m-p/2924838#M166974</guid>
      <dc:creator>mo shea</dc:creator>
      <dc:date>2016-06-15T05:24:03Z</dc:date>
    </item>
  </channel>
</rss>

