<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Akshay, that is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-pat-question/m-p/2752090#M177795</link>
    <description>&lt;P&gt;Thanks Akshay, that is helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Had a followup to that, is there a way to include the outside interface as the first IP address used for the PAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;TJ&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2015 13:40:07 GMT</pubDate>
    <dc:creator>mrthejaswi</dc:creator>
    <dc:date>2015-10-15T13:40:07Z</dc:date>
    <item>
      <title>ASA PAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-pat-question/m-p/2752088#M177789</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recently saw the message "PAT pool exhausted" from&amp;nbsp;one of our firewalls that we manage. Our current set up is a typical PAT on the outside interface.&lt;/P&gt;&lt;P&gt;Current Config:&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network PAT-obj&lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (any,OUTSIDE) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the near future we expect the number of users behind the firewall to grow.&amp;nbsp;As a work around this, I was thinking of implementing a PAT pool, assign a pool of say 3 contiguous ip addresses and using this pool for a PAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Proposed:&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network PAT-pool&lt;/P&gt;&lt;P&gt;range X.Y.Z.10 X.Y.Z.12&lt;/P&gt;&lt;P&gt;object network PAT-obj&lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (any,OUTSIDE) dynamic&amp;nbsp;PAT-pool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question I have is will this allow just 3 hosts to be NAT-ed/PAT-ed out or will it allow 3 * 65K connections outbound?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;TJ&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:44:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-pat-question/m-p/2752088#M177789</guid>
      <dc:creator>mrthejaswi</dc:creator>
      <dc:date>2019-03-12T06:44:13Z</dc:date>
    </item>
    <item>
      <title>Hi,In case of pat-pool, by</title>
      <link>https://community.cisco.com/t5/network-security/asa-pat-question/m-p/2752089#M177792</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In case of pat-pool, by default it would utilize all the ports before moving on to next address in the pat-pool. Please refer the link below which explains different options available (round-robin, extended, flat) with pat-pool and the default behavior of pat-pool :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/nat_objects.html#wp1455942&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rate if it helps!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 20:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-pat-question/m-p/2752089#M177792</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-10-12T20:17:10Z</dc:date>
    </item>
    <item>
      <title>Thanks Akshay, that is</title>
      <link>https://community.cisco.com/t5/network-security/asa-pat-question/m-p/2752090#M177795</link>
      <description>&lt;P&gt;Thanks Akshay, that is helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Had a followup to that, is there a way to include the outside interface as the first IP address used for the PAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;TJ&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 13:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-pat-question/m-p/2752090#M177795</guid>
      <dc:creator>mrthejaswi</dc:creator>
      <dc:date>2015-10-15T13:40:07Z</dc:date>
    </item>
  </channel>
</rss>

