<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global PAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/global-pat/m-p/2800649#M178044</link>
    <description>&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;Hi All, i am currently replacing a PIX firewall with an ASA 9.5(1).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I have configured the access rules but i am unsure on the best way of configuring PAT on the external interface, which is automatic on the PIX.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I have created a container containing our 2 aggregated IP address ranges which are a /19 and a /20 subnet but testing has been unsuccessful.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;When testing external access rules I can only connect if I create an object for the individual PC I am using and NAT &lt;EM&gt;(PAT Hide) &lt;/EM&gt;that to the external interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I have tried doing the same thing using a network object for the local subnet the PC is on but this has also proved unsuccessful.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I can create an access rule for a group of individual (nat/pat hide) PCs but I would prefer to use PAT.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;Any help appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;Pete&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:02:56 GMT</pubDate>
    <dc:creator>SHSCITHelpdesk</dc:creator>
    <dc:date>2019-03-12T07:02:56Z</dc:date>
    <item>
      <title>Global PAT</title>
      <link>https://community.cisco.com/t5/network-security/global-pat/m-p/2800649#M178044</link>
      <description>&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;Hi All, i am currently replacing a PIX firewall with an ASA 9.5(1).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I have configured the access rules but i am unsure on the best way of configuring PAT on the external interface, which is automatic on the PIX.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I have created a container containing our 2 aggregated IP address ranges which are a /19 and a /20 subnet but testing has been unsuccessful.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;When testing external access rules I can only connect if I create an object for the individual PC I am using and NAT &lt;EM&gt;(PAT Hide) &lt;/EM&gt;that to the external interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I have tried doing the same thing using a network object for the local subnet the PC is on but this has also proved unsuccessful.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;I can create an access rule for a group of individual (nat/pat hide) PCs but I would prefer to use PAT.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;Any help appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Arial','sans-serif';"&gt;Pete&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-pat/m-p/2800649#M178044</guid>
      <dc:creator>SHSCITHelpdesk</dc:creator>
      <dc:date>2019-03-12T07:02:56Z</dc:date>
    </item>
    <item>
      <title>Hi Pete,</title>
      <link>https://community.cisco.com/t5/network-security/global-pat/m-p/2800650#M178048</link>
      <description>&lt;P&gt;Hi Pete,&lt;/P&gt;
&lt;P&gt;As per my understanding you would like to translate the inside subnets to outside interface IP so that you can send the traffic to internet. Please correct me if my understanding about the issue is incorrect.&lt;/P&gt;
&lt;P&gt;If you are looking to do a dynamic PAT then below is a sample configuration.&lt;/P&gt;
&lt;P&gt;ASA1(config)# object network obj_192.168.13.0_outside&lt;BR /&gt;ASA1(config-network-object)# subnet 192.168.13.0 255.255.255.0&lt;BR /&gt;ASA1(config-network-object)# nat (inside,outside) dynamic interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can refer the below link for more information&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/document/33921/asa-pre-83-83-nat-configuration-examples&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 15:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-pat/m-p/2800650#M178048</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-17T15:54:44Z</dc:date>
    </item>
  </channel>
</rss>

