<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,You need to create an in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691585#M192025</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You need to create an object-group with all these networks in it and replace the 0.0.0.0 from the object.&lt;/P&gt;&lt;P&gt;You would not be able to use object for multiple subnets and hence us object group and call it using the NAT statement.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Mon, 04 May 2015 12:06:40 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-05-04T12:06:40Z</dc:date>
    <item>
      <title>Dynamic NAT configuration on Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691575#M192015</link>
      <description>&lt;P&gt;Dear Support,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to setup a dynamic NAT on my firewall Cisco ASA 5520. I make the configuration below, but I cannot access to internet. Can you help me please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network LTY_NAT&lt;BR /&gt;&amp;nbsp;subnet 192.168.176.0 255.255.248.0&lt;BR /&gt;object network HQ_NAT&lt;BR /&gt;&amp;nbsp;subnet 192.168.190.0 255.255.255.0&lt;BR /&gt;object network CAD_NAT&lt;BR /&gt;&amp;nbsp;subnet 192.168.140.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object-group network ESN_NAT&lt;BR /&gt;&amp;nbsp;network-object object LTY_NAT&lt;BR /&gt;&amp;nbsp;network-object object HQ_NAT&lt;BR /&gt;&amp;nbsp;network-object object CAD_NAT&lt;/P&gt;&lt;P&gt;nat (any,outside) source dynamic ESN_NAT interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Cisco ASA is connected to the&amp;nbsp;Inside interface(192.168.180.228) with this network 192.168.176.0 255.255.248.0 .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:52:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691575#M192015</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2019-03-12T05:52:36Z</dc:date>
    </item>
    <item>
      <title>Dear Support, When I try to</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691576#M192016</link>
      <description>&lt;P&gt;Dear Support,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try to ping internet I get this error message from Real Time log viewer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;May 03 2015&lt;/TD&gt;&lt;TD&gt;15:53:41&lt;/TD&gt;&lt;TD&gt;302020&lt;/TD&gt;&lt;TD&gt;192.168.182.45&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;8.8.8.8&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Built outbound ICMP connection for faddr 8.8.8.8/0 gaddr 192.168.182.45/1 laddr 192.168.182.45/1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Sun, 03 May 2015 16:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691576#M192016</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-03T16:02:36Z</dc:date>
    </item>
    <item>
      <title>It seems NAT is not working</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691577#M192017</link>
      <description>&lt;P&gt;It seems NAT is not working correctly. The syslog 302020 says&lt;/P&gt;&lt;P&gt;Connection was built when you tried to ping 8.8.8.8 from 192.168.182.45.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;faddr= Foreign address&lt;/P&gt;&lt;P&gt;gaddr (Global address)=NAT address of 192.168.182.45///This should have been the interlace IP address of ASA&lt;/P&gt;&lt;P&gt;laddr (Local address) of 192.168.181.45&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please try below step:-&lt;/P&gt;&lt;P&gt;1) Run packet tracer and see if NAT is being hit.&lt;/P&gt;&lt;P&gt;2) If packet-tracer shows NAT being hit try to do a "clear xlate" and then check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pranay&lt;/P&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;ladd&lt;/DIV&gt;</description>
      <pubDate>Sun, 03 May 2015 17:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691577#M192017</guid>
      <dc:creator>Pranay Prasoon</dc:creator>
      <dc:date>2015-05-03T17:42:00Z</dc:date>
    </item>
    <item>
      <title>Hi Pranay,Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691578#M192018</link>
      <description>&lt;P&gt;Hi Pranay,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Below the results of packet tracer:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vpnserver# packet-tracer input outside rawip 192.168.180.100 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;0-255&amp;gt;&amp;nbsp; Enter the ip protocol id/next header&lt;BR /&gt;vpnserver# packet-tracer input outside rawip 192.168.180.100 25&lt;BR /&gt;ERROR: % Incomplete command&lt;BR /&gt;vpnserver# packet-tracer input outside rawip 192.168.180.100 25 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; A.B.C.D&amp;nbsp; Enter the destination ipv4 address&lt;BR /&gt;vpnserver# packet-tracer input outside rawip 192.168.180.100 25 8.8.8.8&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type:&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (any,outside) source dynamic ESN_NAT interface&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;vpnserver#&lt;/P&gt;</description>
      <pubDate>Sun, 03 May 2015 18:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691578#M192018</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-03T18:55:36Z</dc:date>
    </item>
    <item>
      <title>Hi,The Packet Trace which you</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691579#M192019</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The Packet Trace which you executed is incorrect.&lt;/P&gt;&lt;P&gt;As per the NAT statement , you need to use the LAN interface(inside) interface as the ingress interface for the traffic.&lt;/P&gt;&lt;P&gt;Use option "tcp" instead of "rawip" and then you would be able to see the source and destination ports.&lt;/P&gt;&lt;P&gt;Use this for reference:-&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 03:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691579#M192019</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T03:39:07Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,Thank for</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691580#M192020</link>
      <description>&lt;P&gt;Hi Vibhor Amrodia,&lt;/P&gt;&lt;P&gt;Thank for your reply.&lt;/P&gt;&lt;P&gt;Below the results. But the&amp;nbsp;NAT and access list&amp;nbsp;chosen by the command packet-tracer is not that I have created for the NAT.&lt;/P&gt;&lt;P&gt;My NAT configuration is:&lt;/P&gt;&lt;P&gt;object network LTY_NAT&lt;BR /&gt;&amp;nbsp;subnet 192.168.176.0 255.255.248.0&lt;BR /&gt;object network HQ_NAT&lt;BR /&gt;&amp;nbsp;subnet 192.168.190.0 255.255.255.0&lt;BR /&gt;object network CAD_NAT&lt;BR /&gt;&amp;nbsp;subnet 192.168.140.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object-group network ESN_NAT&lt;BR /&gt;&amp;nbsp;network-object object LTY_NAT&lt;BR /&gt;&amp;nbsp;network-object object HQ_NAT&lt;BR /&gt;&amp;nbsp;network-object object CAD_NAT&lt;/P&gt;&lt;P&gt;nat (any,outside) source dynamic ESN_NAT interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vpnserver# packet-tracer input inside tcp 192.168.180.100 53 8.8.8.8 80&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group 103 in interface inside&lt;BR /&gt;access-list 103 extended permit ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type:&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside,outside) source static Local_LAN Local_LAN destination static Remote&lt;BR /&gt;_LAN Remote_LAN&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 192.168.180.100/53 to 192.168.180.100/53&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 177738, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;vpnserver#&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 10:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691580#M192020</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-04T10:28:46Z</dc:date>
    </item>
    <item>
      <title>Hi,This is the issue. If you</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691581#M192021</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is the issue. If you check the NAT phase:- 6 , it is using a different NAT statement.&lt;/P&gt;&lt;P&gt;The problem is i suspect the Remote_LAN is containing Subnet which is also causing all the traffic to the internet IP addresses to be using this NAT which is acting like a NONAT or not translating the IP addresses to the interface.&lt;/P&gt;&lt;P&gt;Can you post the output of this Object:- Remote_LAN&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;nat (inside,outside) source static Local_LAN Local_LAN destination static Remote&lt;BR /&gt;_LAN Remote_LAN - See more at: https://supportforums.cisco.com/discussion/12497401/dynamic-nat-configuration-cisco-asa-5520#sthash.lhjx4X6z.dpuf&lt;/DIV&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;nat (inside,outside) source static Local_LAN Local_LAN destination static Remote&lt;BR /&gt;_LAN Remote_LAN - See more at: https://supportforums.cisco.com/discussion/12497401/dynamic-nat-configuration-cisco-asa-5520#sthash.lhjx4X6z.dpuf&lt;/DIV&gt;</description>
      <pubDate>Mon, 04 May 2015 10:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691581#M192021</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T10:42:36Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,Thanks!The</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691582#M192022</link>
      <description>&lt;P&gt;Hi Vibhor Amrodia,&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;The object Remote_LAN contains only this subnetwork:&lt;/P&gt;&lt;P&gt;object network Remote_LAN&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ramatoulaye HANE&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 11:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691582#M192022</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-04T11:15:59Z</dc:date>
    </item>
    <item>
      <title>Hi,This is the issue. This</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691583#M192023</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is the issue. This NAT is probably for the VPN traffic and to prevent it from being natted.&lt;/P&gt;&lt;P&gt;If you are using VPN , use specific Remote Subnets or if you are not using VPN , remove this NAT.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 11:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691583#M192023</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T11:24:14Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,I use these</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691584#M192024</link>
      <description>&lt;P&gt;Hi Vibhor Amrodia,&lt;/P&gt;&lt;P&gt;I use these NAT for SSL VPN&lt;/P&gt;&lt;P&gt;object-group network Local_LAN&lt;BR /&gt;&amp;nbsp;network-object 192.168.140.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.130.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.190.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.71.121.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.71.124.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.100.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.200.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.170.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.176.0 255.255.248.0&lt;BR /&gt;&amp;nbsp;network-object 10.71.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 172.28.11.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 172.28.13.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network Remote_LAN&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;So, which network I can specify for this object network Remote_LAN?&lt;/P&gt;&lt;P&gt;Ramatoulaye HANE&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 11:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691584#M192024</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-04T11:43:04Z</dc:date>
    </item>
    <item>
      <title>Hi,You need to create an</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691585#M192025</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You need to create an object-group with all these networks in it and replace the 0.0.0.0 from the object.&lt;/P&gt;&lt;P&gt;You would not be able to use object for multiple subnets and hence us object group and call it using the NAT statement.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:06:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691585#M192025</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T12:06:40Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,Can you</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691586#M192026</link>
      <description>&lt;P&gt;Hi Vibhor Amrodia,&lt;/P&gt;&lt;P&gt;Can you give me an example, because I don't understand what you say. Or I must create local network and remote network with the same network objects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691586#M192026</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-04T12:12:39Z</dc:date>
    </item>
    <item>
      <title>Hi,So , to be clear , answer</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691587#M192027</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;So , to be clear , answer this query for me:-&lt;/P&gt;&lt;P&gt;Local Subnets:-&lt;/P&gt;&lt;P&gt;Ip local Pool for the SSL VPN:-&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691587#M192027</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T12:17:08Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,Local</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691588#M192028</link>
      <description>&lt;P&gt;Hi Vibhor Amrodia,&lt;/P&gt;&lt;P&gt;Local Subnets: 192.168.176.0/21, 192.168.190.0/24, 192.168.140.0/24, 192.168.170.0/24&lt;/P&gt;&lt;P&gt;Ip local Pool for the SSL VPN: ip local pool esn 192.168.182.150-192.168.182.199 mask 255.255.248.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Ramatoulaye HANE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 12:32:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691588#M192028</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-04T12:32:53Z</dc:date>
    </item>
    <item>
      <title>Hi,In this case , you would</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691589#M192029</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In this case , you would need this configuration:-&lt;/P&gt;&lt;P&gt;object-group network LOCAL-SUBNETS&lt;/P&gt;&lt;P&gt;network-object 192.168.176.0 255.255.224.0&lt;/P&gt;&lt;P&gt;network-object 192.168.190..0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;network-object 192.168.140.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.168.170.0 255.255.255.0&lt;/P&gt;&lt;P&gt;Object network Anyconnect&lt;/P&gt;&lt;P&gt;subnet 192.168.182.0 255.255.248.0&lt;/P&gt;&lt;P&gt;nat (inside.outside) source static LOCAL-SUBNETS LOCAL-SUBNETS destination static Anyconnect Anyconnect&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;&lt;DIV id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;nat (inside,outside) source static Local_LAN Local_LAN destination static Remote&lt;BR /&gt;_LAN Remote_LAN - See more at: https://supportforums.cisco.com/discussion/12497401/dynamic-nat-configuration-cisco-asa-5520#sthash.yOdDxL5q.dpuf&lt;/DIV&gt;</description>
      <pubDate>Mon, 04 May 2015 12:45:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691589#M192029</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T12:45:06Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,Thanks!I</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691590#M192030</link>
      <description>&lt;P&gt;Hi Vibhor Amrodia,&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;I modified&amp;nbsp; the remote network. Now Local_LAn and Anyconnect are below:&lt;/P&gt;&lt;P&gt;object-group network Local_LAN&lt;BR /&gt;&amp;nbsp;network-object 192.168.140.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.130.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.190.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.71.121.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.71.124.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.100.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.200.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.170.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.176.0 255.255.248.0&lt;BR /&gt;&amp;nbsp;network-object 10.71.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 172.28.11.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 172.28.13.0 255.255.255.0&lt;/P&gt;&lt;P&gt;Object network Anyconnect&lt;BR /&gt;subnet 192.168.176.0 255.255.248.0&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Local_LAN Local_LAN destination static Anyconnect Anyconnect&lt;/P&gt;&lt;P&gt;Now, what is the next step?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 13:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691590#M192030</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-04T13:38:46Z</dc:date>
    </item>
    <item>
      <title>Hi,Now , I think the traffic</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691591#M192031</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Now , I think the traffic should be allowed for the Outbound internet.&lt;/P&gt;&lt;P&gt;Check it with the packet tracer again.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 13:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691591#M192031</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T13:57:20Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,It works</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691592#M192032</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A about="/users/vamrodia" class="username" datatype="" href="https://supportforums.cisco.com/users/vamrodia" property="foaf:name" title="View user profile." typeof="sioc:UserAccount" lang=""&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;Hi&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt; &lt;A about="/users/vamrodia" class="username" datatype="" href="https://supportforums.cisco.com/users/vamrodia" property="foaf:name" title="View user profile." typeof="sioc:UserAccount" lang=""&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;Vibhor Amrodia,&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It works now.&lt;/P&gt;&lt;P&gt;Thank for your support!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 16:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691592#M192032</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-04T16:14:51Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor Amrodia,The dynamic</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691593#M192033</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN rel="has_creator"&gt;Hi Vibhor Amrodia,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The dynamic NAT is working fine following your guide, but the VPN site to site with my peer is disconnected and I can't access to peer side. What I can do to have dynamic NAT et VPN site to site UP.&lt;/P&gt;&lt;P&gt;Thank in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 10:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691593#M192033</guid>
      <dc:creator>ramatoulaye.hane1</dc:creator>
      <dc:date>2015-05-05T10:04:22Z</dc:date>
    </item>
    <item>
      <title>Hi,Now , you need to check</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691594#M192034</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Now , you need to check the NONAT statement is working for the Site-To-Site VPN tunnel or not. I think this NAT broke that for you.&lt;/P&gt;&lt;P&gt;You need this NAT statement:-&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static &amp;lt;Local Subnets&amp;gt; &amp;lt;Local Subnets&amp;gt; destination static &amp;lt;Remote Subnets&amp;gt; &amp;lt;Remote Subnets&amp;gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 12:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-configuration-on-cisco-asa-5520/m-p/2691594#M192034</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-05T12:20:08Z</dc:date>
    </item>
  </channel>
</rss>

