<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create NAT statement ASA 9.1 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/create-nat-statement-asa-9-1/m-p/2723668#M192346</link>
    <description>&lt;P&gt;I need some help in creating a NAT statement as i am migrating a pre-8.3 migration to 9.1 and almost done all except one type of NAT i can't understand exactly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;v 8.2&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 192.168.20.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 10.38.37.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 10.38.46.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 192.168.12.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.0.0 255.255.0.0 10.38.39.0 255.255.255.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 194.165.102.1 1&lt;BR /&gt;route inside DHCP-pool1 255.255.254.0 10.38.36.1 1&lt;BR /&gt;route inside DHCP-pool2 255.255.254.0 10.38.36.1 1&lt;BR /&gt;route inside DHCP-pool3 255.255.254.0 10.38.36.1 1&lt;BR /&gt;route inside 10.10.37.0 255.255.255.0 10.38.36.1 1&lt;BR /&gt;route inside 10.38.0.0 255.255.0.0 10.38.36.1 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How shall it look like in v 9.1, as the access-list have many lines i thought there is someway i can trim it under object statement?&lt;/P&gt;&lt;P&gt;Also the NAT statement, i am confused in what it should look like, either NAT (inside, any) or NAT (inside,outside)? i have added the route statements and would appreciate some help on this.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:30:14 GMT</pubDate>
    <dc:creator>landgren</dc:creator>
    <dc:date>2019-03-12T06:30:14Z</dc:date>
    <item>
      <title>Create NAT statement ASA 9.1</title>
      <link>https://community.cisco.com/t5/network-security/create-nat-statement-asa-9-1/m-p/2723668#M192346</link>
      <description>&lt;P&gt;I need some help in creating a NAT statement as i am migrating a pre-8.3 migration to 9.1 and almost done all except one type of NAT i can't understand exactly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;v 8.2&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 192.168.20.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 10.38.37.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 10.38.46.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.36.0 255.255.255.0 192.168.12.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 10.38.0.0 255.255.0.0 10.38.39.0 255.255.255.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 194.165.102.1 1&lt;BR /&gt;route inside DHCP-pool1 255.255.254.0 10.38.36.1 1&lt;BR /&gt;route inside DHCP-pool2 255.255.254.0 10.38.36.1 1&lt;BR /&gt;route inside DHCP-pool3 255.255.254.0 10.38.36.1 1&lt;BR /&gt;route inside 10.10.37.0 255.255.255.0 10.38.36.1 1&lt;BR /&gt;route inside 10.38.0.0 255.255.0.0 10.38.36.1 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How shall it look like in v 9.1, as the access-list have many lines i thought there is someway i can trim it under object statement?&lt;/P&gt;&lt;P&gt;Also the NAT statement, i am confused in what it should look like, either NAT (inside, any) or NAT (inside,outside)? i have added the route statements and would appreciate some help on this.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-nat-statement-asa-9-1/m-p/2723668#M192346</guid>
      <dc:creator>landgren</dc:creator>
      <dc:date>2019-03-12T06:30:14Z</dc:date>
    </item>
    <item>
      <title>Another one that is pretty</title>
      <link>https://community.cisco.com/t5/network-security/create-nat-statement-asa-9-1/m-p/2723669#M192347</link>
      <description>&lt;P&gt;Another one that is pretty hard i can't get grip on is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;static (zones,outside) tcp interface 2507 access-list taxing&lt;/P&gt;&lt;P&gt;access-list taxing extended permit tcp host cannonball eq 2507 object-group grp1&lt;/P&gt;&lt;P&gt;object-group network grp1&lt;BR /&gt;&amp;nbsp;network-object host srv1&lt;BR /&gt;&amp;nbsp;network-object host srv2&lt;BR /&gt;&amp;nbsp;network-object host srv3&lt;BR /&gt;&amp;nbsp;network-object host srv4&lt;BR /&gt;&amp;nbsp;network-object net1 255.255.255.240&lt;BR /&gt;&amp;nbsp;network-object host srv7&lt;BR /&gt;&amp;nbsp;network-object host srv8&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 07:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-nat-statement-asa-9-1/m-p/2723669#M192347</guid>
      <dc:creator>landgren</dc:creator>
      <dc:date>2015-08-27T07:07:35Z</dc:date>
    </item>
    <item>
      <title>Hi,object network obj-10.38</title>
      <link>https://community.cisco.com/t5/network-security/create-nat-statement-asa-9-1/m-p/2723670#M192348</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;object network obj-10.38.36.0&lt;/P&gt;&lt;P&gt;subnet 10.38.36.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-10.38.0.0&lt;/P&gt;&lt;P&gt;subnet 10.38.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.20.0&lt;/P&gt;&lt;P&gt;subnet 192.168.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-10.38.37.0&lt;/P&gt;&lt;P&gt;subnet 10.38.37.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-10.38.46.0&lt;/P&gt;&lt;P&gt;subnet 10.38.46.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.12.0&lt;/P&gt;&lt;P&gt;subnet 192.168.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-10.38.39.0&lt;/P&gt;&lt;P&gt;subnet 10.38.39.0 255.255.255.0&lt;/P&gt;&lt;P&gt;For the 1st NAT statement , you have to use the Manual NAT statement:-&lt;/P&gt;&lt;P&gt;Source-Objects:-&lt;/P&gt;&lt;P&gt;object-group network SRC&lt;/P&gt;&lt;P&gt;network-object object obj-10.38.36.0&lt;/P&gt;&lt;P&gt;network-object object obj-10.38.0.0&lt;/P&gt;&lt;P&gt;object-group network DEST&lt;/P&gt;&lt;P&gt;network-object object obj-192.168.20.0&lt;/P&gt;&lt;P&gt;network-object object obj-192.168.12.0&lt;/P&gt;&lt;P&gt;network-object object obj-10.38.37.0&lt;/P&gt;&lt;P&gt;network-object object obj-10.38.46.0&lt;/P&gt;&lt;P&gt;network-object object obj-10.38.37.0&lt;/P&gt;&lt;P&gt;network-object object obj-10.38.39.0&lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic SRC interface destination static DEST DEST no-proxy-arp&lt;/P&gt;&lt;P&gt;I think you would be able to configure the other NAT and it would be in a similar way as above.&lt;/P&gt;&lt;P&gt;Let me know if you have any issues.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2015 14:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-nat-statement-asa-9-1/m-p/2723670#M192348</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-08-30T14:56:53Z</dc:date>
    </item>
  </channel>
</rss>

