<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Source NAT Cisco ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690386#M194278</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to understand the concept on source NAT (not sure if this is the same as Twice NAT).&lt;/P&gt;&lt;P&gt;So I have attached a sample topology. I am in the process of migrating from watchguard firewalls to cisco ASAs, and during the migration I have come across this issue I am trying to get my head around. Im pretty new to configuring firewalls.&lt;/P&gt;&lt;P&gt;So If external Host A&amp;nbsp;is trying to access my internal Server A via ASA 2, the traffic comes in, but on return it will hit the default gateway on the core switch which points to ASA 1. I was told that I can configure Source NAT, to force that traffic to return via the same firewall which involves natting on the Inside and Outside interfaces.&lt;/P&gt;&lt;P&gt;Just wondering if anyone is able to shed some light on this or knows of a good link.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:11:31 GMT</pubDate>
    <dc:creator>Mokhalil82</dc:creator>
    <dc:date>2019-03-12T06:11:31Z</dc:date>
    <item>
      <title>Source NAT Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690386#M194278</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to understand the concept on source NAT (not sure if this is the same as Twice NAT).&lt;/P&gt;&lt;P&gt;So I have attached a sample topology. I am in the process of migrating from watchguard firewalls to cisco ASAs, and during the migration I have come across this issue I am trying to get my head around. Im pretty new to configuring firewalls.&lt;/P&gt;&lt;P&gt;So If external Host A&amp;nbsp;is trying to access my internal Server A via ASA 2, the traffic comes in, but on return it will hit the default gateway on the core switch which points to ASA 1. I was told that I can configure Source NAT, to force that traffic to return via the same firewall which involves natting on the Inside and Outside interfaces.&lt;/P&gt;&lt;P&gt;Just wondering if anyone is able to shed some light on this or knows of a good link.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690386#M194278</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2019-03-12T06:11:31Z</dc:date>
    </item>
    <item>
      <title>Hi,Looking into the topology,</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690387#M194279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Looking into the topology, it seems that we need to get the return traffic go through ASA 2 directly.&lt;/P&gt;&lt;P&gt;For that we need to do source and destination NAT both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all, to answer your question regarding source NAT and twice NAT.&lt;/P&gt;&lt;P&gt;Source NAT simply means to NAT the source IP. For instance, all inside users when go to internet gets translated to outside interface IP.&lt;/P&gt;&lt;P&gt;Twice NAT also called as manual NAT is a feature on code 8.3 and above where in a single NAT statement you can NAT the source and destination both.&lt;/P&gt;&lt;P&gt;In this scenario of your's, the statement's syntax should be like :&lt;/P&gt;&lt;P&gt;nat (outside,inside) source dynamic any interface destination static mapped-ip real-ip .&lt;/P&gt;&lt;P&gt;This will ensure that your return traffic goes to firewall 2.&lt;/P&gt;&lt;P&gt;Some ASA NAT translation links that will be helpful :&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/33921/asa-pre-83-83-nat-configuration-examples&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/configuration/guide/config/nat_overview.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pulkit Saxena&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2015 20:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690387#M194279</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2015-06-27T20:12:01Z</dc:date>
    </item>
    <item>
      <title>Hi Pulkit, thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690388#M194280</link>
      <description>&lt;P&gt;Hi Pulkit, thanks for the response.&lt;/P&gt;&lt;P&gt;I am using asa version 9.3 and currently on ASDM. So am I right in thinking I should configure NAT on both the source interface and destination interface?&lt;/P&gt;&lt;P&gt;What would be my translated source addresses for each. The translated destination I assume will stay the same&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2015 10:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690388#M194280</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2015-06-28T10:59:37Z</dc:date>
    </item>
    <item>
      <title>Hi, There will be a single</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690389#M194281</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There will be a single NAT statement only.&lt;/P&gt;&lt;P&gt;Try going into CLI through ASDM, and apply the NAT statement that I&amp;nbsp;have given above.&lt;/P&gt;&lt;P&gt;In this particular scenario, source will get translated to inside interface IP.&lt;/P&gt;&lt;P&gt;Destination will get translated from the mapped IP to the actual IP.&lt;/P&gt;&lt;P&gt;If you can provide me all actual IP addresses, I can help you with the NAT statement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Pulkit Saxena&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2015 11:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690389#M194281</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2015-06-28T11:06:29Z</dc:date>
    </item>
    <item>
      <title>Hi PulkitSo addresses are as</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690390#M194282</link>
      <description>&lt;P&gt;Hi Pulkit&lt;/P&gt;&lt;P&gt;So addresses are as follows, example IPs of course&lt;/P&gt;&lt;P&gt;Inside Server 10.10.10.50&lt;/P&gt;&lt;P&gt;ASA2 Inside Int 10.10.10.1&lt;/P&gt;&lt;P&gt;ASA2 Outside Int 88.88.88.254&lt;/P&gt;&lt;P&gt;Outside Host 98.98.98.50&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2015 11:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690390#M194282</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2015-06-28T11:26:46Z</dc:date>
    </item>
    <item>
      <title>Hi, I believe that from</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690391#M194283</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe that from outside anyone can connect to your server&amp;nbsp;at&amp;nbsp;88.88.88.254.&lt;/P&gt;&lt;P&gt;So in that case, the NAT statement will be :&lt;/P&gt;&lt;P&gt;nat (outside,inside) source dynamic any interface destination static 88.88.88.254 10.10.10.50&lt;/P&gt;&lt;P&gt;Ensure that we have already allowed the required traffic through access rule in inbound direction.&lt;/P&gt;&lt;P&gt;This will certainly make it work.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Pulkit Saxena&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jun 2015 13:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690391#M194283</guid>
      <dc:creator>Pulkit Saxena</dc:creator>
      <dc:date>2015-06-28T13:37:56Z</dc:date>
    </item>
    <item>
      <title>Thanks Pulkit</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690392#M194284</link>
      <description>&lt;P&gt;Thanks Pulkit&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2015 10:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690392#M194284</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2015-06-29T10:23:02Z</dc:date>
    </item>
    <item>
      <title>Hi Pulkhit,I have got similar</title>
      <link>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690393#M194285</link>
      <description>&lt;P&gt;Hi Pulkhit,&lt;/P&gt;&lt;P&gt;I have got similar kinda issue. But the difference is Real Source (x.x.x.x)&amp;nbsp;and destinations (x.x.x.x) IP's are belong to&amp;nbsp;Same Subnet and NAT already exist to translate destination's subnet IP's to other IP's (y.y.y.y)&amp;nbsp;so they can talk to other networks.&lt;/P&gt;&lt;P&gt;Requirement :&lt;/P&gt;&lt;P&gt;Host 1.1.1.1&amp;nbsp;in Environment A needs to talk to node (1.1.1.20) in Environment B&amp;nbsp;&lt;/P&gt;&lt;P&gt;Environment B inside interface of ASA (image using 9.13) already translating 1.1.1.20 to 3.3.3.20 using static nat entering from outside interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have any solution to it let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Warm Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2015 04:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-nat-cisco-asa/m-p/2690393#M194285</guid>
      <dc:creator>qutub.siddiqui</dc:creator>
      <dc:date>2015-07-27T04:44:28Z</dc:date>
    </item>
  </channel>
</rss>

