<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi. Where is your PAT rule? I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649192#M200862</link>
    <description>&lt;P&gt;Hi. Where is your PAT rule? I can't seem to find it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing you need to remember is that NAT rules are processed in order, so when you have multiple rules matching a request through the firewall, the first rule that matches will be processed. Why do you have so many static nat rules for printers and other hosts? Which devices do you want to provide internet access to?&lt;/P&gt;</description>
    <pubDate>Mon, 27 Apr 2015 15:58:38 GMT</pubDate>
    <dc:creator>Andre Neethling</dc:creator>
    <dc:date>2015-04-27T15:58:38Z</dc:date>
    <item>
      <title>ASA 5515 9.4 NAT Conundrum</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649187#M200751</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've recently started to configure a NAT'ing policy for a cisco ASA 5515 (using FirePower) and I have run into some seriously odd issues. &amp;nbsp;Here's the basic scope.&lt;/P&gt;&lt;P&gt;Physical Config:&lt;/P&gt;&lt;P&gt;single upstream (1 Public in a /26)&amp;nbsp;link on ASA rest are downstream&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have multiple Public&amp;nbsp;IPs&amp;nbsp;statically being NAT'd to Multiple private IPs within the network. &amp;nbsp;They exist in the /26 but do not exists in the configuration of any interfaces.&lt;/P&gt;&lt;P&gt;I want to specifically NAT all outgoing traffic to a single IP as the primary internet drain. (again inside the /26 but no on the outgoing interface)&lt;/P&gt;&lt;P&gt;There are two weird things happening :&lt;/P&gt;&lt;P&gt;1. My basic intrinsic NAT for internet drain does not function unless I modify the global_access access list which is not something I want to do.&lt;/P&gt;&lt;P&gt;2. &amp;nbsp;I have my basic NAT set as a static not a dynamic yet it still functions as a dynamic PAT on a single IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 9.4 NAT documentation seems rather confused on how to proper attain this. &amp;nbsp;Does anyone have any suggestions. &amp;nbsp;I'm rather stumped. &amp;nbsp;As based on the Documentation my config should not even work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE I can provide a heavily obfuscated Config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if people have Seen this issue. &amp;nbsp;The documentation is rife with contradictions and false leads as to what my issue is.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649187#M200751</guid>
      <dc:creator>artemis88</dc:creator>
      <dc:date>2019-03-12T05:50:00Z</dc:date>
    </item>
    <item>
      <title>Post the config please?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649188#M200805</link>
      <description>&lt;P&gt;Post the config please?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 22:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649188#M200805</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-04-24T22:14:09Z</dc:date>
    </item>
    <item>
      <title>Please NOTE Heavily</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649189#M200822</link>
      <description>&lt;P&gt;Please NOTE Heavily Obfuscated : &amp;nbsp;All public&amp;nbsp;turned to 10.255.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTES : &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;All Internet Traffic unless it's in a static NAT should be translated to&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.255.37.60&lt;/P&gt;&lt;P&gt;Primary Out Interface uses 10.255.37.61&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the config&lt;/P&gt;&lt;P&gt;Connected:@ 2015.04.24 - 08:41 - User Levi Pederson&lt;BR /&gt;Type help or '?' for a list of available commands.&lt;BR /&gt;saasa&amp;gt; en&lt;BR /&gt;Password: ********&lt;BR /&gt;saasa# show run&lt;BR /&gt;: Saved&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&lt;BR /&gt;: Serial Number:&amp;nbsp;&lt;BR /&gt;: Hardware: &amp;nbsp; ASA5515, 8192 MB RAM, CPU Clarkdale 3058 MHz, 1 CPU (4 cores)&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.4(1)&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;hostname saasa&lt;BR /&gt;domain-name domain.name&lt;BR /&gt;enable password encrypted&lt;BR /&gt;password encrypted&lt;BR /&gt;names&lt;BR /&gt;ip local pool ANYCONNECT-POOL 192.168.100.1-192.168.100.254 mask 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.10.1.1 255.255.255.240&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;nameif emaildmz&lt;BR /&gt;&amp;nbsp;security-level 10&lt;BR /&gt;&amp;nbsp;ip address 10.10.3.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;description "DMZ -2"&lt;BR /&gt;&amp;nbsp;nameif asa-dmz&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/4&lt;BR /&gt;&amp;nbsp;nameif mnetworks-outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address dhcp&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/5&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 10.255.37.61 255.255.255.192&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.50.0.10 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa941-smp-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;name-server 10.1.0.4&lt;BR /&gt;&amp;nbsp;name-server 10.2.0.4&lt;BR /&gt;&amp;nbsp;name-server 10.1.0.55&lt;BR /&gt;&amp;nbsp;domain-name domain.name&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network mailgate&lt;BR /&gt;&amp;nbsp;host 10.10.3.2&lt;BR /&gt;object network HPLJ4300&lt;BR /&gt;&amp;nbsp;host 10.2.2.140&lt;BR /&gt;object network HPColor-Printer&lt;BR /&gt;&amp;nbsp;host 10.2.2.139&lt;BR /&gt;object network svpdpc86&lt;BR /&gt;&amp;nbsp;host 10.2.2.155&lt;BR /&gt;object network svpdpc83&lt;BR /&gt;&amp;nbsp;host 10.2.2.156&lt;BR /&gt;object network svpdpc84&lt;BR /&gt;&amp;nbsp;host 10.2.2.163&lt;BR /&gt;object network svpdpc60&lt;BR /&gt;&amp;nbsp;host 10.2.2.166&lt;BR /&gt;object network pdoff08&lt;BR /&gt;&amp;nbsp;host 10.2.0.190&lt;BR /&gt;object network svpdpc79&lt;BR /&gt;&amp;nbsp;host 10.2.2.118&lt;BR /&gt;object network svpdlt25&lt;BR /&gt;&amp;nbsp;host 10.2.2.172&lt;BR /&gt;object network svpdpc74&lt;BR /&gt;&amp;nbsp;host 10.2.2.173&lt;BR /&gt;object network svpdpc67&lt;BR /&gt;&amp;nbsp;host 10.2.2.174&lt;BR /&gt;object network svpdpc27&lt;BR /&gt;&amp;nbsp;host 10.2.2.178&lt;BR /&gt;object network svpdpc81&lt;BR /&gt;&amp;nbsp;host 10.2.2.157&lt;BR /&gt;object network HPLJ1320&lt;BR /&gt;&amp;nbsp;host 10.2.2.233&lt;BR /&gt;object network CableCast&lt;BR /&gt;&amp;nbsp;host 10.1.2.124&lt;BR /&gt;object network svpdpc78&lt;BR /&gt;&amp;nbsp;host 10.2.2.119&lt;BR /&gt;object network HPLJ4350&lt;BR /&gt;&amp;nbsp;host 10.2.2.191&lt;BR /&gt;object network DNSSrv&lt;BR /&gt;&amp;nbsp;host 10.1.0.55&lt;BR /&gt;object network LaserFiechSrv&lt;BR /&gt;&amp;nbsp;host 10.1.0.198&lt;BR /&gt;object network emaildmz&lt;BR /&gt;&amp;nbsp;host 10.0.1.18&lt;BR /&gt;object network glacius&lt;BR /&gt;&amp;nbsp;host 10.1.0.165&lt;BR /&gt;object network svpdpc45&lt;BR /&gt;&amp;nbsp;host 10.2.2.217&lt;BR /&gt;object network pdoff06&lt;BR /&gt;&amp;nbsp;host 10.2.2.115&lt;BR /&gt;object network pdoff01&lt;BR /&gt;&amp;nbsp;host 10.2.2.110&lt;BR /&gt;object network pdoff03&lt;BR /&gt;&amp;nbsp;host 10.2.2.112&lt;BR /&gt;object network pdoff02&lt;BR /&gt;&amp;nbsp;host 10.2.2.111&lt;BR /&gt;object network pdoff05&lt;BR /&gt;&amp;nbsp;host 10.2.2.114&lt;BR /&gt;object network pdoff04&lt;BR /&gt;&amp;nbsp;host 10.2.2.113&lt;BR /&gt;object network svpdpc53&lt;BR /&gt;&amp;nbsp;host 10.2.2.225&lt;BR /&gt;object network ViewSecSrv&lt;BR /&gt;&amp;nbsp;host 10.9.0.7&lt;BR /&gt;object network svpdpc68&lt;BR /&gt;&amp;nbsp;host 10.2.2.228&lt;BR /&gt;object network WebTracSrv&lt;BR /&gt;&amp;nbsp;host 10.3.0.13&lt;BR /&gt;object network WebServer&lt;BR /&gt;&amp;nbsp;host 10.1.0.38&lt;BR /&gt;object network HPLJ1300n&lt;BR /&gt;&amp;nbsp;host 10.2.2.126&lt;BR /&gt;object network svpdpc75&lt;BR /&gt;&amp;nbsp;host 10.2.2.243&lt;BR /&gt;object network HPLJ1320b&lt;BR /&gt;&amp;nbsp;host 10.2.0.203&lt;BR /&gt;object network svpdpc87&lt;BR /&gt;&amp;nbsp;host 10.2.2.167&lt;BR /&gt;object network HelpDeskSrv&lt;BR /&gt;&amp;nbsp;host 10.1.0.49&lt;BR /&gt;object network svpdpc80&lt;BR /&gt;&amp;nbsp;host 10.2.2.246&lt;BR /&gt;object network svpdpc56&lt;BR /&gt;&amp;nbsp;host 10.2.2.190&lt;BR /&gt;object network svpdpc64&lt;BR /&gt;&amp;nbsp;host 10.2.2.227&lt;BR /&gt;object network pdoff07&lt;BR /&gt;&amp;nbsp;host 10.2.2.116&lt;BR /&gt;object network svpdpc89&lt;BR /&gt;&amp;nbsp;host 10.2.2.117&lt;BR /&gt;object network FinanceSvr&lt;BR /&gt;&amp;nbsp;host 10.1.0.44&lt;BR /&gt;object network ENMMailSvr&lt;BR /&gt;&amp;nbsp;host 10.51.0.2&lt;BR /&gt;object network MailServer&lt;BR /&gt;&amp;nbsp;host 10.1.0.20&lt;BR /&gt;object network svpdpc85&lt;BR /&gt;&amp;nbsp;host 10.2.2.154&lt;BR /&gt;object network Source-NAT&lt;BR /&gt;&amp;nbsp;host 10.255.37.60&lt;BR /&gt;object network Scott-County&lt;BR /&gt;&amp;nbsp;host 10.255.27.202&lt;BR /&gt;object network county-gcweba&lt;BR /&gt;&amp;nbsp;host 156.98.10.33&lt;BR /&gt;object network wolfie&lt;BR /&gt;&amp;nbsp;host 10.255.27.203&lt;BR /&gt;object network ENMNetwork&lt;BR /&gt;&amp;nbsp;subnet 10.100.1.0 255.255.255.0&lt;BR /&gt;object network access-102-obj-allowed-in&lt;BR /&gt;&amp;nbsp;subnet 192.168.100.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description "Allowed Access in to Network 10.0.0.0 255.192.0.0"&lt;BR /&gt;object network default-coS-NAT&lt;BR /&gt;&amp;nbsp;host 10.255.37.60&lt;BR /&gt;object network remote-access-vpn&lt;BR /&gt;&amp;nbsp;subnet 192.168.100.0 255.255.255.0&lt;BR /&gt;object network VPN-Remote-access&lt;BR /&gt;&amp;nbsp;subnet 192.168.100.0 255.255.255.0&lt;BR /&gt;object service FirePanel8888&lt;BR /&gt;&amp;nbsp;service tcp source eq 8888&amp;nbsp;&lt;BR /&gt;object network local-access-01&lt;BR /&gt;&amp;nbsp;subnet 10.0.0.0 255.0.0.0&lt;BR /&gt;object network AnyConnect-VPN-Pool&lt;BR /&gt;&amp;nbsp;subnet 192.168.100.0 255.255.255.0&lt;BR /&gt;object network McAfee-SaaS-1st&lt;BR /&gt;&amp;nbsp;range Public-1 Public-2&lt;BR /&gt;&amp;nbsp;description E-mail Cloud Filtering&lt;BR /&gt;object network McAfee-SaaS-2nd&lt;BR /&gt;&amp;nbsp;range Public-1 Public-2&lt;BR /&gt;&amp;nbsp;description E-mail Cloud Filtering&lt;BR /&gt;object network firepanel-public&lt;BR /&gt;&amp;nbsp;host 10.255.37.34&lt;BR /&gt;object network LaserJet-SO&lt;BR /&gt;&amp;nbsp;host 10.2.2.183&lt;BR /&gt;object network 10-255-99-27-24&lt;BR /&gt;&amp;nbsp;subnet 10.255.27.0 255.255.255.0&lt;BR /&gt;object network COS_Source-NAT&lt;BR /&gt;&amp;nbsp;subnet 10.0.0.0 255.0.0.0&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq pop3&lt;BR /&gt;&amp;nbsp;port-object eq smtp&lt;BR /&gt;object-group network ASARemoteNetworks&lt;BR /&gt;&amp;nbsp;network-object 10.1.0.0 255.255.252.0&lt;BR /&gt;&amp;nbsp;network-object 10.9.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.51.0.0 255.255.255.0&lt;BR /&gt;object-group service DM_INLINE_SERVICE_1&lt;BR /&gt;&amp;nbsp;service-object ip&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq www&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq https&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq 1081&amp;nbsp;&lt;BR /&gt;object-group network ENMPD_REMOTE_NETWORK&lt;BR /&gt;&amp;nbsp;network-object 10.102.1.0 255.255.255.0&lt;BR /&gt;object-group network COS_LOCAL&lt;BR /&gt;&amp;nbsp;network-object 10.1.0.0 255.255.252.0&lt;BR /&gt;&amp;nbsp;network-object 10.2.0.0 255.255.252.0&lt;BR /&gt;&amp;nbsp;network-object 10.51.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.9.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object host 156.98.10.33&lt;BR /&gt;&amp;nbsp;network-object host 10.255.27.202&lt;BR /&gt;&amp;nbsp;network-object host 10.255.27.203&lt;BR /&gt;object-group network ENMPW_REMOTE_NETWORK&lt;BR /&gt;&amp;nbsp;network-object 10.101.1.0 255.255.255.0&lt;BR /&gt;object-group network COS_LOCAL-PW&lt;BR /&gt;&amp;nbsp;network-object 10.1.0.0 255.255.252.0&lt;BR /&gt;&amp;nbsp;network-object 10.51.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.9.0.0 255.255.255.0&lt;BR /&gt;object-group service DM_INLINE_TCP_3 tcp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt;&amp;nbsp;protocol-object udp&lt;BR /&gt;&amp;nbsp;protocol-object tcp&lt;BR /&gt;object-group service DM_INLINE_SERVICE_3&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq 4172&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq www&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq https&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object udp destination eq 4172&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq 22443&amp;nbsp;&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq 8443&amp;nbsp;&lt;BR /&gt;object-group network finance-external-hosts&lt;BR /&gt;&amp;nbsp;network-object host 108.166.31.220&lt;BR /&gt;&amp;nbsp;network-object host 209.198.206.133&lt;BR /&gt;&amp;nbsp;network-object host 209.198.206.134&lt;BR /&gt;&amp;nbsp;network-object host 209.198.206.135&lt;BR /&gt;&amp;nbsp;network-object host 209.198.206.136&lt;BR /&gt;object-group network access-102-ogn&lt;BR /&gt;&amp;nbsp;network-object 10.10.10.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.10.2.0 255.255.254.0&lt;BR /&gt;&amp;nbsp;network-object 192.168.100.0 255.255.255.0&lt;BR /&gt;object-group service DM_INLINE_TCP_4 tcp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;object-group service https-udp udp&lt;BR /&gt;&amp;nbsp;port-object eq 443&lt;BR /&gt;object-group network McAfee-SaaS&lt;BR /&gt;&amp;nbsp;description E-mail Cloud Filtering&lt;BR /&gt;&amp;nbsp;network-object object McAfee-SaaS-1st&lt;BR /&gt;&amp;nbsp;network-object object McAfee-SaaS-2nd&lt;BR /&gt;object-group network firepanel-local-ip&lt;BR /&gt;&amp;nbsp;network-object host 10.1.0.61&lt;BR /&gt;&amp;nbsp;network-object host 10.3.0.9&lt;BR /&gt;&amp;nbsp;network-object host 10.6.2.40&lt;BR /&gt;&amp;nbsp;network-object host 10.6.2.41&lt;BR /&gt;&amp;nbsp;network-object host 10.7.0.20&lt;BR /&gt;&amp;nbsp;network-object host 10.8.0.4&lt;BR /&gt;&amp;nbsp;network-object host 10.22.0.10&lt;BR /&gt;access-list allow-all standard permit any4&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit ip 10.0.0.0 255.248.0.0 10.10.10.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit ip 10.0.0.0 255.248.0.0 10.10.2.0 255.255.254.0&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit ip 10.0.0.0 255.192.0.0 192.168.100.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit ip object-group COS_LOCAL object-group ENMPD_REMOTE_NETWORK&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit ip object-group COS_LOCAL-PW object-group ENMPW_REMOTE_NETWORK&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit ip object-group ASARemoteNetworks host 10.253.253.2&amp;nbsp;&lt;BR /&gt;access-list global_mpc extended permit tcp any any object-group DM_INLINE_TCP_1&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object mailgate eq smtp&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp object-group McAfee-SaaS object MailServer eq smtp&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object MailServer object-group DM_INLINE_TCP_3&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp host 172.16.12.4 10.255.37.0 255.255.255.192&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp 208.38.68.128 255.255.255.192 object svpdpc56 eq 9100&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object CableCast eq www&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any any eq pptp&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit gre any any&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object HPLJ4300 eq 9100&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit object-group TCPUDP any object DNSSrv eq domain&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit ip 10.255.27.0 255.255.255.0 object HPLJ4350&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit ip object 10-255-99-27-24 object LaserJet-SO&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit ip 10.255.27.0 255.255.255.0 object HPLJ1300n&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit ip 207.7.154.0 255.255.255.0 object glacius&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object LaserFiechSrv eq www&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object HPLJ1320 eq 9100&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object HPLJ1320b eq 9100&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object HelpDeskSrv eq www&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit tcp any object WebTracSrv object-group DM_INLINE_TCP_4&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit udp any object WebTracSrv eq www&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit udp any object WebTracSrv eq 443&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_1 object-group finance-external-hosts object FinanceSvr&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_1 host 108.166.31.220 object FinanceSvr&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_3 any object ViewSecSrv&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit icmp any any log disable&amp;nbsp;&lt;BR /&gt;access-list outside_access_in remark Elko New Market Mail Server &amp;nbsp;"ENMMAIL"&lt;BR /&gt;access-list emaildmz_access_in extended permit tcp host 10.10.3.2 host 10.1.0.20&amp;nbsp;&lt;BR /&gt;access-list emaildmz_access_in extended permit ip host 10.10.3.2 host 10.1.0.20&amp;nbsp;&lt;BR /&gt;access-list emaildmz_access_in extended permit ip host 10.10.3.2 host 10.1.0.55&amp;nbsp;&lt;BR /&gt;access-list emaildmz_access_in extended permit ip host 10.10.3.2 10.0.0.0 255.192.0.0&amp;nbsp;&lt;BR /&gt;access-list emaildmz_access_in extended permit ip host 10.10.3.2 any&amp;nbsp;&lt;BR /&gt;access-list ENM-Remote_access_in extended permit ip host 10.253.253.2 object-group ASARemoteNetworks&amp;nbsp;&lt;BR /&gt;access-list outside_2_cryptomap extended permit ip object-group COS_LOCAL object-group ENMPD_REMOTE_NETWORK&amp;nbsp;&lt;BR /&gt;access-list sfr_redirect extended permit ip any any&amp;nbsp;&lt;BR /&gt;access-list VPN_NAT extended permit ip 192.168.100.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list VPN_NAT extended permit ip 10.102.1.0 255.255.255.0 object SC-local&lt;BR /&gt;access-list VPN_NAT extended permit ip 10.102.1.0 255.255.255.0 object SC-local-gwca&lt;BR /&gt;access-list global-access extended permit ip any any&amp;nbsp;&lt;BR /&gt;access-list Tunnel webtype permit tcp 10.0.0.0 255.0.0.0 log default&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging buffer-size 64000&lt;BR /&gt;logging buffered notifications&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu emaildmz 1500&lt;BR /&gt;mtu asa-dmz 1500&lt;BR /&gt;mtu mnetworks-outside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;no failover&lt;BR /&gt;no monitor-interface service-module&amp;nbsp;&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-741.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;!&lt;BR /&gt;object network mailgate&lt;BR /&gt;&amp;nbsp;nat (emaildmz,outside) static 10.255.37.3&lt;BR /&gt;object network HPLJ4300&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.33&lt;BR /&gt;object network HPColor-Printer&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.37&lt;BR /&gt;object network svpdpc86&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.38&lt;BR /&gt;object network svpdpc83&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.39&lt;BR /&gt;object network svpdpc84&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.44&lt;BR /&gt;object network svpdpc60&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.47&lt;BR /&gt;object network pdoff08&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.49&lt;BR /&gt;object network svpdpc79&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.52&lt;BR /&gt;object network svpdlt25&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.53&lt;BR /&gt;object network svpdpc74&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.54&lt;BR /&gt;object network svpdpc67&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.55&lt;BR /&gt;object network svpdpc27&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.59&lt;BR /&gt;object network svpdpc81&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.31&lt;BR /&gt;object network HPLJ1320&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.48&lt;BR /&gt;object network CableCast&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.12&lt;BR /&gt;object network svpdpc78&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.24&lt;BR /&gt;object network HPLJ4350&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.26&lt;BR /&gt;object network DNSSrv&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.27&lt;BR /&gt;object network LaserFiechSrv&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.11&lt;BR /&gt;object network emaildmz&lt;BR /&gt;&amp;nbsp;nat (inside,emaildmz) static 10.0.1.18&lt;BR /&gt;object network glacius&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.14&lt;BR /&gt;object network svpdpc45&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.6&lt;BR /&gt;object network pdoff06&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.16&lt;BR /&gt;object network pdoff01&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.18&lt;BR /&gt;object network pdoff03&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.19&lt;BR /&gt;object network pdoff02&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.28&lt;BR /&gt;object network pdoff05&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.29&lt;BR /&gt;object network pdoff04&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.40&lt;BR /&gt;object network svpdpc53&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.41&lt;BR /&gt;object network ViewSecSrv&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.42&lt;BR /&gt;object network svpdpc68&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.51&lt;BR /&gt;object network WebTracSrv&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.20&lt;BR /&gt;object network HPLJ1300n&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.25&lt;BR /&gt;object network svpdpc75&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.8&lt;BR /&gt;object network HPLJ1320b&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.30&lt;BR /&gt;object network svpdpc87&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.5&lt;BR /&gt;object network HelpDeskSrv&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.35&lt;BR /&gt;object network svpdpc80&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.7&lt;BR /&gt;object network svpdpc56&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.9&lt;BR /&gt;object network svpdpc64&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.15&lt;BR /&gt;object network pdoff07&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.22&lt;BR /&gt;object network svpdpc89&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.23&lt;BR /&gt;object network FinanceSvr&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.50&lt;BR /&gt;object network MailServer&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.2&lt;BR /&gt;object network svpdpc85&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.32&lt;BR /&gt;object network LaserJet-SO&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.255.37.10&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) after-auto source static firepanel-local-ip firepanel-public description "Mapped FirePanel Block 10.255.37.34"&lt;BR /&gt;nat (inside,outside) after-auto source static any any destination static VPN-Remote-access VPN-Remote-access&lt;BR /&gt;nat (inside,outside) after-auto source static LOCAL_NETWORS-COS destination static ENMPD_REMOTE_NETWORK ENMPD_REMOTE_NETWORK&lt;BR /&gt;nat (inside,outside) after-auto source static any Source-NAT&lt;BR /&gt;nat (inside,outside) after-auto source dynamic COS_Source-NAT Source-NAT&lt;BR /&gt;nat (inside,outside) after-auto source dynamic access-102-ogn default-coS-NAT inactive&lt;BR /&gt;nat (outside,inside) after-auto source static AnyConnect-VPN-Pool AnyConnect-VPN-Pool destination static local-access-01 local-access-01&lt;BR /&gt;access-group emaildmz_access_in in interface emaildmz&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 10.255.37.62 1&lt;BR /&gt;route inside 10.0.0.0 255.192.0.0 10.10.1.2 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;aaa-server TACACS+ protocol tacacs+&lt;BR /&gt;aaa-server RADIUS protocol radius&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&amp;nbsp;&lt;BR /&gt;sysopt noproxyarp inside&lt;BR /&gt;sysopt noproxyarp emaildmz&lt;BR /&gt;sysopt noproxyarp asa-dmz&lt;BR /&gt;sysopt noproxyarp mnetworks-outside&lt;BR /&gt;sysopt noproxyarp management&lt;BR /&gt;telnet 10.0.0.0 255.0.0.0 inside&lt;BR /&gt;telnet 192.168.10.0 255.255.255.0 inside&lt;BR /&gt;telnet Public-2&amp;nbsp;255.255.255.255 outside&lt;BR /&gt;telnet 192.168.10.0 255.255.255.0 management&lt;BR /&gt;telnet timeout 10&lt;BR /&gt;no ssh stricthostkeycheck&lt;BR /&gt;ssh 10.0.0.0 255.0.0.0 inside&lt;BR /&gt;ssh 192.168.10.0 255.255.255.0 inside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh public-3 255.255.255.255 outside&lt;BR /&gt;ssh timeout 10&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;management-access inside&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics port&lt;BR /&gt;threat-detection statistics protocol&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp authenticate&lt;BR /&gt;ntp server 10.1.0.50 source inside prefer&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;class-map sfr_cm&lt;BR /&gt;&amp;nbsp;match access-list sfr_redirect&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect icmp&amp;nbsp;&lt;BR /&gt;&amp;nbsp;class sfr_cm&lt;BR /&gt;&amp;nbsp; sfr fail-open&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 15:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649189#M200822</guid>
      <dc:creator>artemis88</dc:creator>
      <dc:date>2015-04-27T15:22:46Z</dc:date>
    </item>
    <item>
      <title>Please NOTE Heavily</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649190#M200836</link>
      <description>&lt;P&gt;Accidentally Double Posted : deleted&lt;/P&gt;&lt;P&gt;Levi&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 15:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649190#M200836</guid>
      <dc:creator>artemis88</dc:creator>
      <dc:date>2015-04-27T15:23:41Z</dc:date>
    </item>
    <item>
      <title>Please NOTE Heavily</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649191#M200851</link>
      <description>&lt;P&gt;triple posted - Error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Levi&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 15:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649191#M200851</guid>
      <dc:creator>artemis88</dc:creator>
      <dc:date>2015-04-27T15:24:21Z</dc:date>
    </item>
    <item>
      <title>Hi. Where is your PAT rule? I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649192#M200862</link>
      <description>&lt;P&gt;Hi. Where is your PAT rule? I can't seem to find it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing you need to remember is that NAT rules are processed in order, so when you have multiple rules matching a request through the firewall, the first rule that matches will be processed. Why do you have so many static nat rules for printers and other hosts? Which devices do you want to provide internet access to?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2015 15:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-9-4-nat-conundrum/m-p/2649192#M200862</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-04-27T15:58:38Z</dc:date>
    </item>
  </channel>
</rss>

