<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,I think the only other in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591438#M203492</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think the only other possible way to reduce the NAT statements would be to use the object groups in the NAT statements.&lt;/P&gt;&lt;P&gt;Object-group network source&lt;/P&gt;&lt;P&gt;object src1&lt;/P&gt;&lt;P&gt;object src2&lt;/P&gt;&lt;P&gt;object src3&lt;/P&gt;&lt;P&gt;Object-group network destination&lt;/P&gt;&lt;P&gt;object dest1&lt;/P&gt;&lt;P&gt;object dest2&lt;/P&gt;&lt;P&gt;object dest3&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static source source-translated destination static destination-translated destination&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Sat, 22 Nov 2014 09:26:40 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2014-11-22T09:26:40Z</dc:date>
    <item>
      <title>Multiple static source NATs to multiple static destination NATs</title>
      <link>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591436#M203490</link>
      <description>&lt;P&gt;I have been presented with a NAT scenario that I'm trying to work though, basically it is a src and dst nat like so:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src1-original src1-translated destination static dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The twist is there are a large number of (random) source nats, over 100 of them, so it then looks like so:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src1-original src1-translated destination static dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src2-original src2-translated destination static dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src3-original src3-translated destination static dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the plot thickens... they also have 100+ random dst NATs we need to account for... for an example of 3 servers on each side, that's 9 lines of nat:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src1-original src1-translated destination static dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src2-original src2-translated destination static dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src3-original src3-translated destination static dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src1-original src1-translated destination static dst2-original dst2-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src2-original src2-translated destination static dst2-original dst2-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src3-original src3-translated destination static dst2-original dst2-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src1-original src1-translated destination static dst3-original dst3-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src2-original src2-translated destination static dst3-original dst3-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src3-original src3-translated destination static dst3-original dst3-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we get up to 100 servers on each side, a static mesh of these NATs gets up to 10000 lines of NAT. Eeek! I've been trying to lab out other ways to do this more effectively but am stumped. Is there a better way to go about this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591436#M203490</guid>
      <dc:creator>parsonsproject1</dc:creator>
      <dc:date>2019-03-12T05:07:25Z</dc:date>
    </item>
    <item>
      <title>If I can have it evaluate NAT</title>
      <link>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591437#M203491</link>
      <description>&lt;P&gt;If I can have it evaluate&amp;nbsp;NAT two different times&amp;nbsp;that could help reduce it to 200 lines if there are 100 servers on each side.&amp;nbsp;The first pass-through does the src translation:&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static src1-original src1-translated destination static dst-subnet-original dst-subnet-original&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;nat (inside,outside) source static src2-original src2-translated destination static dst-subnet-original dst-subnet-original&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;nat (inside,outside) source static src3-original src3-translated destination static dst-subnet-original dst-subnet-original&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the source is translated then the second pass-through&amp;nbsp;evaluates does the&amp;nbsp;dst translation:&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static &lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;src-subnet-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;src-subnet-translated&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt;destination static &lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;dst1-original dst1-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static &lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;src-subnet-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;src-subnet-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt; destination static &lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;dst2-original dst2-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static &lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;src-subnet-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;src-subnet-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt; destination static &lt;/STRONG&gt;&lt;/EM&gt;&lt;EM style="font-size: 14px;"&gt;&lt;STRONG&gt;dst3-original dst3-translated&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2014 22:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591437#M203491</guid>
      <dc:creator>parsonsproject1</dc:creator>
      <dc:date>2014-11-21T22:43:02Z</dc:date>
    </item>
    <item>
      <title>Hi,I think the only other</title>
      <link>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591438#M203492</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think the only other possible way to reduce the NAT statements would be to use the object groups in the NAT statements.&lt;/P&gt;&lt;P&gt;Object-group network source&lt;/P&gt;&lt;P&gt;object src1&lt;/P&gt;&lt;P&gt;object src2&lt;/P&gt;&lt;P&gt;object src3&lt;/P&gt;&lt;P&gt;Object-group network destination&lt;/P&gt;&lt;P&gt;object dest1&lt;/P&gt;&lt;P&gt;object dest2&lt;/P&gt;&lt;P&gt;object dest3&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) source static source source-translated destination static destination-translated destination&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Sat, 22 Nov 2014 09:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591438#M203492</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-11-22T09:26:40Z</dc:date>
    </item>
    <item>
      <title>Thank you Vibhor that worked</title>
      <link>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591439#M203493</link>
      <description>&lt;P&gt;Thank you Vibhor that worked as expected during my testing!&amp;nbsp;Using object-groups if it finds a match on let's say line 43 of the original source, it will go to line 43 for the translated-source object-group. So as long as the original source and translated source line up on the same lines between the two object groups, that works!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2014 16:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-static-source-nats-to-multiple-static-destination-nats/m-p/2591439#M203493</guid>
      <dc:creator>parsonsproject1</dc:creator>
      <dc:date>2014-11-24T16:05:21Z</dc:date>
    </item>
  </channel>
</rss>

