<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I am running 9.1.2. I guess in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-nat/m-p/2564309#M206096</link>
    <description>&lt;P&gt;I am running 9.1.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess object nat is almost the same as command "nat (inside,DMZ) source dynamic 192.168.21.0/24 interface, isn't it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, I tried that, does not work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like DMZ interface didn't know where to forward the traffic, so no NAT is performed. I tried to remove default route on outside (to internet) and then "nat (inside,outside)" was not working as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I can't add another route for inteface DMZ...And DMZ should know the "default route" by command "nat (DMZ,outside) source dynamic DMZ interface.&lt;/P&gt;&lt;P&gt;Thx anyway for you suggestion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;edit : I managed to inside network be translated finally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (inside,dmz) source dynamic pat-pool PAT-POOL interface destination static ANY any; PAT-POOL is ip address from DMZ subnet&lt;/P&gt;&lt;P&gt;UDP PAT from inside:10.0.0.2/61028 to dmz:192.168.200.222/61028 flags ri idle 0:00:10 timeout 0:00:30&lt;BR /&gt;UDP PAT from inside:10.0.0.2/61060 to dmz:192.168.200.222/61060 flags ri idle 0:00:24 timeout 0:00:30&lt;BR /&gt;UDP PAT from inside:10.0.0.2/55226 to dmz:192.168.200.222/55226 flags ri idle 0:00:24 timeout 0:00:30&lt;BR /&gt;ICMP PAT from inside:10.0.0.2/1 to dmz:192.168.200.222/1 flags ri idle 0:00:01 timeout 0:00:30&lt;BR /&gt;ciscoasa(config)#&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But but even if I have "nat (dmz,outside) source dynamic dmz interface" command, 192.168.200.222 cannot reach internet &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Oct 2014 10:24:59 GMT</pubDate>
    <dc:creator>Jiri Chvatal</dc:creator>
    <dc:date>2014-10-14T10:24:59Z</dc:date>
    <item>
      <title>Cisco ASA problem with NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-nat/m-p/2564307#M206094</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to accomplish following task :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some DMZ zone on ASA. It has access only to internet, not to inside network. This is network used for visitors.&lt;/P&gt;&lt;P&gt;I would like to perform nat from inside subnet to DMZ and then from DMZ to outside. Why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two facilities, only one ASA as GW. I cannot directly connect second facility to ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So let's say I need for example network 172.16.20.0 /24 to be nated to DMZ interface. And DMZ interface has nat (DMZ,outside) source dynamic DMZ-LAN interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem I have is, ASA cannot do NAT from inside network to DMZ. Inside to outside works just fine. See the config part below :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.21.201 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;nameif DMZ&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.30.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (inside,DMZ) after-auto&amp;nbsp;source dynamic WIFI_NAT (172.16.10.0/24)&amp;nbsp;interface - this is command ASA ignores&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) after-auto source dynamic DMZ interface - this command works fine (dmz network can access internet)&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source dynamic (172.16.1.0/24)&amp;nbsp;interface - this command works fine, subnet 172.16.1.0/24 can access internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access lists are set for test purpose all to permit ip any any.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas, why xlate from inside to DMZ is not working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-nat/m-p/2564307#M206094</guid>
      <dc:creator>Jiri Chvatal</dc:creator>
      <dc:date>2019-03-12T04:55:08Z</dc:date>
    </item>
    <item>
      <title>What code are you running?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-nat/m-p/2564308#M206095</link>
      <description>&lt;P&gt;What code are you running? Why not&amp;nbsp;use object NAT?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network Inside&lt;/P&gt;&lt;P&gt;subnet 192.168.21.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside,dmz) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So anyone coming into the DMZ from the Inside will NAT to 192.168.30.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 19:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-nat/m-p/2564308#M206095</guid>
      <dc:creator>david-swope</dc:creator>
      <dc:date>2014-10-13T19:51:50Z</dc:date>
    </item>
    <item>
      <title>I am running 9.1.2. I guess</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-nat/m-p/2564309#M206096</link>
      <description>&lt;P&gt;I am running 9.1.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess object nat is almost the same as command "nat (inside,DMZ) source dynamic 192.168.21.0/24 interface, isn't it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, I tried that, does not work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like DMZ interface didn't know where to forward the traffic, so no NAT is performed. I tried to remove default route on outside (to internet) and then "nat (inside,outside)" was not working as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I can't add another route for inteface DMZ...And DMZ should know the "default route" by command "nat (DMZ,outside) source dynamic DMZ interface.&lt;/P&gt;&lt;P&gt;Thx anyway for you suggestion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;edit : I managed to inside network be translated finally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (inside,dmz) source dynamic pat-pool PAT-POOL interface destination static ANY any; PAT-POOL is ip address from DMZ subnet&lt;/P&gt;&lt;P&gt;UDP PAT from inside:10.0.0.2/61028 to dmz:192.168.200.222/61028 flags ri idle 0:00:10 timeout 0:00:30&lt;BR /&gt;UDP PAT from inside:10.0.0.2/61060 to dmz:192.168.200.222/61060 flags ri idle 0:00:24 timeout 0:00:30&lt;BR /&gt;UDP PAT from inside:10.0.0.2/55226 to dmz:192.168.200.222/55226 flags ri idle 0:00:24 timeout 0:00:30&lt;BR /&gt;ICMP PAT from inside:10.0.0.2/1 to dmz:192.168.200.222/1 flags ri idle 0:00:01 timeout 0:00:30&lt;BR /&gt;ciscoasa(config)#&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But but even if I have "nat (dmz,outside) source dynamic dmz interface" command, 192.168.200.222 cannot reach internet &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 10:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-nat/m-p/2564309#M206096</guid>
      <dc:creator>Jiri Chvatal</dc:creator>
      <dc:date>2014-10-14T10:24:59Z</dc:date>
    </item>
  </channel>
</rss>

