<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks,Could you please in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554039#M236861</link>
    <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Could you please assist me with cli syntax to do &amp;nbsp;NAT company1 to the shared printer lan. i got all this goofed up &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;nat (company1,shared) after-auto source static &amp;lt; got lost &amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jul 2014 14:42:03 GMT</pubDate>
    <dc:creator>f_westerlund</dc:creator>
    <dc:date>2014-07-03T14:42:03Z</dc:date>
    <item>
      <title>multi company network</title>
      <link>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554037#M236858</link>
      <description>&lt;P style="margin-top:0cm;margin-right:0cm;margin-bottom:7.5pt;margin-left:0cm;
line-height:15.0pt"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;Hi!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;I’m asked to setup a multi company network. There will be approximately 4-8 small companies around 8-15 people in each company.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;These companies will share some resources as printers and probably a nas. Furthermore they will have their own wlan ssid trunked from E0/7 to the AP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;Thinking about using asa5505 security plus license. AP will be this one AIR-SAP1602I-E-K9. As of now to allow more ports for users I will just hock up small simple switches to each Ethernet port on the ASA. When there are no more room I will buy a vlan capable switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;Each company per vlan.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;company1 Vlan10 192.168.10.0/24&lt;BR /&gt;company2 Vlan20 192.168.20.0/24&lt;BR /&gt;company3 Vlan30 192.168.30.0/24&lt;BR /&gt;company4 Vlan40 192.168.40.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;Shared Vlan100 192.168.100.0/24, printer ip 192.168.100.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;The companies should be separated from each other and only able to access the internet and the printer vlan. I got public ip in a 248 subnetmask giving me 6 addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;Company1 need to have 1 private ip. Also given ability to access their desktop PC from home. Other companies could share the same public IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;Copmany2 will host a web server so it also needs a public ip accessible from outside.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;Setting up Vlan and interfaces is no problem. The problems for me starts when creating NAT rules. Guess I will not use same-security-traffic permit inter-interface and use ACL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;How should you managed the traffic flow?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 7.5pt; line-height: 15pt;"&gt;&lt;SPAN lang="EN-US" style="font-family: Arial, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; line-height: 107%;"&gt;Br&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt; line-height: 107%; font-family: Arial, sans-serif;"&gt;Fredrik&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554037#M236858</guid>
      <dc:creator>f_westerlund</dc:creator>
      <dc:date>2019-03-12T04:25:05Z</dc:date>
    </item>
    <item>
      <title>You're on the right track.One</title>
      <link>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554038#M236859</link>
      <description>&lt;P&gt;You're on the right track.&lt;/P&gt;&lt;P&gt;One VLAN per company, each assigned to an interface, no same-security-traffic. Make them all security level 100. Make the printer VLAN 90.&lt;/P&gt;&lt;P&gt;Create a remote access VPN for company 1 with split tunnel and only give them route to their assigned network. Make the nat rule for them as nat(company1,outside) with dynamic translation to the outside interface. Make separate nat rules for the other companies as well with dynamic translation to one of your other public IPs. Make one specific port forwarding NAT rule for the company 2 webserver.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 13:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554038#M236859</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-07-03T13:00:51Z</dc:date>
    </item>
    <item>
      <title>Thanks,Could you please</title>
      <link>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554039#M236861</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Could you please assist me with cli syntax to do &amp;nbsp;NAT company1 to the shared printer lan. i got all this goofed up &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;nat (company1,shared) after-auto source static &amp;lt; got lost &amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 14:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554039#M236861</guid>
      <dc:creator>f_westerlund</dc:creator>
      <dc:date>2014-07-03T14:42:03Z</dc:date>
    </item>
    <item>
      <title>Actually no NAT is required</title>
      <link>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554040#M236862</link>
      <description>&lt;P&gt;Actually no NAT is required between the various company subnets and the shared printer subnet. They simply use the ASA interfaces assigned to them as their default gateway.&lt;/P&gt;&lt;P&gt;The ASA sees all the networks as connected and by default will allow connections to establish to a lower security level interface. NAT is not necessary and the addresses can remain in their "real" form.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 16:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-company-network/m-p/2554040#M236862</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-07-03T16:11:05Z</dc:date>
    </item>
  </channel>
</rss>

