<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 IOS: 9.0.3: Createing a group object and PAT range in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511232#M237925</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp; I need to add multiple entries of the following on a 5510 running asa903-k8.bin and ASDM-716.bin file.:&lt;/P&gt;&lt;P&gt;object network Mitel5000-01&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-02&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-03&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-04&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-05&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6031 6031&lt;BR /&gt;object network Mitel5000-01&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6032 6032&lt;BR /&gt;object network Mitel5000-02&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6033 6033&lt;BR /&gt;object network Mitel5000-03&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6034 6034&lt;BR /&gt;object network Mitel5000-04&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6035 6035&lt;BR /&gt;object network Mitel5000-05&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6036 6036&lt;BR /&gt;object network Mitel5000-06&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6037 6037&lt;/P&gt;&lt;P&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5004&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5005&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5006&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 50098&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way were I could just put a range in for all three of the configs? I am completely new and would love some help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:16:58 GMT</pubDate>
    <dc:creator>CSCO10812764</dc:creator>
    <dc:date>2019-03-12T04:16:58Z</dc:date>
    <item>
      <title>ASA 5510 IOS: 9.0.3: Createing a group object and PAT range</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511232#M237925</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp; I need to add multiple entries of the following on a 5510 running asa903-k8.bin and ASDM-716.bin file.:&lt;/P&gt;&lt;P&gt;object network Mitel5000-01&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-02&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-03&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-04&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;object network Mitel5000-05&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6031 6031&lt;BR /&gt;object network Mitel5000-01&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6032 6032&lt;BR /&gt;object network Mitel5000-02&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6033 6033&lt;BR /&gt;object network Mitel5000-03&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6034 6034&lt;BR /&gt;object network Mitel5000-04&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6035 6035&lt;BR /&gt;object network Mitel5000-05&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6036 6036&lt;BR /&gt;object network Mitel5000-06&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp 6037 6037&lt;/P&gt;&lt;P&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5004&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5005&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5006&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 50098&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way were I could just put a range in for all three of the configs? I am completely new and would love some help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:16:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511232#M237925</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2019-03-12T04:16:58Z</dc:date>
    </item>
    <item>
      <title>It is possible to group the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511233#M237926</link>
      <description>&lt;P&gt;It is possible to group the NAT statements into two statement.&lt;/P&gt;&lt;P&gt;access-list inbound extended permit udp any4 object Mitel5000 range 5004 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 eq 50098&lt;/P&gt;&lt;P&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;/P&gt;&lt;P&gt;object service Mitel-Ports1&lt;BR /&gt;&amp;nbsp; service udp destination range 5004 5007&lt;BR /&gt;object service Mitel-Ports2&lt;BR /&gt;&amp;nbsp; service udp destination eq 50098&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports1 Mitel-Ports1&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports2 Mitel-Ports2&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 10:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511233#M237926</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-04T10:51:22Z</dc:date>
    </item>
    <item>
      <title>Hi thanks for your help. Can</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511234#M237927</link>
      <description>&lt;P&gt;Hi thanks for your help. Can I ask does this look right?&lt;/P&gt;&lt;P&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;/P&gt;&lt;P&gt;object service Mitel-Ports1&lt;BR /&gt;&amp;nbsp; service udp destination range 5004 5007&lt;BR /&gt;object service Mitel-Ports2&lt;BR /&gt;&amp;nbsp; service udp destination range 6004 6261&lt;BR /&gt;object service Mitel-Ports3&lt;BR /&gt;&amp;nbsp; service udp destination range 6604 7039&lt;BR /&gt;object service Mitel-Ports4&lt;BR /&gt;&amp;nbsp; service udp destination range 50098 50508&lt;/P&gt;&lt;P&gt;access-list inbound extended permit udp any4 object Mitel5000 range 5004 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 range 6004 6261&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 range 6604 7039&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 range 50098 50508&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports1 Mitel-Ports1&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports2 Mitel-Ports2&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports3 Mitel-Ports3&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports4 Mitel-Ports4&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;And can this be shortened?&lt;/P&gt;&lt;P&gt;access-list inbound extended permit tcp any interface Outside eq 6800&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside eq 6801&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside eq 6802&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside eq 3998&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside eq 3999&lt;/P&gt;&lt;P&gt;To this?&lt;/P&gt;&lt;P&gt;access-list inbound extended permit tcp any interface Outside range 6800 6801&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 3998 3999&lt;/P&gt;&lt;P&gt;object service Mitel-Ports5&lt;BR /&gt;&amp;nbsp; service udp destination range 6800 6801&lt;BR /&gt;object service Mitel-Ports6&lt;BR /&gt;&amp;nbsp; service udp destination range 3998 3999&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports5 Mitel-Ports5&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports6 Mitel-Ports6&lt;/P&gt;&lt;P&gt;Thank you SOOOO very much for your help so far. I think I got it but would love your further input.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2014 18:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511234#M237927</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-05T18:56:57Z</dc:date>
    </item>
    <item>
      <title>This is my final config,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511235#M237928</link>
      <description>&lt;P&gt;This is my final config, would you please tell me if I have it right:&lt;/P&gt;&lt;P&gt;enable password XXXXXX&lt;BR /&gt;password XXXXXX&lt;BR /&gt;User Enable password XXXXXX&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;name 10.2.254.11 ECHS-PDC&lt;BR /&gt;name 10.2.254.12 ECHS-XCH&lt;BR /&gt;name 10.2.254.111 Mitel5000&lt;/P&gt;&lt;P&gt;int e0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Outside&lt;BR /&gt;security-level 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address X.X.X.X 255.255.255.240&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description WAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Inside&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.254.9 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description LAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;int e0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif VoIP-Link&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.111.1 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description VOIP Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int Management0/0&lt;BR /&gt;nameif Management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;no shutdown&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;telnet 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;telnet 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;http 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;http 192.168.1.0 255.255.255.0 Management&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.5 Management&lt;BR /&gt;dhcpd enable Management&lt;/P&gt;&lt;P&gt;ssh 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;ssh 192.168.1.0 255.255.255.0 Management&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;host 10.2.254.11&lt;BR /&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-list outbound extended permit gre any4 any4&lt;BR /&gt;access-list outbound extended permit tcp any4 any4 eq pptp&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq www&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq https&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-PDC eq pptp&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 range 5004 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 range 6004 6261&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 range 6604 7039&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000 range 50098 50508&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 6800 6801&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 3998 3999&lt;/P&gt;&lt;P&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp https https&lt;BR /&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp www www&lt;BR /&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp pptp pptp&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports1 Mitel-Ports1&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports2 Mitel-Ports2&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports3 Mitel-Ports3&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports4 Mitel-Ports4&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports5 Mitel-Ports5&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports6 Mitel-Ports6&lt;/P&gt;&lt;P&gt;object service Mitel-Ports1&lt;BR /&gt;&amp;nbsp; service udp destination range 5004 5007&lt;BR /&gt;object service Mitel-Ports2&lt;BR /&gt;&amp;nbsp; service udp destination range 6004 6261&lt;BR /&gt;object service Mitel-Ports3&lt;BR /&gt;&amp;nbsp; service udp destination range 6604 7039&lt;BR /&gt;object service Mitel-Ports4&lt;BR /&gt;&amp;nbsp; service udp destination range 50098 50508&lt;BR /&gt;object service Mitel-Ports5&lt;BR /&gt;&amp;nbsp; service udp destination range 6800 6801&lt;BR /&gt;object service Mitel-Ports6&lt;BR /&gt;&amp;nbsp; service udp destination range 3998 3999&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp; nat (Inside,Outside) dynamic interface&lt;/P&gt;&lt;P&gt;access-group inbound in interface Outside&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 X.X.X..49 1&lt;BR /&gt;route Inside 10.2.246.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.247.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.248.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.249.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.250.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.251.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.252.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.253.0 255.255.255.0 10.2.254.19 1&lt;/P&gt;&lt;P&gt;logging asdm 6&lt;BR /&gt;domain-name XXXXXXXXXXXXXXXXXXX&lt;BR /&gt;crypto key generate rsa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2014 19:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511235#M237928</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-05T19:11:53Z</dc:date>
    </item>
    <item>
      <title>Yes both those examples you</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511236#M237929</link>
      <description>&lt;P&gt;Yes both those examples you posted there look good but remember to reference the Mitel5000-HOST object group in the NAT statements.&lt;/P&gt;&lt;P&gt;As for your configuration&lt;STRONG&gt;&lt;EM&gt;, &lt;/EM&gt;&lt;/STRONG&gt;you are using an IP to name map that is referenced in the NAT statements.&amp;nbsp; You must reference an object group in the NAT statements so change Mitel5000 to Mitel5000-HOST.&lt;/P&gt;&lt;P&gt;Also, you do not have a dynamic PAT to allow internet access...even though you have an object group matching all traffic. I suggest adding a NAT statement for this object group if the users require access to the internet.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN style="font-size:18px;"&gt;&lt;STRONG&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Other than that it looks good.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 07:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511236#M237929</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T07:27:28Z</dc:date>
    </item>
    <item>
      <title>Hi Thanks for the replie. I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511237#M237930</link>
      <description>&lt;P&gt;Hi Thanks for the replie. I really apperciate your help.&amp;nbsp; A couple a quick questions.&amp;nbsp; I am not sure what you mean by "reference the Mitel5000-HOST object group in the NAT statements."&lt;/P&gt;&lt;P&gt;Am I correct in saying I need to change this bit:&lt;/P&gt;&lt;P&gt;name 10.2.254.11 ECHS-PDC&lt;BR /&gt;name 10.2.254.12 ECHS-XCH&lt;BR /&gt;name 10.2.254.111 Mitel5000&lt;/P&gt;&lt;P&gt;to this:&lt;/P&gt;&lt;P&gt;name 10.2.254.11 ECHS-PDC&lt;BR /&gt;name 10.2.254.12 ECHS-XCH&lt;BR /&gt;name 10.2.254.111 Mitel5000-HOST&lt;/P&gt;&lt;P&gt;Also users need internet access and I thought I had done by this statement:&lt;/P&gt;&lt;P&gt;object network obj_any&lt;BR /&gt;&amp;nbsp; nat (Inside,Outside) dynamic interface&lt;/P&gt;&lt;P&gt;(Its just before the routing tables in the above example). Do I need to enter it has&lt;/P&gt;&lt;P&gt;object network obj_any&lt;BR /&gt;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; nat (Inside,Outside) dynamic interface&lt;/P&gt;&lt;P&gt;Or do I need to enter it has:&lt;/P&gt;&lt;P&gt;object network obj_any&lt;BR /&gt;&amp;nbsp; nat (Inside,Outside) dynamic interface&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;Sorry for being a pain and asking tom many questions. You have been a great support. I realy want to put this issue to bed and value your input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 08:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511237#M237930</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T08:56:15Z</dc:date>
    </item>
    <item>
      <title>HiWhen you say "reference the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511238#M237931</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;When you say "reference the Mitel5000-HOST object group in the NAT statements."&lt;/P&gt;&lt;P&gt;Do you mean I need to change this:&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports1 Mitel-Ports1&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports2 Mitel-Ports2&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports3 Mitel-Ports3&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports4 Mitel-Ports4&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports5 Mitel-Ports5&lt;BR /&gt;nat (inside,outside) source static Mitel5000 interface service Mitel-Ports6 Mitel-Ports6&lt;/P&gt;&lt;P&gt;To this:&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports1 Mitel-Ports1&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports2 Mitel-Ports2&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports3 Mitel-Ports3&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports4 Mitel-Ports4&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports5 Mitel-Ports5&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports6 Mitel-Ports6&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 09:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511238#M237931</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T09:00:02Z</dc:date>
    </item>
    <item>
      <title>Is this ok now?enable</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511239#M237932</link>
      <description>&lt;P&gt;Is this ok now?&lt;/P&gt;&lt;P&gt;enable password xxxx&lt;BR /&gt;password xxxx&lt;BR /&gt;User Enable password xxxx&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;name 10.2.254.11 ECHS-PDC&lt;BR /&gt;name 10.2.254.12 ECHS-XCH&lt;BR /&gt;name 10.2.254.111 Mitel5000-HOST&lt;/P&gt;&lt;P&gt;int e0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Outside&lt;BR /&gt;security-level 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address x.x.x.53 255.255.255.240&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description WAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Inside&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.254.9 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description LAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;int e0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif VoIP-Link&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.111.1 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description VOIP Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int Management0/0&lt;BR /&gt;nameif Management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;no shutdown&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;telnet 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;telnet 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;http 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;http 192.168.1.0 255.255.255.0 Management&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.5 Management&lt;BR /&gt;dhcpd enable Management&lt;/P&gt;&lt;P&gt;ssh 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;ssh 192.168.1.0 255.255.255.0 Management&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;host 10.2.254.11&lt;BR /&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-list outbound extended permit gre any4 any4&lt;BR /&gt;access-list outbound extended permit tcp any4 any4 eq pptp&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq www&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq https&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-PDC eq pptp&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 5004 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 6004 6261&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 6604 7039&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 50098 50508&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 6800 6801&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 3998 3999&lt;/P&gt;&lt;P&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp https https&lt;BR /&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp www www&lt;BR /&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp pptp pptp&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports1 Mitel-Ports1&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports2 Mitel-Ports2&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports3 Mitel-Ports3&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports4 Mitel-Ports4&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports5 Mitel-Ports5&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports6 Mitel-Ports6&lt;/P&gt;&lt;P&gt;object service Mitel-Ports1&lt;BR /&gt;&amp;nbsp; service udp destination range 5004 5007&lt;BR /&gt;object service Mitel-Ports2&lt;BR /&gt;&amp;nbsp; service udp destination range 6004 6261&lt;BR /&gt;object service Mitel-Ports3&lt;BR /&gt;&amp;nbsp; service udp destination range 6604 7039&lt;BR /&gt;object service Mitel-Ports4&lt;BR /&gt;&amp;nbsp; service udp destination range 50098 50508&lt;BR /&gt;object service Mitel-Ports5&lt;BR /&gt;&amp;nbsp; service udp destination range 6800 6801&lt;BR /&gt;object service Mitel-Ports6&lt;BR /&gt;&amp;nbsp; service udp destination range 3998 3999&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp; nat (Inside,Outside) dynamic interface&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;access-group inbound in interface Outside&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 x.x.x.49 1&lt;BR /&gt;route Inside 10.2.246.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.247.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.248.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.249.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.250.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.251.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.252.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.253.0 255.255.255.0 10.2.254.19 1&lt;/P&gt;&lt;P&gt;logging asdm 6&lt;BR /&gt;domain-name x-x-x&lt;BR /&gt;crypto key generate rsa&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 09:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511239#M237932</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T09:04:40Z</dc:date>
    </item>
    <item>
      <title>Sorry I had overlooked the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511240#M237933</link>
      <description>&lt;P&gt;Sorry I had overlooked the obj_any NAT statement.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;name 10.2.254.111 Mitel5000-HOST&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The above is not a network object, this is an alias (a mapping of IP to a name)&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The above is a network object&lt;/P&gt;&lt;P&gt;You are referencing the alias in your NAT statements and not the object group&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static &lt;EM&gt;&lt;STRONG&gt;Mitel5000 &lt;/STRONG&gt;&lt;/EM&gt;interface service Mitel-Ports1 Mitel-Ports1&lt;/P&gt;&lt;P&gt;This will not work since Mitel5000 is not a network object...you will get an error when entering this... or at least I got an error last time I tried to do this.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Sorry for being a pain and asking tom many questions&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;No worries &lt;IMG alt="smiley" height="23" src="https://supportforums.cisco.com/profiles/commons/libraries/ckeditor/plugins/smiley/images/regular_smile.png" title="smiley" width="23" /&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 09:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511240#M237933</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T09:04:48Z</dc:date>
    </item>
    <item>
      <title>Yes, looks good now.--Please</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511241#M237934</link>
      <description>&lt;P&gt;Yes, looks good now.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 09:08:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511241#M237934</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T09:08:26Z</dc:date>
    </item>
    <item>
      <title>Hi - Many thanks again. I get</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511242#M237935</link>
      <description>&lt;P&gt;Hi - Many thanks again. I get errors on the following commands:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) static interface service tcp pptp pptp&lt;/P&gt;&lt;P&gt;Being:&lt;/P&gt;&lt;P&gt;ciscoasa(config)# nat (Inside,Outside) static interface service tcp pptp pptp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;BR /&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 09:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511242#M237935</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T09:59:09Z</dc:date>
    </item>
    <item>
      <title>Have you defined the Inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511243#M237936</link>
      <description>&lt;P&gt;Have you defined the Inside interface already?&lt;/P&gt;&lt;P&gt;It seems to indicate that the interface name does not exist.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 10:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511243#M237936</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T10:03:38Z</dc:date>
    </item>
    <item>
      <title>By the way my fonal config,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511244#M237937</link>
      <description>&lt;P&gt;By the way my fonal config, which I tested in the lab and get no errors, look like this...&lt;/P&gt;&lt;P&gt;enable password XXXX&lt;BR /&gt;password XXXX&lt;BR /&gt;User Enable password XXXX&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;name 10.2.254.11 ECHS-PDC&lt;BR /&gt;name 10.2.254.12 ECHS-XCH&lt;BR /&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;/P&gt;&lt;P&gt;int e0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Outside&lt;BR /&gt;security-level 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address X.X.X.53 255.255.255.240&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description WAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Inside&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.254.9 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description LAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;int e0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif VoIP-Link&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.111.1 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description VOIP Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int Management0/0&lt;BR /&gt;nameif Management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;no shutdown&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;telnet 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;telnet 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;http 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;http 192.168.1.0 255.255.255.0 Management&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.5 Management&lt;BR /&gt;dhcpd enable Management&lt;/P&gt;&lt;P&gt;ssh 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;ssh 192.168.1.0 255.255.255.0 Management&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;host 10.2.254.11&lt;BR /&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;BR /&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp https https&lt;BR /&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp www www&lt;BR /&gt;object network ECHS-PDC&lt;/P&gt;&lt;P&gt;access-list outbound extended permit gre any4 any4&lt;BR /&gt;access-list outbound extended permit tcp any4 any4 eq pptp&lt;/P&gt;&lt;P&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 5004 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 6004 6261&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 6604 7039&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 50098 50508&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 6800 6801&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 3998 3999&lt;/P&gt;&lt;P&gt;access-list inbound extended permit tcp any4 object ECHS-PDC eq pptp&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq www&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq https&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object service Mitel-Ports1&lt;BR /&gt;&amp;nbsp; service udp destination range 5004 5007&lt;BR /&gt;object service Mitel-Ports2&lt;BR /&gt;&amp;nbsp; service udp destination range 6004 6261&lt;BR /&gt;object service Mitel-Ports3&lt;BR /&gt;&amp;nbsp; service udp destination range 6604 7039&lt;BR /&gt;object service Mitel-Ports4&lt;BR /&gt;&amp;nbsp; service udp destination range 50098 50508&lt;BR /&gt;object service Mitel-Ports5&lt;BR /&gt;&amp;nbsp; service udp destination range 6800 6801&lt;BR /&gt;object service Mitel-Ports6&lt;BR /&gt;&amp;nbsp; service udp destination range 3998 3999&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports1 Mitel-Ports1&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports2 Mitel-Ports2&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports3 Mitel-Ports3&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports4 Mitel-Ports4&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports5 Mitel-Ports5&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports6 Mitel-Ports6&lt;/P&gt;&lt;P&gt;access-group inbound in interface Outside&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 X.X.X.49 1&lt;BR /&gt;route Inside 10.2.246.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.247.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.248.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.249.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.250.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.251.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.252.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.253.0 255.255.255.0 10.2.254.19 1&lt;/P&gt;&lt;P&gt;logging asdm 6&lt;BR /&gt;domain-name X-X-X&lt;BR /&gt;crypto key generate rsa&lt;/P&gt;&lt;P&gt;The only command I am missing is...&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) static interface service tcp pptp pptp&lt;/P&gt;&lt;P&gt;Not sure what this command is for but when I run it I get error message of:&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;BR /&gt;ciscoasa(config)# nat (Inside,Outside) static interface service tcp pptp pptp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;BR /&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;Please could show us what I am doing wrong? Again many thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 10:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511244#M237937</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T10:06:09Z</dc:date>
    </item>
    <item>
      <title>ah ok here is the problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511245#M237938</link>
      <description>&lt;P&gt;ah ok here is the problem:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;ciscoasa(config)# &lt;/EM&gt;&lt;/STRONG&gt;nat (Inside,Outside) static interface service tcp pptp pptp&lt;/P&gt;&lt;P&gt;you need to add this type of command under a network object.&amp;nbsp; for example&lt;/P&gt;&lt;P&gt;object network TEST&lt;BR /&gt;&amp;nbsp; subnet 1.1.1.0 255.255.255.0&lt;BR /&gt;&amp;nbsp; nat (Inside,Outside) static interface service tcp pptp pptp&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 10:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511245#M237938</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T10:15:23Z</dc:date>
    </item>
    <item>
      <title>Hi, thanks for that. Can I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511246#M237939</link>
      <description>&lt;P&gt;Hi, thanks for that. Can I ask if I do the following:&lt;/P&gt;&lt;P&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service udp X X&lt;/P&gt;&lt;P&gt;What do I need to put to get the range of ports? I am comparing with..&lt;/P&gt;&lt;P&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;host 10.2.254.11&lt;BR /&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp pptp pptp&lt;/P&gt;&lt;P&gt;Many thanks again for your continuous support. Your unreal!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 10:52:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511246#M237939</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T10:52:23Z</dc:date>
    </item>
    <item>
      <title>What do I need to put to get</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511247#M237940</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;What do I need to put to get the range of ports?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I am not 100% sure I understand what you mean by range of ports. But, if I understand correctly, you could create a service object that defines the range of ports and then call that object group in the NAT statement...for example&lt;/P&gt;&lt;P&gt;object service PORT-RANGE&lt;BR /&gt;&amp;nbsp; service tcp destination range 1024 4000&lt;/P&gt;&lt;P&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) source static Mitel5000-HOST interface service PORT-RANGE PORT-RANGE&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 11:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511247#M237940</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T11:06:57Z</dc:date>
    </item>
    <item>
      <title>Hello again...Many thanks, I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511248#M237941</link>
      <description>&lt;P&gt;Hello again...Many thanks, I think I have done the above. This is my final config, can I ask you to please cast a eye on it and see it all looks good? Many Thanks for your help today.&lt;/P&gt;&lt;P&gt;enable password XXXX&lt;BR /&gt;password XXXX&lt;BR /&gt;User Enable password XXXX&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;name 10.2.254.11 ECHS-PDC&lt;BR /&gt;name 10.2.254.12 ECHS-XCH&lt;BR /&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp; host 10.2.254.111&lt;/P&gt;&lt;P&gt;int e0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Outside&lt;BR /&gt;security-level 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address X.X.X.53 255.255.255.240&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description WAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif Inside&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.254.9 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description LAN Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;int e0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nameif VoIP-Link&lt;BR /&gt;security-level 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;ip address 10.2.111.1 255.255.255.0&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;description VOIP Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int e0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;no shutdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;int Management0/0&lt;BR /&gt;nameif Management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;no shutdown&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;telnet 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;telnet 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;http 10.0.0.0 255.0.0.0 Inside&lt;BR /&gt;http 192.168.1.0 255.255.255.0 Management&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.5 Management&lt;BR /&gt;dhcpd enable Management&lt;/P&gt;&lt;P&gt;ssh 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;ssh 192.168.1.0 255.255.255.0 Management&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-XCH&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp https https&lt;/P&gt;&lt;P&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;host 10.2.254.12&lt;BR /&gt;object network ECHS-XCH-01&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp www www&lt;/P&gt;&lt;P&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;host 10.2.254.11&lt;BR /&gt;object network ECHS-PDC&lt;BR /&gt;&amp;nbsp;nat (Inside,Outside) static interface service tcp pptp pptp&lt;/P&gt;&lt;P&gt;object network Mitel5000-HOST&lt;BR /&gt;&amp;nbsp;host 10.2.254.111&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 5004 5007&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 6004 6261&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 6604 7039&lt;BR /&gt;access-list inbound extended permit udp any4 object Mitel5000-HOST range 50098 50508&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 6800 6801&lt;BR /&gt;access-list inbound extended permit tcp any interface Outside range 3998 3999&lt;/P&gt;&lt;P&gt;access-list outbound extended permit gre any4 any4&lt;BR /&gt;access-list outbound extended permit tcp any4 any4 eq pptp&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-PDC eq pptp&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq www&lt;BR /&gt;access-list inbound extended permit tcp any4 object ECHS-XCH eq https&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object service Mitel-Ports1&lt;BR /&gt;&amp;nbsp; service udp destination range 5004 5007&lt;BR /&gt;object service Mitel-Ports2&lt;BR /&gt;&amp;nbsp; service udp destination range 6004 6261&lt;BR /&gt;object service Mitel-Ports3&lt;BR /&gt;&amp;nbsp; service udp destination range 6604 7039&lt;BR /&gt;object service Mitel-Ports4&lt;BR /&gt;&amp;nbsp; service udp destination range 50098 50508&lt;BR /&gt;object service Mitel-Ports5&lt;BR /&gt;&amp;nbsp; service udp destination range 6800 6801&lt;BR /&gt;object service Mitel-Ports6&lt;BR /&gt;&amp;nbsp; service udp destination range 3998 3999&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports1 Mitel-Ports1&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports2 Mitel-Ports2&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports3 Mitel-Ports3&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports4 Mitel-Ports4&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports5 Mitel-Ports5&lt;BR /&gt;nat (inside,outside) source static Mitel5000-HOST interface service Mitel-Ports6 Mitel-Ports6&lt;/P&gt;&lt;P&gt;access-group inbound in interface Outside&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 X.X.X.49 1&lt;BR /&gt;route Inside 10.2.246.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.247.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.248.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.249.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.250.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.251.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.252.0 255.255.255.0 10.2.254.19 1&lt;BR /&gt;route Inside 10.2.253.0 255.255.255.0 10.2.254.19 1&lt;/P&gt;&lt;P&gt;logging asdm 6&lt;BR /&gt;domain-name X-X-X&lt;BR /&gt;crypto key generate rsa&lt;/P&gt;&lt;P&gt;You have been amazing with you support. Many thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 11:19:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511248#M237941</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T11:19:06Z</dc:date>
    </item>
    <item>
      <title>Yes, this looks good. but a</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511249#M237942</link>
      <description>&lt;P&gt;Yes, this looks good. but a couple thoughts.&lt;/P&gt;&lt;P&gt;I see an ACL that is not in use...do you need this there?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outbound extended permit gre any4 any4&lt;BR /&gt;access-list outbound extended permit tcp any4 any4 eq pptp&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;You are allowing telnet connections, which isn't a secure protocol, if you don't need to use this I suggest removing it.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;telnet 10.2.254.0 255.255.255.0 Inside&lt;BR /&gt;telnet 10.0.0.0 255.0.0.0 Inside&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 11:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511249#M237942</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T11:28:15Z</dc:date>
    </item>
    <item>
      <title>HiWhat do these commands..</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511250#M237943</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;What do these commands...&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outbound extended permit gre any4 any4&lt;BR /&gt;access-list outbound extended permit tcp any4 any4 eq pptp&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;actually mean?&lt;/P&gt;&lt;P&gt;I want to&amp;nbsp; go and test my config in live situ. Last time I did this the phone went down...truly existed to see how it all goes today.&lt;/P&gt;&lt;P&gt;Many many thanks&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 11:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511250#M237943</guid>
      <dc:creator>CSCO10812764</dc:creator>
      <dc:date>2014-06-06T11:40:40Z</dc:date>
    </item>
    <item>
      <title>basically if you applied that</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511251#M237944</link>
      <description>&lt;P&gt;basically if you applied that ACL to the Inside interface you would only be permiting gre and PPTP traffic, all other traffic will be dropped that is generated from the Inside network and entering the ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless you have a requirement to&amp;nbsp; deny the Inside users access to certain servers, PCs, etc., then I would leave the configuration as is.&amp;nbsp; your current configuration will allow all traffic from a higher security level to an equal or lower security.&amp;nbsp; So your inside users will not be restricted as things stand now.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 11:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-ios-9-0-3-createing-a-group-object-and-pat-range/m-p/2511251#M237944</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-06T11:47:37Z</dc:date>
    </item>
  </channel>
</rss>

