<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic and Static PAT using a single public IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480838#M238063</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to configure PAT on a new ASA-5510 running 9.0(3) and I'm having some issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our setup we have a single public IP address(lets say 127.1.1.1) which is assigned to the outside interface, and we need to use that for both dynamic PAT to allow all machines in our 10.1.0.0 255.255.255.0 subnet hit the outside world, as well as allow the outside world FTP access to (10.1.0.124) on the inside using static PAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have dynamic PAT working and we are able to hit the outside world, but I can't get the static service PAT working to forward FTP traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration looks like this right now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj-10.1.0.124&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 10.1.0.124&lt;/P&gt;&lt;P&gt;object network obj-10.1.0.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 10.1.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (infra,outside) source dynamic obj-10.1.0.0 interface&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;object network obj-10.1.0.124&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (infra,outside) static interface service tcp 21 21&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should the dynamic PAT rule also be written as a network object rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:15:22 GMT</pubDate>
    <dc:creator>stevenilan</dc:creator>
    <dc:date>2019-03-12T04:15:22Z</dc:date>
    <item>
      <title>Dynamic and Static PAT using a single public IP</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480838#M238063</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to configure PAT on a new ASA-5510 running 9.0(3) and I'm having some issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our setup we have a single public IP address(lets say 127.1.1.1) which is assigned to the outside interface, and we need to use that for both dynamic PAT to allow all machines in our 10.1.0.0 255.255.255.0 subnet hit the outside world, as well as allow the outside world FTP access to (10.1.0.124) on the inside using static PAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have dynamic PAT working and we are able to hit the outside world, but I can't get the static service PAT working to forward FTP traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration looks like this right now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj-10.1.0.124&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 10.1.0.124&lt;/P&gt;&lt;P&gt;object network obj-10.1.0.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 10.1.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (infra,outside) source dynamic obj-10.1.0.0 interface&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;object network obj-10.1.0.124&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (infra,outside) static interface service tcp 21 21&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should the dynamic PAT rule also be written as a network object rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480838#M238063</guid>
      <dc:creator>stevenilan</dc:creator>
      <dc:date>2019-03-12T04:15:22Z</dc:date>
    </item>
    <item>
      <title>That looks correct, just add</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480839#M238065</link>
      <description>&lt;P&gt;That looks correct, just add another static PAT for TCP port 20 as well.&lt;/P&gt;&lt;P&gt;Here's a link to a useful Doc :&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/33921/asa-pre-83-83-nat-configuration-examples&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 19:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480839#M238065</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2014-05-28T19:06:55Z</dc:date>
    </item>
    <item>
      <title>Thanks for your reply.  It</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480840#M238066</link>
      <description>&lt;P&gt;Thanks for your reply.&amp;nbsp; It isn't working though so I'm not sure what the problem is, adding another PAT translation for port 20 did not help either.&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 20:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480840#M238066</guid>
      <dc:creator>stevenilan</dc:creator>
      <dc:date>2014-05-28T20:58:04Z</dc:date>
    </item>
    <item>
      <title>Please post the output of the</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480841#M238068</link>
      <description>&lt;P&gt;Please post the output of the following :&lt;/P&gt;&lt;P&gt;show nat detail&lt;/P&gt;&lt;P&gt;show run nat&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 21:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480841#M238068</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2014-05-28T21:00:56Z</dc:date>
    </item>
    <item>
      <title>Changing the global PAT to an</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480842#M238071</link>
      <description>&lt;P&gt;Changing the global PAT to an object PAT rule got everything working correctly.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj-10.1.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.1.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-ftp-access&lt;BR /&gt;&amp;nbsp;host 10.1.0.124&lt;/P&gt;&lt;P&gt;object network obj-10.1.0.0&lt;BR /&gt;&amp;nbsp;nat (infra,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network obj-ftp-access&lt;BR /&gt;&amp;nbsp;nat (infra,outside) static interface service tcp 21 21&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2014 14:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480842#M238071</guid>
      <dc:creator>stevenilan</dc:creator>
      <dc:date>2014-05-29T14:26:53Z</dc:date>
    </item>
    <item>
      <title>Thanks for your help Manish,</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480843#M238073</link>
      <description>&lt;P&gt;Thanks for your help Manish, I figured it out.&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2014 14:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-and-static-pat-using-a-single-public-ip/m-p/2480843#M238073</guid>
      <dc:creator>stevenilan</dc:creator>
      <dc:date>2014-05-29T14:27:29Z</dc:date>
    </item>
  </channel>
</rss>

