<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OK, dumb question, but does in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486240#M238479</link>
    <description>&lt;P&gt;OK, dumb question, but does the backup interface have an IP address and security level assigned?&lt;/P&gt;</description>
    <pubDate>Wed, 14 May 2014 14:12:47 GMT</pubDate>
    <dc:creator>Colin Higgins</dc:creator>
    <dc:date>2014-05-14T14:12:47Z</dc:date>
    <item>
      <title>dynamic NAT for 2 interface with ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486239#M238477</link>
      <description>&lt;P&gt;I have ASA 5510 with 8.4(2) version.&lt;/P&gt;&lt;P&gt;I need help to create 2 dynamic NAT for 2 interface. Here is what I have.&lt;/P&gt;&lt;P&gt;Outside interface&lt;/P&gt;&lt;P&gt;Inside interface&lt;/P&gt;&lt;P&gt;DMZ interface&lt;/P&gt;&lt;P&gt;backup interface&lt;/P&gt;&lt;P&gt;Here is my nat&lt;/P&gt;&lt;P&gt;object network DMZ-10.1.8.0_24&lt;BR /&gt;&amp;nbsp;nat (dmz,outside) dynamic interface&lt;BR /&gt;object network INSIDE-10.1.7.0_24&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;I want to add additional NAT like&lt;/P&gt;&lt;P&gt;"object network INSIDE-10.1.7.0_24&lt;BR /&gt;&amp;nbsp;nat (inside,backup) dynamic interface"&lt;/P&gt;&lt;P&gt;But it does not allow me to add, once I add, it removes "nat (inside,outside) dynamic interface". My goal is to achieve inside network and dmz network to translate backup network interface without affecting current outside NAT. backup interface is private network which connect to different network with other untrusted connections connect to that network. Thanks in advance for your advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486239#M238477</guid>
      <dc:creator>Wilco Fong</dc:creator>
      <dc:date>2019-03-12T04:12:04Z</dc:date>
    </item>
    <item>
      <title>OK, dumb question, but does</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486240#M238479</link>
      <description>&lt;P&gt;OK, dumb question, but does the backup interface have an IP address and security level assigned?&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 14:12:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486240#M238479</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2014-05-14T14:12:47Z</dc:date>
    </item>
    <item>
      <title>Hi Colin,Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486241#M238481</link>
      <description>&lt;P&gt;Hi Colin,&lt;/P&gt;&lt;P&gt;Thanks for your reply. Yes backup interface has same security level as outside and it has ip assigned.&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 15:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486241#M238481</guid>
      <dc:creator>Wilco Fong</dc:creator>
      <dc:date>2014-05-14T15:30:54Z</dc:date>
    </item>
    <item>
      <title>You need to create another</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486242#M238482</link>
      <description>&lt;P&gt;You need to create another object, with the same IP address and use this new object for nat. Exemple&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;INSIDE-10.1.7.0_24-2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;subnet&amp;nbsp;10.1.7.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;nat (inside,backup) dynamic interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Also if the backup interface has the same security level of the inside interface you need to allow the traffic explicitly because it's denied by default. Use the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 17:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-nat-for-2-interface-with-asa-8-4-2/m-p/2486242#M238482</guid>
      <dc:creator>guibarati</dc:creator>
      <dc:date>2014-05-14T17:28:49Z</dc:date>
    </item>
  </channel>
</rss>

