<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple PAT using ASDM gui in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-pat-using-asdm-gui/m-p/3911460#M24810</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;First, I'm not an expert in networking, I am a sysadmin.&lt;/P&gt;&lt;P&gt;I have an access to our cisco ASA via ASDM GUI (v7.8).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 servers on private network (same subnet, serv1 192.168.0.1 and serv2 192.168.0.2) and 1 IP on public network (say, 18.18.18.18).&lt;/P&gt;&lt;P&gt;I need to PAT outside (world) connections to our two internal servers.&lt;/P&gt;&lt;P&gt;I would like to achieve this :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;connect to 18.18.18.18:5001 would PAT to 192.168.0.1:5001&lt;/P&gt;&lt;P&gt;connect to 18.18.18.18:5002 would PAT to 192.168.0.2:5002&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could achieve to get first PAT to work (using "NAT RULES" tab), but when I try to add the second PAT I get&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Pool (0.0.0.0) overlap with existing pool"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this is theoricaly possible but I don't know how to achieve this using ASDM GUI (only access I have).&lt;/P&gt;&lt;P&gt;I can do this with an easy iptables NAT table, but I'm missing something for ASDM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit : more details :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each NAT rule is created with following options (see attached crafted capture)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sans titre3.png" style="width: 659px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/43472iB273377724ADF1CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Sans titre3.png" alt="Sans titre3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit2 :&lt;/P&gt;&lt;P&gt;Ok found something, I need I think to provide "Source interface" too but the problem is I don't have the sufficient rights to see the external network card of ASA, I think.&lt;/P&gt;&lt;P&gt;I tried using dynamic PAT (Hide), and got it to work for both ports, but not the way I want : the ASA hide the original IP and it's a security matter to us to have a fail2ban up and running to block external IPs bruteforcing.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2019 13:53:43 GMT</pubDate>
    <dc:creator>tntteam100687</dc:creator>
    <dc:date>2019-08-21T13:53:43Z</dc:date>
    <item>
      <title>Multiple PAT using ASDM gui</title>
      <link>https://community.cisco.com/t5/network-security/multiple-pat-using-asdm-gui/m-p/3911460#M24810</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;First, I'm not an expert in networking, I am a sysadmin.&lt;/P&gt;&lt;P&gt;I have an access to our cisco ASA via ASDM GUI (v7.8).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 servers on private network (same subnet, serv1 192.168.0.1 and serv2 192.168.0.2) and 1 IP on public network (say, 18.18.18.18).&lt;/P&gt;&lt;P&gt;I need to PAT outside (world) connections to our two internal servers.&lt;/P&gt;&lt;P&gt;I would like to achieve this :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;connect to 18.18.18.18:5001 would PAT to 192.168.0.1:5001&lt;/P&gt;&lt;P&gt;connect to 18.18.18.18:5002 would PAT to 192.168.0.2:5002&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could achieve to get first PAT to work (using "NAT RULES" tab), but when I try to add the second PAT I get&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Pool (0.0.0.0) overlap with existing pool"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this is theoricaly possible but I don't know how to achieve this using ASDM GUI (only access I have).&lt;/P&gt;&lt;P&gt;I can do this with an easy iptables NAT table, but I'm missing something for ASDM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit : more details :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each NAT rule is created with following options (see attached crafted capture)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sans titre3.png" style="width: 659px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/43472iB273377724ADF1CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Sans titre3.png" alt="Sans titre3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit2 :&lt;/P&gt;&lt;P&gt;Ok found something, I need I think to provide "Source interface" too but the problem is I don't have the sufficient rights to see the external network card of ASA, I think.&lt;/P&gt;&lt;P&gt;I tried using dynamic PAT (Hide), and got it to work for both ports, but not the way I want : the ASA hide the original IP and it's a security matter to us to have a fail2ban up and running to block external IPs bruteforcing.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 13:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-pat-using-asdm-gui/m-p/3911460#M24810</guid>
      <dc:creator>tntteam100687</dc:creator>
      <dc:date>2019-08-21T13:53:43Z</dc:date>
    </item>
  </channel>
</rss>

