<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT B/W inside to DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457977#M268624</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vibhor , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your support , i am new in security so i am having lots issues . i tried alot to run Packet Tracer commnad but still i am unable to run it correctly , let see if i have to check nat or ping traffic issue what is the correct packet Tracer command santax . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly&amp;nbsp; i have cisco Wireless ip phones on inside network and my callmanager is behind the DMZ what exacltly i need to do to register this ip phone with callmanage &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Mar 2014 14:57:55 GMT</pubDate>
    <dc:creator>aslam.bajwa</dc:creator>
    <dc:date>2014-03-05T14:57:55Z</dc:date>
    <item>
      <title>NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457971#M268610</link>
      <description>&lt;P&gt;Hello , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have ASA 8.6 i need to configure nating between inside and DMZ . network details is as under :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;network behind inside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.16.8.0 / 24&lt;/P&gt;&lt;P&gt;10.16.10.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;network behind DMZ interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.16.7.0/24&lt;/P&gt;&lt;P&gt;10.16.6.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what configuration i need on ASA so inside and outside can communicate with eachother please advice.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457971#M268610</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2019-03-12T03:53:40Z</dc:date>
    </item>
    <item>
      <title>NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457972#M268611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;object-group network Inside_Networks&lt;/P&gt;&lt;P&gt;network-object 10.16.8.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 10.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network DMZ_Networks&lt;/P&gt;&lt;P&gt;network-object 10.16.7.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 10.16.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume your interfaces are named "inside" and "DMZ"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,dmz) source static Inside_Networks Inside_Networks destination static DMZ_Networks DMZ_Networks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 00:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457972#M268611</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2014-03-05T00:59:20Z</dc:date>
    </item>
    <item>
      <title>NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457973#M268614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many Thanks for your reply , i will check today and update you .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please tell me aboute routes also if required , so that i will be able to ping .from both side&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 05:58:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457973#M268614</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2014-03-05T05:58:46Z</dc:date>
    </item>
    <item>
      <title>NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457974#M268616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aslam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be honest , I see that you have these Subnets behind the ASA Interfaces. You are not translation the traffic between the Inside and DMZ interface and hence , I don't think you need any NAT statements on the ASA device to communicate between these Two interfaces(As nat-control is disabled by default on the ASA 8.3+).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still , you would need Static routes for every L3 network behind the ASA interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 13:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457974#M268616</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-03-05T13:42:17Z</dc:date>
    </item>
    <item>
      <title>NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457975#M268619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vibhor , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have done the nating , its working fine as i can ping fron ASA to network behind the inside and DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i can not ping from DMZ switch to ASA inside and from inside Switch to asa DMZ interfaces . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there is routing issues on both DMZ and inside swith . can yo advise &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457975#M268619</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2014-03-05T14:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457976#M268622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aslam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be clear , we cannot ping the DMZ interface IP on the ASA from Any device behind the Inside interface and vice versa by architecture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To ping from the devices behind the DMZ interface to the Inside devices , you would also need to allow the traffic using ACL on the DMZ interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please send me the Packet-tracer for the traffic which is not working if possible. Also , run this command on the ASA device:-&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;fixup protocol icmp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457976#M268622</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-03-05T14:35:55Z</dc:date>
    </item>
    <item>
      <title>NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457977#M268624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vibhor , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your support , i am new in security so i am having lots issues . i tried alot to run Packet Tracer commnad but still i am unable to run it correctly , let see if i have to check nat or ping traffic issue what is the correct packet Tracer command santax . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly&amp;nbsp; i have cisco Wireless ip phones on inside network and my callmanager is behind the DMZ what exacltly i need to do to register this ip phone with callmanage &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457977#M268624</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2014-03-05T14:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT B/W inside to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457978#M268626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aslam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for a late reply. As per your 1st query , you can check this Doc for more information on Packet Tracer on ASA:-&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-5796"&gt;https://supportforums.cisco.com/docs/DOC-5796&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also share the configuration and I can help you out. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per your 2nd Query , If you want the IP phones to coimmunicate with the Call Manager on the DMZ , I would say the NAT should be there for Communication , Inspection and Access-rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 15:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-b-w-inside-to-dmz/m-p/2457978#M268626</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-03-06T15:37:24Z</dc:date>
    </item>
  </channel>
</rss>

