<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inbound Static Nat on ASA 8.3 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476136#M269986</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply. &lt;/P&gt;&lt;P&gt;The external mail servers will need to forward to 154.11.11.30 a IP address in the firewall subnet range and then forwarded to 10.0.0.100. I will need to translate out bound mail to 154.11.11.30 and then out to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;OutSide&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Firewall&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mailserver inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;207.211.30.0 255.255.254.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&amp;gt; &lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 154.11.11.30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&amp;gt; &lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;205.139.110.0 255.255.254.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 09 Feb 2014 18:17:33 GMT</pubDate>
    <dc:creator>mani.khatra</dc:creator>
    <dc:date>2014-02-09T18:17:33Z</dc:date>
    <item>
      <title>Inbound Static Nat on ASA 8.3</title>
      <link>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476134#M269984</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to configure a inbound static nat from multible public subnets to 1 internal mail server on an ASA 5510 with &lt;/P&gt;&lt;P&gt;Software Version 8.3(2)34. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to allow access&amp;nbsp; from the public subnets listed below to the internal mail server on port 25.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;207.211.31.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;207.211.30.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;205.139.110.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;205.139.111.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476134#M269984</guid>
      <dc:creator>mani.khatra</dc:creator>
      <dc:date>2019-03-12T03:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Static Nat on ASA 8.3</title>
      <link>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476135#M269985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, Mani.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would configure static network object NAT (unless you need to limit translation to the external servers only):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network EXTERNAL_MAIL_SERVERS&lt;/P&gt;&lt;P&gt; network-object 207.211.30.0 255.255.254.0&lt;/P&gt;&lt;P&gt; network-object 205.139.110.0 255.255.254.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network INTERNAL_MAIL_SERVER&lt;/P&gt;&lt;P&gt; host 10.0.0.100&lt;/P&gt;&lt;P&gt; nat (inside, outside) static interface service tcp 25 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE_IN extended permit tcp object-group &lt;SPAN style="font-size: 10pt;"&gt;EXTERNAL_MAIL_SERVERS object INTERNAL_MAIL_SERVER eq 25&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Feb 2014 07:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476135#M269985</guid>
      <dc:creator>Vasilii Mikhailovskii</dc:creator>
      <dc:date>2014-02-09T07:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Static Nat on ASA 8.3</title>
      <link>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476136#M269986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply. &lt;/P&gt;&lt;P&gt;The external mail servers will need to forward to 154.11.11.30 a IP address in the firewall subnet range and then forwarded to 10.0.0.100. I will need to translate out bound mail to 154.11.11.30 and then out to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;OutSide&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Firewall&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mailserver inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;207.211.30.0 255.255.254.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&amp;gt; &lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 154.11.11.30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&amp;gt; &lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;205.139.110.0 255.255.254.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Feb 2014 18:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476136#M269986</guid>
      <dc:creator>mani.khatra</dc:creator>
      <dc:date>2014-02-09T18:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Static Nat on ASA 8.3</title>
      <link>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476137#M269987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the IP-address (154.11.11.30) is the one that provider assigned you, then:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;if the IP-address is assign on public ASA interface, then use configuration from my last post;&lt;/LI&gt;&lt;LI&gt;if it's not assigned to ASA's interface, but within public IP-range provider has assigned you, then adjust my last configuration with&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;object network INTERNAL_MAIL_SERVER&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;host 10.0.0.100&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;nat (inside, outside) static 154.11.11.30 service tcp 25 25&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 06:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476137#M269987</guid>
      <dc:creator>Vasilii Mikhailovskii</dc:creator>
      <dc:date>2014-02-10T06:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Static Nat on ASA 8.3</title>
      <link>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476138#M269988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once Again Thank You. I will be trying the config below provided by you. One question, is it possible to do this config in a manual nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network EXTERNAL_MAIL_SERVERS&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;network-object 207.211.30.0 255.255.254.0&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;network-object 205.139.110.0 255.255.254.0&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network INTERNAL_MAIL_SERVER &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;host 10.0.0.100&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;nat (inside, outside) static 154.11.11.30 service tcp 25 25&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;access-list OUTSIDE_IN extended permit tcp object-group EXTERNAL_MAIL_SERVERS object INTERNAL_MAIL_SERVER eq 25&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 19:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476138#M269988</guid>
      <dc:creator>mani.khatra</dc:creator>
      <dc:date>2014-02-10T19:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Static Nat on ASA 8.3</title>
      <link>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476139#M269989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;One question, is it possible to do this config in a manual nat?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what did you mean as "manual nat".&lt;/P&gt;&lt;P&gt; If you are talking about ASDM, then, sorry, I've never used it to configure ASA (only to monitor).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Feb 2014 08:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-static-nat-on-asa-8-3/m-p/2476139#M269989</guid>
      <dc:creator>Vasilii Mikhailovskii</dc:creator>
      <dc:date>2014-02-11T08:32:40Z</dc:date>
    </item>
  </channel>
</rss>

