<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policy Based PAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-based-pat/m-p/2446249#M270278</link>
    <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having a problem setting up a policy based pat.&amp;nbsp; I 'll tell you what I tried to do and then you can advise me if this is correct.&amp;nbsp; This is on a&lt;/P&gt;&lt;P&gt;ASA 8.6 5540.&lt;/P&gt;&lt;P&gt;We are trying to access a webpage that an application running on port 8080, external to my firewall on 172.53.16.17.&amp;nbsp; The partner organisation&amp;nbsp; wants the source address to be 172.53.130.17 and is dropping anything which has an internal ip address.&amp;nbsp; I therefore followed the example on the cisco website&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-SOURCE ( my lan)&lt;BR /&gt;subnet 172.30.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-SOURCE-MAPPED (the transition)&lt;BR /&gt;host 172.53.130.17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-DESTINATION (the app)&lt;BR /&gt;host 172.53.16.17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object service SERVICE&amp;nbsp; ( the service which translates the www traffic to 8080)&lt;BR /&gt;service tcp source eq www destination eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run the following command&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static PAT-SOURCE PAT-SOURCED-MAPPED destination static PAT-DESTINATION PAT-DESTINATION service SERVICE SERVICE&lt;/P&gt;&lt;P&gt;I receive the following error-&lt;/P&gt;&lt;P&gt;ERROR: PAT-SOURCED-MAPPED doesn't match an existing object or object-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:40:40 GMT</pubDate>
    <dc:creator>steve martin</dc:creator>
    <dc:date>2019-03-12T03:40:40Z</dc:date>
    <item>
      <title>Policy Based PAT</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-pat/m-p/2446249#M270278</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having a problem setting up a policy based pat.&amp;nbsp; I 'll tell you what I tried to do and then you can advise me if this is correct.&amp;nbsp; This is on a&lt;/P&gt;&lt;P&gt;ASA 8.6 5540.&lt;/P&gt;&lt;P&gt;We are trying to access a webpage that an application running on port 8080, external to my firewall on 172.53.16.17.&amp;nbsp; The partner organisation&amp;nbsp; wants the source address to be 172.53.130.17 and is dropping anything which has an internal ip address.&amp;nbsp; I therefore followed the example on the cisco website&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-SOURCE ( my lan)&lt;BR /&gt;subnet 172.30.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-SOURCE-MAPPED (the transition)&lt;BR /&gt;host 172.53.130.17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PAT-DESTINATION (the app)&lt;BR /&gt;host 172.53.16.17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object service SERVICE&amp;nbsp; ( the service which translates the www traffic to 8080)&lt;BR /&gt;service tcp source eq www destination eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run the following command&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static PAT-SOURCE PAT-SOURCED-MAPPED destination static PAT-DESTINATION PAT-DESTINATION service SERVICE SERVICE&lt;/P&gt;&lt;P&gt;I receive the following error-&lt;/P&gt;&lt;P&gt;ERROR: PAT-SOURCED-MAPPED doesn't match an existing object or object-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-pat/m-p/2446249#M270278</guid>
      <dc:creator>steve martin</dc:creator>
      <dc:date>2019-03-12T03:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based PAT</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-pat/m-p/2446250#M270279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ERROR messages states that you are using the &lt;STRONG&gt;"object"&lt;/STRONG&gt; or &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; name that doesnt exist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice that you have typed it wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command has &lt;STRONG&gt;PAT-SOURCE&lt;SPAN style="color: #ff0000;"&gt;D&lt;/SPAN&gt;-MAPPED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual&lt;STRONG&gt; "object"&lt;/STRONG&gt; is named &lt;STRONG&gt;PAT-SOURCE-MAPPED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though I think you might have to change the &lt;STRONG&gt;"object"&lt;/STRONG&gt; name a bit because of other reasons. The that reason is that you should probably change the NAT to be a Dynamic Policy PAT by changing the "source static" to "source dynamic" and because of this the "object" name starting with PAT might confuse the ASA. Or atleast I think I had such a problem in the past.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; To me it seems that there are some things that need to be changed in the configurations.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;"source static"&lt;/STRONG&gt; -&amp;gt; &lt;STRONG&gt;"source dynamic"&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;PAT-SOURCE-MAPPED --&amp;gt; MAPPED-IP&lt;/STRONG&gt; (for example)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;"object service"&lt;/STRONG&gt; needs redoing&lt;/LI&gt;&lt;LI&gt;Because of the above changes the actual &lt;STRONG&gt;"nat"&lt;/STRONG&gt; command needs changes&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest the following configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PAT-SOURCE&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; subnet 172.30.0.0 255.255.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network MAPPED-IP&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; host 172.53.130.17&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PAT-DESTINATION&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;host 172.53.16.17&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service TCP-80&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;service tcp destination eq 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service TCP-8080&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service tcp destination eq 8080&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat&amp;nbsp; (inside,outside) source dynamic PAT-SOURCE MAPPED-IP&amp;nbsp; destination static PAT-DESTINATION PAT-DESTINATION service TCP-8080 TCP-80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above configuration does so that when connection is coming from&lt;STRONG&gt; PAT-SOURCE&lt;/STRONG&gt; and going to &lt;STRONG&gt;PAT-DESTINATION &lt;/STRONG&gt;with the destination port &lt;STRONG&gt;TCP-80&lt;/STRONG&gt; then the source address will be NATed to &lt;STRONG&gt;MAPPED-IP&lt;/STRONG&gt; and the destination port will be UN-NATed to &lt;STRONG&gt;TCP-8080&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I missunderstood the purpose of the NAT configuration (according to the above description I gave) then please correct me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2014 13:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-pat/m-p/2446250#M270279</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-05T13:29:55Z</dc:date>
    </item>
    <item>
      <title>Policy Based PAT</title>
      <link>https://community.cisco.com/t5/network-security/policy-based-pat/m-p/2446251#M270280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for your help, I've spend two days looking at it and I still had typo's.&amp;nbsp; Works a treat.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2014 14:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-based-pat/m-p/2446251#M270280</guid>
      <dc:creator>steve martin</dc:creator>
      <dc:date>2014-02-05T14:17:14Z</dc:date>
    </item>
  </channel>
</rss>

