<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-help/m-p/2420263#M308975</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jumora! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically my crypto map ACL will look like:&lt;/P&gt;&lt;P&gt;ACL crypto 1 permit my_vpn vend_nat &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I dint need to reference the vendors 192 subnet because the inside interface is doing the NATing correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Nov 2013 02:53:00 GMT</pubDate>
    <dc:creator>Mike Hogenauer</dc:creator>
    <dc:date>2013-11-14T02:53:00Z</dc:date>
    <item>
      <title>NAT Help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/2420259#M308967</link>
      <description>&lt;P&gt;Hi –&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just wanted to verify my config and make sure I’m doing this correctly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’m setting up a new ASA VPN firewall for all our vendor site-to-site connections. I don’t want to expose my inside subnets to the vendors so I was going to carve out subnets from a 10.3.0.0/16 space to NAT the traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; -------------------------------&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Vendor X subnet &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Object network &lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt;"&gt;VEND_X_VPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;192.168.1.0 /24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Internal subnet&lt;/STRONG&gt; for vendor X to connect to”&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Object network &lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt;"&gt;MY_VPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;10.1.60.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object network &lt;STRONG&gt;VEND_NAT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 10pt;"&gt;network 10.3.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT Statement&lt;/STRONG&gt; – this would be applied on my firewall so I’m assuming the Vendor will put the NAT’d address (10.3.1.0/24)in his crypto map to connect to. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source dynamic object-group MY_VPN obj-VEND_NAT destination static VEND_X_VPN VEND_X_VPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; -------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this look right? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/2420259#M308967</guid>
      <dc:creator>Mike Hogenauer</dc:creator>
      <dc:date>2019-03-12T03:04:51Z</dc:date>
    </item>
    <item>
      <title>NAT Help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/2420260#M308968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just change it to source static:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static object-group MY_VPN obj-VEND_NAT destination static VEND_X_VPN VEND_X_VPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPN portion is correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 00:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/2420260#M308968</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-14T00:36:11Z</dc:date>
    </item>
    <item>
      <title>NAT Help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/2420261#M308970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On your local VPN math address ACL you need to put the &lt;STRONG style="font-size: 10pt;"&gt;10.3.1.0/24 &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 00:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/2420261#M308970</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-14T00:37:34Z</dc:date>
    </item>
    <item>
      <title>NAT Help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/2420262#M308972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have any doubts please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark as answered and rate the assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 00:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/2420262#M308972</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-14T00:45:39Z</dc:date>
    </item>
    <item>
      <title>NAT Help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/2420263#M308975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jumora! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically my crypto map ACL will look like:&lt;/P&gt;&lt;P&gt;ACL crypto 1 permit my_vpn vend_nat &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I dint need to reference the vendors 192 subnet because the inside interface is doing the NATing correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 02:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/2420263#M308975</guid>
      <dc:creator>Mike Hogenauer</dc:creator>
      <dc:date>2013-11-14T02:53:00Z</dc:date>
    </item>
    <item>
      <title>NAT Help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/2420264#M308977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok wait, from what I understood what you were doing was NATTING your local network so that the remote VPN network would not know of your real network 10.1.60.0/24 so you were going to translate it to &lt;STRONG style="font-size: 10pt;"&gt;10.3.1.0/24 when going to &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;192.168.1.0 /24. If this was the case the NAT rule that I going to place under this conversation is correct:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static object-group MY_VPN obj-VEND_NAT destination static VEND_X_VPN VEND_X_VPN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Then what you need to add on the match address ACL would be somehting like this:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list VPN &lt;STRONG&gt;permit ip 10.3.1.0 255.255.255.0 &lt;/STRONG&gt;192.168.1.0&amp;nbsp; 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is what I was saying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 17:00:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/2420264#M308977</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-14T17:00:24Z</dc:date>
    </item>
  </channel>
</rss>

