<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT object with destination address exclusion (ASA) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325298#M311035</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jouni,&lt;/P&gt;&lt;P&gt; seems like you purified what I wrote above, so I think it should work now with you right and legit commands. &lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;&lt;P&gt;Marek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 13 Oct 2013 16:23:42 GMT</pubDate>
    <dc:creator>mareks-vader</dc:creator>
    <dc:date>2013-10-13T16:23:42Z</dc:date>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325286#M311014</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;can you please advice how to make a NAT object where I want map all traffic from one address a.b.c.d to address x.y.v.z exluding that traffic which is going to k.l.m.n.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is like this BSD rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;map xl3 from a.b.c.d/24 ! to k.l.m.n/13 -&amp;gt; x.y.v.z/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325286#M311014</guid>
      <dc:creator>mareks-vader</dc:creator>
      <dc:date>2019-03-12T02:51:38Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325287#M311015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure I understand your question completely.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying that you simply want to map a certain host address to something else when it going to a certain destination address? If so you can naturally configure this with Manual NAT. This Manual NAT would only apply when traffic is coming from certain source address and going to certain destination address. All other traffic would have some other NAT rule applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't really exclude anything from a NAT configurations in the new ASA software levels (8.3 and above). You simply configure the NAT to be as specific as it can to apply to only the certain traffic you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The older software levels (8.2 and below) I think had some changes to exclude some traffic from a NAT rule but even then it had pretty limited options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I think we need a bit clarification on what the actual setup requirement is (atleast I do &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 12:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325287#M311015</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-13T12:19:20Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325288#M311017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jouni, thank you for quick reply.&lt;/P&gt;&lt;P&gt;It is that I´m new in this, and reading a manual is not helping me. I can do a simple rule like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_name&lt;/P&gt;&lt;P&gt;host a.b.c.d&lt;/P&gt;&lt;P&gt;nat (GE0/1,any) static x.y.v.z service tcp no1 no2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which I simply understand that it is maping outgoing ip a.b.c.d to x.y.v.z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I need is that firewall will look on packet and if it would go to destination ip k.l.m.n it won ´t translate address a.b.c.d to x.y.v.z&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or maybe I´m confused a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Marek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 12:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325288#M311017</guid>
      <dc:creator>mareks-vader</dc:creator>
      <dc:date>2013-10-13T12:29:01Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325289#M311018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems that your original NAT rule above is a Static PAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its also configured that this translation will apply to any destination interface. I personally tend to use only the required destination interface in the &lt;STRONG&gt;"nat"&lt;/STRONG&gt; command so that it doesnt apply to traffic from other interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to know that I am giving the right instructions I would need to know behind which interface are the destination networks to which your example NAT should apply to and behind which interface is the destination k.l.m.n address that this NAT should not apply to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still a bit confused on the NAT configuration you have provided. Its a Static PAT configurations that is usually configured to enable connections incoming from the destination interface of the command and it usually doesnt apply to connections formed from the source host a.b.c.d (except when its replying to the connection coming from behind the other interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you had said that you had this Static NAT configurations (that doesnt mention the service)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj_name&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;host a.b.c.d&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (GE0/1,any) static x.y.v.z&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then the example would have been clearer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to give an example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Static NAT configurations that binds a local address to public address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network STATIC&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (LAN,WAN) static 1.1.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if the host 10.10.10.10 connects to any network behind interface &lt;STRONG&gt;"WAN"&lt;/STRONG&gt; it will always have this NAT applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we want to avoid this from happening and have some certain destination IP address to which we dont want to do any translation then we would configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network DESTINATION&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host k.l.m.n&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network HOST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (LAN,WAN) source static HOST HOST destination DESTINATION DESTINATION&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above configure is most commonly used in situation where the host needs to be contacted from behind a VPN Client or L2L VPN Connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 12:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325289#M311018</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-13T12:42:45Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325290#M311022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;so when I have this BSD rule:&lt;/P&gt;&lt;P&gt;map xl2 from 192.168.1.0/24 ! to 10.50.0.0/13 -&amp;gt; 90.162.12.2/32&lt;/P&gt;&lt;P&gt;where xli1 is LAN and xl2 is WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it should be like this?:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object netwok HOST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subnet 192.168.1.0 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object netwok EXCLUDE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subnet 10.50.0.0 255.240.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (xl1,xl2) source static HOST destination 90.162.12.2 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (xl1,xl2) source static HOST HOST destination EXCLUDE EXCLUDE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;???&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Marek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 13:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325290#M311022</guid>
      <dc:creator>mareks-vader</dc:creator>
      <dc:date>2013-10-13T13:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325291#M311024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea about BSD rules myself. I guess it refers to an actual PC OS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you have a Static NAT configured for a SINGLE host and want to avoid that Static NAT being applied when the host in question connects to a certain destination network/host (or even multiple different networks/hosts) then you would configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static NAT&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This is the Static NAT configurations for the actual host that might already exists&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network STATIC&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host &lt;HOST local="" ip=""&gt;&lt;/HOST&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (xl1,xl2) static &lt;PUBLIC ip=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NONAT / NAT0 / NAT Exempt&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This configuration is the NAT configuration with which we want to avoid the above Static NAT being applied to the host when it connects to a certain network.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network NONAT-DESTINATION&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; subnet &lt;DESTINATION network=""&gt; &lt;MASK&gt;&lt;/MASK&gt;&lt;/DESTINATION&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network NONAT-SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host &lt;HOST local="" ip=""&gt;&lt;/HOST&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (xl1,xl2) source static NONAT-SOURCE NONAT-SOURCE destination static NONAT-DESTINATION NONAT-DESTINATION&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above configuration we first define Static NAT for IP address &lt;STRONG&gt;&lt;HOST local="" ip=""&gt;&lt;/HOST&gt;&lt;/STRONG&gt; to the NAT IP address of &lt;STRONG&gt;&lt;PUBLIC ip=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have a requirement that the above Static NAT should not&amp;nbsp; apply for this &lt;STRONG&gt;&lt;HOST local="" ip=""&gt;&lt;/HOST&gt;&lt;/STRONG&gt; when the destination is &lt;STRONG&gt;&lt;DESTINATION network=""&gt;&lt;/DESTINATION&gt;&lt;/STRONG&gt; therefore we configure another NAT configuration that is on a higher priority in the ASAs NAT configurations and will therefore override the Static NAT in the cases we need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this made sense &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 13:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325291#M311024</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-13T13:16:08Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325292#M311026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Great, this means sense to me now.&lt;/P&gt;&lt;P&gt;Just one question that higher priority is because that Static NAT is made inside the object STATIC and the second rule is made outside any object?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much, appreciate your help.&lt;/P&gt;&lt;P&gt;Marek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 13:23:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325292#M311026</guid>
      <dc:creator>mareks-vader</dc:creator>
      <dc:date>2013-10-13T13:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325293#M311028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its a bit hard to explain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did write a document here on the Cisco Support Community about this new NAT configuration format, even though it doesnt yet answer all the questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can look at it here&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-31116" rel="nofollow"&gt;https://supportforums.cisco.com/docs/DOC-31116&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It explains the order of NAT configurations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But to explain the same thing here it would basically be this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are essentially 2 type of NAT configurations in the new ASA software.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;There is Auto NAT / Network Object NAT which are configured inside "object network"&lt;/LI&gt;&lt;LI&gt;There is Manual NAT / Twice NAT wich are NOT configured inside any object. They on the other hand use "object network" and "object-group network" to define the conditions to for the NAT.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are also 3 Sections of NAT configurations&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Section 1 is the highest and first matched NAT configuration and its Manual NAT / Twice NAT (like the NAT0 example above)&lt;/LI&gt;&lt;LI&gt;Section 2 is the next in priority and its configured with Auto NAT / Network Object NAT only!&lt;/LI&gt;&lt;LI&gt;Section 3 is the lowest priority and its configured with Manual NAT / Twice NAT. A Manual NAT / Twice NAT configuration is consider to be Section 3 when you add an &lt;STRONG&gt;"after-auto"&lt;/STRONG&gt; parameter to the command. Otherwise the configuration is identical to the Section 1. The &lt;STRONG&gt;"after-auto"&lt;/STRONG&gt; refers to the fact that these rules come after the Auto NAT&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;nat (xl1,xl2) &lt;SPAN style="color: #ff0000;"&gt;after-auto&lt;/SPAN&gt; source static NONAT-SOURCE NONAT-SOURCE destination static NONAT-DESTINATION NONAT-DESTINATION&lt;/STRONG&gt; (even though configuring this with so low priority wouldnt really make sense)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that made sense &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do remember to mark a reply as the correct answer if it answered your question and rate helpfull answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to ask more if needed though&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 13:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325293#M311028</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-13T13:31:10Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325294#M311030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Amazing, now I understand it well and I can do some more difficult things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to translate all udp and tcp traffic from 172.50.20.0/24 to 90.160.12.2 but to ports 20001-30000 is this correct after our discussion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object netwok SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subnet 172.50.20.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service UDP_IN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service udp source any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service UDP_OUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service udp source range 20001 30000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service TCP_IN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service tcp source any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service TCP_OUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service tcp source range 20001 30000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside, outside) source static SOURCE 90.160.12.2 service UDP_IN UDP_OUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside, outside) source static SOURCE 90.160.12.2 service TCP_IN TCP_OUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Marek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 13:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325294#M311030</guid>
      <dc:creator>mareks-vader</dc:creator>
      <dc:date>2013-10-13T13:52:25Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325295#M311032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think again we have to clarify a bit what you want to actually do so I can give an accurate answer. If I understood you correctly you have used some other device to do NAT before Cisco firewalls so we might be talking about the same things but with a bit different terms/logic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Translate the SOURCE network 172.50.20.0/24 to the PAT IP address 90.160.12.2 when the SOURCE network is connecting to ports TCP/UDP 20001-30000&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR Do you want to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Translate the SOURCE network 172.50.20.0/24 to the PAT IP address 90.160.12.2 and be visible to the hosts behind "outside" interface with TCP/UDP ports 20001-30000&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR something else perhaps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 14:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325295#M311032</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-13T14:05:51Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325296#M311033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jouni,&lt;/P&gt;&lt;P&gt;the second one is what I actualy want to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Marek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 14:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325296#M311033</guid>
      <dc:creator>mareks-vader</dc:creator>
      <dc:date>2013-10-13T14:10:10Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325297#M311034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I have gotten this to work better with some configuration but couldnt find that post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine this is not some configuration I would want to suggest to anyone without having doubts of its actual performance and reliability.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service TCP-REAL-PORTS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source range 0 65535&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service TCP-MAPPED-PORTS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source range 20001 30000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service UDP-REAL-PORTS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service udp source range 0 65535&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service UDP-MAPPED-PORTS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service udp source range 20001 30000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object netwok SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subnet 172.50.20.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PUBLIC&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 90.160.12.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static SOURCE PUBLIC service TCP-REAL-PORTS TCP-MAPPED-PORTS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static SOURCE PUBLIC service UDP-REAL-PORTS UDP-MAPPED-PORTS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When testing traffic from &lt;STRONG&gt;"inside"&lt;/STRONG&gt; to &lt;STRONG&gt;"outside"&lt;/STRONG&gt; with the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command it seemed to operate the way you wanted but I am still not really convinced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will have to see if I can find the older thread/discussion where I made a similiar configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 15:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325297#M311034</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-13T15:33:10Z</dc:date>
    </item>
    <item>
      <title>NAT object with destination address exclusion (ASA)</title>
      <link>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325298#M311035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jouni,&lt;/P&gt;&lt;P&gt; seems like you purified what I wrote above, so I think it should work now with you right and legit commands. &lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;&lt;P&gt;Marek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 16:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-object-with-destination-address-exclusion-asa/m-p/2325298#M311035</guid>
      <dc:creator>mareks-vader</dc:creator>
      <dc:date>2013-10-13T16:23:42Z</dc:date>
    </item>
  </channel>
</rss>

