<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic PAT 9.1(x) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313429#M342979</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks again Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I'm using the following configs , and it seems that is working as expected. Now I only need to wait to exhausted the "interface" PAT address in order to confirm that uses the next PAT address defined on the range:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any-inside&lt;BR /&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-A.A.A.A-B.B.B.B&lt;BR /&gt; range A.A.A.A B.B.B.B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manual NAT Policies (Section 3)&lt;BR /&gt;1 (inside) to (outside) source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B interface&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 19728, untranslate_hits = 5854&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by the way the xlate are hitting the "interface" outside , I was looking for that &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 14 Sep 2013 11:34:17 GMT</pubDate>
    <dc:creator>asotres</dc:creator>
    <dc:date>2013-09-14T11:34:17Z</dc:date>
    <item>
      <title>Dynamic PAT 9.1(x)</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313425#M342972</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already set up a Dynamic PAT ( manual NAT) for Internet traffic as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any-inside&lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic obj_any-inside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything was good until,&amp;nbsp; I started to receive a NAT/PAT pool exhausted log message since we had 65,000 + NAT xlates, so I decided to add another Dynamic PAT with a range of ip adddresses without removing the original PAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-A.A.A.A-B.B.B.B&lt;BR /&gt;range A.A.A.A B.B.B.B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B round-robin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;= Is this is a valid configuration in order to,&amp;nbsp; if the first PAT get exhausted the next xlate will hit the second PAT ( Pool range)&amp;nbsp; and start using the A.A.A.A as PAT address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5585-X-9.1# sh run nat&lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic obj_any-inside interface&lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B round-robin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5585-X-9.1# sh nat&lt;/P&gt;&lt;P&gt;2 (inside) to (outside) source dynamic obj_any-inside interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1204998, untranslate_hits = 68047&lt;/P&gt;&lt;P&gt;3 (inside) to (outside) source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B round-robin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313425#M342972</guid>
      <dc:creator>asotres</dc:creator>
      <dc:date>2019-03-12T02:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT 9.1(x)</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313426#M342974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to say that I have yet to reach a situation where I would&amp;nbsp; have faced this problem as in our environments with bigger customer (on our scale) there is usually different Dynamic PAT addresses assigned for different sections/users of the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I think you could probably do is combine both of the proposed Dynamic PAT configurations into a single configuration line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) after-auto source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B interface round-robin&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine this would enable to have both the range of PAT-addresses in use and the &lt;STRONG&gt;"interface"&lt;/STRONG&gt; IP address also as a PAT IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you dont want to remove the original one I guess you could use a variant of the above command and add it with a priority/line number so it sits on top of the current Dynamic PAT rule. Though your current Dynamic PAT rules are Section 1 Twice NAT / Manual NAT rules so I am kind of wondering how the rest of the NAT rules are built if you have these rules at such a high priority.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used the &lt;STRONG&gt;"after-auto"&lt;/STRONG&gt; in the Twice NAT / Manual NAT configuration as I typically use the basic/default Dynamic PAT configuration at the very lowest priority so that they dont interfere with the operation of Static NAT/PAT or possibly some Policy type NAT/PAT configurations. I guess in your situation you would have to modify the above command to remove the &lt;STRONG&gt;"after-auto"&lt;/STRONG&gt; and add a line number after the &lt;STRONG&gt;")"&lt;/STRONG&gt; to insert the rule on top of the current rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess there would be an option to change the &lt;STRONG&gt;"timeout pat-xlate 0:00:30"&lt;/STRONG&gt; default value too BUT again I have not tested this or had to use it myself to this day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What exactly is the traffic that manages to consume your whole PAT port range? Is there a lot of users or large amount of connections from fewer hosts? Have you checked the &lt;STRONG&gt;"show nat pool"&lt;/STRONG&gt; output while this was happenning?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe this configuration command might also help with your situation?&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/command-reference/wz.html#wp1837352" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/asa/command-reference/wz.html#wp1837352&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Sep 2013 10:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313426#M342974</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-14T10:20:38Z</dc:date>
    </item>
    <item>
      <title>Dynamic PAT 9.1(x)</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313427#M342976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Jouni , let me try combine both . I haven't checked the "show nat pool" , and most of the traffic is Internet Traffic , since this firewall is only for Egress Internet for all users, I could say that is the only NAT/PAT that we are running on this box for now!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Sep 2013 10:31:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313427#M342976</guid>
      <dc:creator>asotres</dc:creator>
      <dc:date>2013-09-14T10:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic PAT 9.1(x)</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313428#M342977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A quick test with a NAT Pool configurations where I had 2 Dynamic NAT configuration line below on my test firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network NAT1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; range 1.1.1.1 1.1.1.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network NAT2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; range 2.2.2.1 2.2.2.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (WLAN,WAN) after-auto source dynamic any NAT1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (WLAN,WAN) after-auto source dynamic any NAT2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I tested what would happen with exhausting the 2 IP address range configured under &lt;STRONG&gt;"object network NAT1"&lt;/STRONG&gt; what resulted was that the traffic hitting from a third source address hit the same first NAT rule and NAT failed for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;3RD SOURCE ADDRESS PACKET-TRACER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Phase: 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: NAT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Subtype:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Result: ALLOW&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (WLAN,WAN) after-auto source dynamic any NAT1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Additional Information:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Additional Information should specify which translation is done. It doesnt so no translation was performed&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Result:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;input-interface: WLAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;input-status: up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;input-line-status: up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;output-interface: WAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;output-status: up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;output-line-status: up&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Action: drop&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Drop-reason: (nat-xlate-failed) NAT failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Translation failed&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if this will be the same for Dynamic PAT as the above configuration that I mentioned was Dynamic NAT with 2 IP address pools.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess if the Dynamic PAT ignores the following Dynamic PAT configurations in the same way then I would suggest considering creating a single Dynamic PAT Pool configuration with possinly adding the &lt;STRONG&gt;"interface"&lt;/STRONG&gt; parameter as mentioned earlier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or you could create multiple Dynamic PAT rules but rather than specifying ANY source address, divice your internal networks in &lt;STRONG&gt;"object network"&lt;/STRONG&gt; or &lt;STRONG&gt;"object-group network"&lt;/STRONG&gt; and give them their own Dynamic PAT IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Sep 2013 10:41:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313428#M342977</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-14T10:41:54Z</dc:date>
    </item>
    <item>
      <title>Dynamic PAT 9.1(x)</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313429#M342979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks again Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I'm using the following configs , and it seems that is working as expected. Now I only need to wait to exhausted the "interface" PAT address in order to confirm that uses the next PAT address defined on the range:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any-inside&lt;BR /&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-A.A.A.A-B.B.B.B&lt;BR /&gt; range A.A.A.A B.B.B.B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manual NAT Policies (Section 3)&lt;BR /&gt;1 (inside) to (outside) source dynamic obj_any-inside pat-pool obj-A.A.A.A-B.B.B.B interface&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 19728, untranslate_hits = 5854&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by the way the xlate are hitting the "interface" outside , I was looking for that &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Sep 2013 11:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-pat-9-1-x/m-p/2313429#M342979</guid>
      <dc:creator>asotres</dc:creator>
      <dc:date>2013-09-14T11:34:17Z</dc:date>
    </item>
  </channel>
</rss>

