<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please help !!! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345658#M343726</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jouni for your reply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Sep 2013 00:43:20 GMT</pubDate>
    <dc:creator>Rohit Mangotra</dc:creator>
    <dc:date>2013-09-05T00:43:20Z</dc:date>
    <item>
      <title>Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345651#M343715</link>
      <description>&lt;P&gt;We were running Cisco ASA 5520 version 5.2 at the moment, and now we are upgrading to ASA 5525 X series version 8.6. Below is the sample code that I have attached, could anyone please tell me if I am doing this right? Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;current version 5.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 2 202.190.70.80&lt;/P&gt;&lt;P&gt;global (dmz) 2 192.168.1.59&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.108.0 255.255.255.192&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.108.64 255.255.255.192&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.30.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 2 192.168.128.0 255.255.255.252&lt;/P&gt;&lt;P&gt;nat (inside) 2 192.168.129.0 255.255.255.252&lt;/P&gt;&lt;P&gt;nat (dmz) 2 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;To new ASA version 8.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.16.2.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.16.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.16.5.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.16.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.16.10.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.20.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.30.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.30.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.30.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.108.0 255.255.255.192&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.16.108.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.16.108.0 255.255.255.192&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.108.64 255.255.255.192&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.16.108.64&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.16.108.64 255.255.255.192&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 192.168.128.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-192.168.128.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 192.168.128.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 192.168.129.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-192.168.129.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 192.168.129.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz) 2 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-192.168.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (dmz,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (dmz,dmz) dynamic 192.168.1.59&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345651#M343715</guid>
      <dc:creator>Rohit Mangotra</dc:creator>
      <dc:date>2019-03-12T02:32:36Z</dc:date>
    </item>
    <item>
      <title>Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345652#M343717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first thing to notice is that you can only have a SINGLE &lt;STRONG&gt;"nat"&lt;/STRONG&gt; statement under an &lt;STRONG&gt;"object network"&lt;/STRONG&gt; so that configuration you propose wont work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you could try are the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network INSIDE-PAT-SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 172.16.2.0 255.255.255.252&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 172.16.5.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 172.16.10.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 172.16.108.0 255.255.255.192&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 172.16.108.64 255.255.255.192&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 172.20.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 172.30.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 192.168.128.0 255.255.255.252&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 192.168.129.0 255.255.255.252&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network OUTSIDE-PAT-IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 202.190.70.80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network DMZ-PAT-IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.59&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) after-auto source dynamic INSIDE-PAT-SOURCE OUTSIDE-PAT-IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,dmz) after-auto source dynamic INSIDE-PAT-SOURCE DMZ-PAT-IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above configuration should handle Dynamic PAT from &lt;STRONG&gt;"inside"&lt;/STRONG&gt; to &lt;STRONG&gt;"outside"&lt;/STRONG&gt; and from &lt;STRONG&gt;"inside"&lt;/STRONG&gt; to &lt;STRONG&gt;"dmz"&lt;/STRONG&gt;. Though I personally rather not configure any dynamic NAT/PAT between my local interfaces but I assume you have some reason for it, perhaps related to routing behind &lt;STRONG&gt;"dmz"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network DMZ-PAT-SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 192.168.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz,outside) after-auto source dynamic DMZ-PAT-SOURCE OUTSIDE-PAT-IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above configuration should handle Dynamic PAT from &lt;STRONG&gt;"dmz"&lt;/STRONG&gt; to &lt;STRONG&gt;"outside"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please&amp;nbsp; do remember to mark a reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 07:07:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345652#M343717</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-30T07:07:45Z</dc:date>
    </item>
    <item>
      <title>Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345653#M343718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot Jouni for the quick reply. Based on your suggestion that we can not use more than one NAT statement under Object Network. Can we do the following way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; object network obj-172.16.2.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.16.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 202.190.70.80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; object network obj-172.16.2.0-01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 172.16.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (inside,dmz) dynamic 192.168.1.59&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Furthermore, I am not familiar with after-auto source&amp;nbsp; dynamic command yet. I will do bit more reading on this one. However, the way you suggest seems straight forward and easy to follow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You,&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rohit.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 07:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345653#M343718</guid>
      <dc:creator>Rohit Mangotra</dc:creator>
      <dc:date>2013-08-30T07:33:18Z</dc:date>
    </item>
    <item>
      <title>Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345654#M343719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you could do it in the above way but in my opinion it just generates so much more configurations that it makes the configuration messy and harder to read.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The example I gave only generates 3 actual NAT configurations along with the couple of &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; and &lt;STRONG&gt;"object" &lt;/STRONG&gt;and achieves all the same things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT configuration format that I use are basically Manual NAT while your examples are Auto NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manual NAT is by default Section 1, which means its matched first from all the NAT configurations. With an&lt;STRONG&gt; "after-auto" &lt;/STRONG&gt;parameter in the configuration its moved to Section 3 which essentially lowers it to the very bottom priority when matching NAT rules/configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Auto NAT is always Section 2 which places it to the middle in terms of priority when matching NAT rules/configurations)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One big different with Auto NAT and Manual NAT is the fact that Manual NAT can NAT both the source and the destination address. That is why you are seeing parameters like &lt;STRONG&gt;"source dynamic"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is some more information related to the new NAT on a document I wrote here on CSC&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-31116"&gt;https://supportforums.cisco.com/docs/DOC-31116&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please&amp;nbsp; do remember to mark a reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 07:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345654#M343719</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-30T07:41:49Z</dc:date>
    </item>
    <item>
      <title>Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345655#M343721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot Jouni for quick reply. I think I need to read a bit more on this. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 08:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345655#M343721</guid>
      <dc:creator>Rohit Mangotra</dc:creator>
      <dc:date>2013-08-30T08:45:10Z</dc:date>
    </item>
    <item>
      <title>Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345656#M343723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just one more question I want to confirm:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, we have the VPN concentrator behind ASA 5.1. As mentioned, we are going to upgrade to version 8.6. Could you please have a look at the following static NAT transformation if it is correct or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.31&lt;/P&gt;&lt;P&gt; vlan 31&lt;/P&gt;&lt;P&gt; nameif vpn_private&lt;/P&gt;&lt;P&gt; security-level 75&lt;/P&gt;&lt;P&gt; ip address 172.31.0.1 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.67&lt;/P&gt;&lt;P&gt; vlan 67&lt;/P&gt;&lt;P&gt; nameif vpn_public&lt;/P&gt;&lt;P&gt; security-level 75&lt;/P&gt;&lt;P&gt; ip address a.b.c.177 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) static (dmz,vpn_private) 192.168.1.0 192.168.1.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;2) static (dmz,vpn_public) 192.168.1.0 192.168.1.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;3) static (inside,vpn_private) 172.16.0.0 172.16.0.0 netmask 255.255.0.0&lt;/P&gt;&lt;P&gt;4) static (inside,vpn_public) 172.16.0.0 172.16.0.0 netmask 255.255.0.0 &lt;/P&gt;&lt;P&gt;5) static (vpn_private,inside) 172.31.0.0 172.31.0.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;6) static (vpn_public,outside) a.b.c.176 a.b.c.176 netmask 255.255.255.240&lt;/P&gt;&lt;P&gt;7) static (vpn_public,inside) a.b.c.176 a.b.c.176 netmask 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) object network obj-192.168.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (dmz,vpn_private) static obj-192.168.1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) object network obj-192.168.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (dmz,vpn_public) static obj-192.168.1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) object network obj-172.16.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 172.16.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (inside,vpn_private) static obj-172.16.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) object network obj-172.16.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 172.16.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (inside,vpn_public) static obj-172.16.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5) object network obj-172.31.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 172.31.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (vpn_private,inside) static obj-172.31.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6) object network obj-a.b.c.176&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet a.b.c.176 255.255.255.240&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (vpn_public,outside) static obj-a.b.c.176&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7) object network obj-a.b.c.176&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet a.b.c.176 255.255.255.240&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (vpn_public,inside) static obj-a.b.c.176&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for all your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Rohit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 04:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345656#M343723</guid>
      <dc:creator>Rohit Mangotra</dc:creator>
      <dc:date>2013-09-04T04:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345657#M343724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All of those configurations would seem to be Static Identity NAT. Essentially used in the current setup to enable traffic without doing NAT to the source/destination IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I usually leave out those&lt;STRONG&gt; "static"&lt;/STRONG&gt; configurations completely and wont create any configurations to replace them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though I usually like to look at the whole setup before making decisions or leaving any configurations off the migration configuration. I am not completely sure what the &lt;STRONG&gt;"static"&lt;/STRONG&gt; configurations that are between your local interfaces and the public VPN interface. Typically the VPN public interface would only have NAT configurations towards the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 06:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345657#M343724</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-04T06:31:05Z</dc:date>
    </item>
    <item>
      <title>Please help !!!</title>
      <link>https://community.cisco.com/t5/network-security/please-help/m-p/2345658#M343726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jouni for your reply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 00:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help/m-p/2345658#M343726</guid>
      <dc:creator>Rohit Mangotra</dc:creator>
      <dc:date>2013-09-05T00:43:20Z</dc:date>
    </item>
  </channel>
</rss>

