<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I utilize multiple internet IP addresses on an ASA inter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/3766319#M347929</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I forgot to mention that we're using a OVH VRack.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.ovh.com/gb/en/dedicated/ip-block-vrack/" target="_blank"&gt;https://docs.ovh.com/gb/en/dedicated/ip-block-vrack/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
    <pubDate>Wed, 19 Dec 2018 01:11:15 GMT</pubDate>
    <dc:creator>patrickheinzelmann</dc:creator>
    <dc:date>2018-12-19T01:11:15Z</dc:date>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA interface</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231441#M347912</link>
      <description>&lt;P&gt;I have a single ASA and multiple internet IP addresses available.&amp;nbsp; I'll have internal networks InsideA and InsideB, which will be on seperate subnets.&lt;/P&gt;&lt;P&gt;I would like four external interfaces, OutsideW, OutsideX, OutsideY, and OutsideZ.&lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have been alloted several&amp;nbsp; internet IP addresses, but they are contiguous.&amp;nbsp;&amp;nbsp;&amp;nbsp; That means I can not create an subinterface for each IP, as they would overlap.&amp;nbsp;&amp;nbsp; I don't believe ASA have standby interfaces.&amp;nbsp;&amp;nbsp; Is there a way I can take advantage of the multiple internet addresses?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231441#M347912</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2019-03-12T01:59:08Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231442#M347913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You dont tell us why you would want to configure such setup. What would be your aim?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing you can do is use these different public IP addresses as NAT IP address on the ASA. Whether if they are configured directly on the "outside" interface or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can you please clarify what the purpose of even attempting something like this be?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 16:32:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231442#M347913</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-17T16:32:05Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231443#M347914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;The setup is partially legacy, and we are consolodating several off-site proxies into one area.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think what you are saying is I have no need for multiple IPs.&amp;nbsp; I can take my multiple "inside" networks and push them out over one IP.&amp;nbsp; Then I would use Policy NAT to seperate which inside PC went to which final destination.&amp;nbsp;&amp;nbsp; Is that what you are saying?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would prefer to have my Inside1 network as isolated as possible from my Inside2 network.&amp;nbsp;&amp;nbsp; Inside1 will be general internet, Inside2 will be important financial information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I have general internet traffic use one IP address, and have the financial information come in on another?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 18:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231443#M347914</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2013-06-17T18:14:09Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231444#M347915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a small public subnet on your current "outside" interface on the ASA then theres nothing stopping you from giving each of your internal LAN networks their own public NAT IP address with which they are visible to the Internet. This can be done by configuring Dynamic PAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally if you have 2 different LAN networks (interfaces) on the ASA then there is also nothing stopping you from completely blocking the traffic between these 2 LAN segments (interfaces)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wish so, you are naturally also able to use the remaining public IP addresses for Static NAT for the different hosts/servers behind your ASAs LAN interfaces. That is if you need to provide connectivity to some of your servers through the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still not 100% sure on how you want to setup the ASA and your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 18:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231444#M347915</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-17T18:43:43Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231445#M347916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i think you need the config below ??????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;BR /&gt;description 802.1q Trunking Interface for test networks&lt;/P&gt;&lt;P&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.2&lt;BR /&gt;description Test Subnet 1&lt;/P&gt;&lt;P&gt;vlan 2&lt;BR /&gt;nameif test1&lt;/P&gt;&lt;P&gt;security-level 90&lt;BR /&gt;ip address 10.1.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1.3&lt;BR /&gt;description Test Subnet 2 vlan 3&lt;BR /&gt;nameif test2&lt;BR /&gt;security-level 80&lt;BR /&gt;ip address 10.1.2.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope the above config help you.....??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 18:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231445#M347916</guid>
      <dc:creator>taurusadnan</dc:creator>
      <dc:date>2013-06-17T18:47:57Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231446#M347917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have a small subnet of public addresses on the outside, lets say 50.50.50.1 - 50.50.50.7. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; How can I take advantage of the six usable addresses?&amp;nbsp;&amp;nbsp; There&amp;nbsp; are no secondary addresses on the ASA.&amp;nbsp;&amp;nbsp; And I can't configure six outside interfaces, since they are all in the same subnet.&amp;nbsp;&amp;nbsp; That is my basic problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 00:45:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231446#M347917</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2013-06-18T00:45:07Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231447#M347918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cant split that single subnet to several interfaces on the ASA as you say. Also notice that if you have an /29 subnet then it means you will have 8 IP address of which 5 are USABLE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1 IP address is the subnet/network address and CANT BE USED&lt;/LI&gt;&lt;LI&gt;1 IP address needs to be used for the gateway of that network and CANT BE USED on the ASA&lt;/LI&gt;&lt;LI&gt;1 IP address is the broadcast IP address of the subnet/network and CANT BE USED&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So as you can see, you can only use 5 public IP addresses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only situation on an ASA where you could possibly split even those 5 IP addresses to 5 different interfaces would be to configure the ASA in Multiple Context mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would essentially mean virtualizing your ASA and configure 5 virtual firewalls in that single hardware. Then you could share the same "outside" interface on each virtual firewall and have different public IP address for each firewall. This would also essentially provide the isolation that you want between the local network. Ofcourse provided that the network behind the ASA isnt tied together also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though, while the virtual firewall might suite your needs better in your situation (if I understood your needs correctly) it would most probably mean that you would have to get additional licenses from Cisco to enable those features. You can confirm the support for Security Contexts with the "show version" command on the ASA. It should list the amount provided your ASA supports them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 06:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231447#M347918</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-18T06:08:44Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231448#M347919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks again Jouni.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to use the multiple internet addresses?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is Policy-Nat going to help me here, where Inside1 uses one internet address, and Inside2 uses another?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm still confused on how Policy-Nat works, and I've looked at three examples in the textbooks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 14:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231448#M347919</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2013-06-18T14:50:44Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231449#M347921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can naturally give different local network different public IP address towards the Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example lets say you have&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;2 local networks &lt;STRONG&gt;10.10.10.0/24&lt;/STRONG&gt; and &lt;STRONG&gt;10.10.20.0/24&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;2 interfaces called &lt;STRONG&gt;"lan-1" &lt;/STRONG&gt;and &lt;STRONG&gt;"lan-2"&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;1 wan interface called &lt;STRONG&gt;"wan"&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the requirement is that all the hosts on each local network should be PATed to their own public IP address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you could configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;ASA 8.2 and older software level&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (wan) 10 1.1.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (wan) 20 1.1.1.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (lan-1) 10 10.10.10.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (lan-2) 10 10.10.20.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;ASA 8.3 and newer software level&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network LAN-1-PAT-SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 10.10.10.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network LAN-2-PAT-SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 10.10.20.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PAT-IP-1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 1.1.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PAT-IP-2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 1.1.1.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (lan-1,wan) after-auto source dynamic LAN-1-PAT-SOURCE PAT-IP-1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (lan-2.wan) after-auto source dynamic LAN-2-PAT-SOURCE PAT-IP-2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above would configure Dynamic PAT using different public IP addresses for each LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally you can also configure Static NAT for your servers in addition to this if you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as I said I am not completely sure of your setup and its requirements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 15:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231449#M347921</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-18T15:34:37Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231450#M347923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; One last question: what would the WAN interface configuration look like?&lt;/P&gt;&lt;P&gt;That's where I get confused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231450#M347923</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2013-06-18T17:39:09Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231451#M347924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well lets say you have the network 50.50.50.0/29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;50.50.50.0 is the network address&lt;/LI&gt;&lt;LI&gt;50.50.50.1 is the ISP gateway&lt;/LI&gt;&lt;LI&gt;50.50.50.2 is the ASA &lt;STRONG&gt;"wan"&lt;/STRONG&gt; interface IP address&lt;UL&gt;&lt;LI&gt;Can be used for NAT also&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;50.50.50.3 free to be used with NAT&lt;/LI&gt;&lt;LI&gt;50.50.50.4 free to be used with NAT&lt;/LI&gt;&lt;LI&gt;50.50.50.5 free to be used with NAT&lt;/LI&gt;&lt;LI&gt;50.50.50.6 free to be used with NAT&lt;/LI&gt;&lt;LI&gt;50.50.50.7 is the broadcast address of the subnet. Cant be used for NAT&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your WAN interface would be configured the same way as always.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface GigabitEthernet0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; description WAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nameif wan&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; security-level 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; ip address 50.50.50.2 255.255.255.248&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route wan 0.0.0.0 0.0.0.0 50.50.50.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can basically configure the available public IP address for different NAT as you see fit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 17:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231451#M347924</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-18T17:53:31Z</dc:date>
    </item>
    <item>
      <title>How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231452#M347926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I think I got it.&amp;nbsp;&amp;nbsp; This is a tremendous help.&amp;nbsp; Will give it a shot in the lab and will close the trail soon.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 18:04:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/2231452#M347926</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2013-06-18T18:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/3766310#M347927</link>
      <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can I also use to different RIPE blocks at the same interface wan?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We setup the new ASAv on ESXi and our servers are currently using multiple smaller RIPE Blocks (8 to 16 IPs).&amp;nbsp;As we want to move the servers behind the firewall, I&amp;nbsp;added them as "Public Server" for testing purposes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This only works if the servers are using an IP address of the same RIPE Block as the wan interface of the ASAv.&lt;/P&gt;
&lt;P&gt;Can we using some routing to use a different&amp;nbsp;gateway&amp;nbsp;for an other RIPE Block?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently, I have added following&amp;nbsp;static routes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;route wan 0.0.0.0 0.0.0.0&amp;nbsp;xxx&lt;SPAN&gt;.xxx.100.1 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;route wan xxx.xxx.xxx.200&amp;nbsp;255.255.255.248 xxx.xxx.xxx.206&amp;nbsp;1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;xxx&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;xxx&lt;/SPAN&gt;&lt;SPAN&gt;.100&lt;/SPAN&gt;&lt;SPAN&gt;.1 =&amp;gt; Gateway of&amp;nbsp;first RIPE Block&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;xxx&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;xxx&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;xxx&lt;/SPAN&gt;&lt;SPAN&gt;.200 =&amp;gt; Network of second RIPE Block&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;xxx.xxx.xxx.206 =&amp;gt;&amp;nbsp;Gateway of second RIPE Block&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise, I have to get a new and bigger RIPE Block and exchange all the public IP of our current servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/3766310#M347927</guid>
      <dc:creator>patrickheinzelmann</dc:creator>
      <dc:date>2018-12-19T00:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: How can I utilize multiple internet IP addresses on an ASA inter</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/3766319#M347929</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I forgot to mention that we're using a OVH VRack.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.ovh.com/gb/en/dedicated/ip-block-vrack/" target="_blank"&gt;https://docs.ovh.com/gb/en/dedicated/ip-block-vrack/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 01:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-utilize-multiple-internet-ip-addresses-on-an-asa/m-p/3766319#M347929</guid>
      <dc:creator>patrickheinzelmann</dc:creator>
      <dc:date>2018-12-19T01:11:15Z</dc:date>
    </item>
  </channel>
</rss>

