<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510-Query in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266915#M348221</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP has routed this /28 public pool towards CE ip (x.x.x.18) which is configured on outside interface. In that case my inside IPs would be PAT with x.x.x.18.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i am wondering that how static NAT would work. If i do static NAT with a /28 public pool then how it will work since this pool is not configured any where. And what would be ARP of this NAT ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need you help on this pls. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Jun 2013 10:53:54 GMT</pubDate>
    <dc:creator>Anukalp S</dc:creator>
    <dc:date>2013-06-12T10:53:54Z</dc:date>
    <item>
      <title>ASA 5510-Query</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266911#M348217</link>
      <description>&lt;P&gt;Hi..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have taken a new internet link from ISP for my new office. I am planning to terminate link directly on ASA since we want to save the cost for router.&lt;/P&gt;&lt;P&gt;I am not much aware if this set up is more secure and functional fine. Need more inputs on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i am provided with below IPs, so need help to configure this on mentioned set up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PE ip : x.x.x.17/30&lt;/P&gt;&lt;P&gt;CE ip : x.x.x.18/30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;public ip pool : y.y.y.28/28 &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266911#M348217</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-03-12T01:56:28Z</dc:date>
    </item>
    <item>
      <title>ASA 5510-Query</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266912#M348218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont see a problem with the setup. The ASA is Security device and is supposed to be located on the edge of the network. Naturally there are setup where there is even a device in front of ASA filtering traffi that can reach the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration of the &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface should be pretty basic just like any other ASA interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface Ethernet0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; description WAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nameif outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; security-level 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; ip add x.x.x.18 255.255.255.252&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no shutdown&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.17&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally you will need the basic NAT configuration and such for the whole setup to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your public IP pools network address doesnt however match the network mask of /28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you have an additional public subnet/network allocated by the ISP then you can start directly configuring NAT configuration using its IP addresses. Or perhaps even use it behind the actual ASA firewall depending on your needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on what software you are using on the ASA firewall there might be some things you need to take into consideration with this additional public subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I imagine that the ISP has routed that public subnet towards your IP address of x.x.x.18?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 10:04:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266912#M348218</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-12T10:04:04Z</dc:date>
    </item>
    <item>
      <title>ASA 5510-Query</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266913#M348219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your information, actually public ip pool mentioned above just for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you mean to say that if we go with this setup then /32 ip is not required to configure. I need to configure a ip from public pool on outside interface and then PAT it with my inside IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running 8.4(5) software.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 10:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266913#M348219</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2013-06-12T10:20:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5510-Query</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266914#M348220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if I understood you correctly here but correct if I am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A small subnet of /30 mask that is configured directly between your ASA and the ISP gateway&lt;/LI&gt;&lt;LI&gt;A small subnet of /28 mask that will be used for NAT purposes&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you just wanted to configure a Dynamic PAT for all your LAN users then you can also use the &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface IP address and not waste any public IP addresses from the actual extra public subnet you got from your ISP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you for example just had&lt;STRONG&gt; "inside"&lt;/STRONG&gt; and&lt;STRONG&gt; "outside"&lt;/STRONG&gt; interface and a network &lt;STRONG&gt;10.10.10.0/24&lt;/STRONG&gt; behind the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface then you could configure the default Dynamic PAT rule like this for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network DEFAULT-PAT-SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object 10.10.10.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) after-auto source dynamic DEFAULT-PAT-SOURCE interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am wondering about the additional public subnet of /28 mask. Has the ISP said that they have routed the network towards your public IP address that is configured on the ASA &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface? Or is that subnet also configured on their gateway device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In that case you might have to enable this command also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;arp permit-nonconnected&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will enable that you can use a subnet on the ASA for NAT when that subnet in question is not configured on any actual interface of your ASA. And to me this seems to be the case in your setup since you have been allocated 2 public subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you need this configuration depends totally how the ISP has handled the second subnet of /28 mask. If its routed towards your ASA &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface IP address then there is no problem. If they have configured that network directly on their gateway device then you will need the above command to be able to use those IP addresses in your NAT configuration and for them to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to mark the reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or ask more if needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 10:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266914#M348220</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-12T10:30:38Z</dc:date>
    </item>
    <item>
      <title>ASA 5510-Query</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266915#M348221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP has routed this /28 public pool towards CE ip (x.x.x.18) which is configured on outside interface. In that case my inside IPs would be PAT with x.x.x.18.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i am wondering that how static NAT would work. If i do static NAT with a /28 public pool then how it will work since this pool is not configured any where. And what would be ARP of this NAT ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need you help on this pls. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 10:53:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266915#M348221</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2013-06-12T10:53:54Z</dc:date>
    </item>
    <item>
      <title>ASA 5510-Query</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266916#M348222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct about the Dynamic PAT address. Its the one configured in my above reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now with regards to the second subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The good thing in your case is that the ISP has routed this network towards your ASA "outside" interface IP address. This means that when traffic is coming from the Internet towards some public IP address from the ISP gateway then the ISP gateway will simply forward the traffic to your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the ASA receives the traffic it naturally sees traffic coming towards one of its Static NAT IP addresses and everything works just fine provided the Static NAT configuration, the ACL allowing the traffic and the actual server is configured correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ARP doesnt come into play at any point here with regards to the public subnet with /28 mask. Since the ISP has a route for that network towards the ASA "outside" inteface it will NEVER ARP for the MAC address of the server. This is because ARP is only used if the device sees the subnet as directly connected. Now that the ISP has a route for the network behind some other L3 hop in the network it simply forward the traffic to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So there should be no problems related to ARP with your setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There isnt either any problem having these public IP addresses as NAT IP address on your ASAs configurations either. This is a very typical scenario and in your case should not provide any problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 11:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266916#M348222</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-12T11:02:47Z</dc:date>
    </item>
    <item>
      <title>ASA 5510-Query</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266917#M348223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jouni..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It means that second subnet is not needed to configure on any interfaces, and if is static NAT with any server then this will work fine.This was actually my concern.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 11:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-query/m-p/2266917#M348223</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2013-06-12T11:23:59Z</dc:date>
    </item>
  </channel>
</rss>

