<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Twice NAT vs Network Object NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274197#M349587</link>
    <description>&lt;P&gt;I have a firewall where there is an object in the dmz that needs to be translated to the outside and inside using the same ip address.&amp;nbsp; I have noticed in the configuration that this is being done as a twice NAT and a network object NAT but I know the Twice NAT will take precedence.&amp;nbsp; For instance I have found the following configuration entries on the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_10.10.10.70&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 10.10.11.70&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_76.77.200.110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) source static obj_10.10.10.70 obj_76.77.200.110&lt;/P&gt;&lt;P&gt;nat (dmz,inside) source static obj_10.10.10.70 obj_76.77.200.110 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_10.10.10.70&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (dmz,any) static 76.77.146.81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which way is the better practice to accomplish translating the object to the same ip on the outside and the inside?&amp;nbsp; Should you keep the Twice NAT or the Object NAT?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:46:19 GMT</pubDate>
    <dc:creator>Mitchell Theriot</dc:creator>
    <dc:date>2019-03-12T01:46:19Z</dc:date>
    <item>
      <title>Twice NAT vs Network Object NAT</title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274197#M349587</link>
      <description>&lt;P&gt;I have a firewall where there is an object in the dmz that needs to be translated to the outside and inside using the same ip address.&amp;nbsp; I have noticed in the configuration that this is being done as a twice NAT and a network object NAT but I know the Twice NAT will take precedence.&amp;nbsp; For instance I have found the following configuration entries on the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_10.10.10.70&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 10.10.11.70&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_76.77.200.110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) source static obj_10.10.10.70 obj_76.77.200.110&lt;/P&gt;&lt;P&gt;nat (dmz,inside) source static obj_10.10.10.70 obj_76.77.200.110 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_10.10.10.70&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (dmz,any) static 76.77.146.81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which way is the better practice to accomplish translating the object to the same ip on the outside and the inside?&amp;nbsp; Should you keep the Twice NAT or the Object NAT?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274197#M349587</guid>
      <dc:creator>Mitchell Theriot</dc:creator>
      <dc:date>2019-03-12T01:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Twice NAT vs Network Object NAT</title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274198#M349588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to use either of the NAT Rule types to achieve this. What the above is essentially doing is Static NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally prefer to do the Static NAT and Static PAT always with Network Object NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I want to override the Static NAT&amp;nbsp; (Network Object NAT) for example then I use some Twice NAT configuration. Consider for example a NAT0 / NAT Exempt type Twice NAT configuration that tells specifically when the NAT should be applied. In those cases the "destination static" is added to the end of the "nat" command to tell the remote network. So for that "destination" network(s) the Twice NAT would override the Network Object NAT but otherwise the Network Object NAT would apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice also that the Twice NAT can be overriden by Network Object NAT. Though this can ONLY happen when you use "after-auto" after the "()" in the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would personally suggest using Network Object NAT for Static NAT configurations BUT Twice NAT is also an ok solution. In that case you have to manage the NAT ordering though. This is because for example when you have Static NAT and NAT0 configured with Twice NAT then there is a possibility that the Static NAT will override the NAT0 if the ordering is incorrect. I find it more clear when I know that Static NAT/PAT is always as Network Object NAT and NAT0/Policy type NAT configurations are Twice NAT. (Default Dynamic PAT/NAT I typically configure with Twice NAT with the added "after-auto" parameter which moves the rules at the very end of the NAT rules after Network Object NAT)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wrote a document on the forums about the new NAT format if you want to take a look. It probably clarifies the different NAT Rule types and the ordering done by the ASA than I can do in this post &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-31116" rel="nofollow"&gt;https://supportforums.cisco.com/docs/DOC-31116&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 May 2013 16:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274198#M349588</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-20T16:40:28Z</dc:date>
    </item>
    <item>
      <title>Twice NAT vs Network Object NAT</title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274199#M349589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks that does help with mapping to the same ip to multiple interfaces.&amp;nbsp; What if you you mapped two objects to the same ip based on the service?&amp;nbsp; Would Twice NAT or network object NAT be used?&amp;nbsp; For example lets say you have two hosts 10.10.10.5 and 10.10.10.10 in the dmz. You want to map both to the outside IP of 76.77.200.40 but specify which service to use.&amp;nbsp; For example if it is http use to 10.10.10.5 and if smtp use to 10.10.10.10.&amp;nbsp; Would the best way be to created the two following object nats or use a twice nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_10.10.10.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (dmz,outside) static 76.77.200.40 service tcp http http&lt;/P&gt;&lt;P&gt;object network obj_10.10.10.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (dmz,outside) static 76.77.200.40 service tcp smtp smtp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 May 2013 16:52:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274199#M349589</guid>
      <dc:creator>Mitchell Theriot</dc:creator>
      <dc:date>2013-05-20T16:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Twice NAT vs Network Object NAT</title>
      <link>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274200#M349590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would use Network Object NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though again I have to state that nothing is stopping you from using the Twice NAT format. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; That is what I mostly see Cisco people on these forums suggesting but I personally prefer Network Object NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT configuration format using Twice NAT would be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network WEB-SERVER&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network MAIL-SERVER&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service HTTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source eq 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service SMTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source eq 25&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz,outside) source static WEB-SERVER interface service HTTP HTTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz,outside) source static SMTP-SERVER interface service SMTP SMTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above uses the "outside" interface IP address. If you wanted to use a separate IP address you could use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network WEB-SERVER&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network MAIL-SERVER&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service HTTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source eq 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service SMTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source eq 25&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PUBLIC-IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 76.77.200.40&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz,outside) source static WEB-SERVER PUBLIC-IP service HTTP HTTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz,outside) source static SMTP-SERVER PUBLIC-IP service SMTP SMTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say you configure the Twice NAT format. Then in the near future you have to configure NAT0 for some L2L VPN connecting a remote site to your head office. If you were to configure the NAT0 configuration using Twice NAT without taking into account the ordering of Twice NAT rules (didnt use the line number) then you would find that SMTP and HTTP traffic to the remote site wouldnt work while other traffic would. In this case when we use Static PAT (Port Forward) we can naturally see that it wouldnt cause as much problem as Static NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My personal split (mentioned in the document) of NAT Type is the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Twice NAT without "after-auto" (First NAT configurations to be matched) &lt;UL&gt;&lt;LI&gt;NAT0&lt;/LI&gt;&lt;LI&gt;Policy NAT configurations&lt;/LI&gt;&lt;LI&gt;Other special NAT configurations&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Network Object NAT &lt;UL&gt;&lt;LI&gt;Static NAT&lt;/LI&gt;&lt;LI&gt;Static PAT&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Twice NAT with "after-auto" (Last NAT configurations to be matched, only difference is the "after-auto parameter) &lt;UL&gt;&lt;LI&gt;Default Dynamic PAT and NAT rules for local networks.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to mark any reply as correct answer if it answered your question. And/or rate helpfull posts &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally ask more if needed or if you wish me to clarify something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 May 2013 17:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/twice-nat-vs-network-object-nat/m-p/2274200#M349590</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-20T17:04:14Z</dc:date>
    </item>
  </channel>
</rss>

