<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT configuration issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139566#M358805</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, thanks for the quick replies!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what is happening:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I take the NAT out, I can ping the host from an upstream router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I put it back in and try to ping the host at its natted address, I don't get any reply, although I see an entry in the ACL and if I do a show xlate interface &lt;INTERFACE&gt; I see the mapping.&lt;/INTERFACE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT statement is set up like this (see info above)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (VLAN200,VLAN100) 172.25.100.100 172.29.87.133 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure why it isn't working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Apr 2013 20:53:07 GMT</pubDate>
    <dc:creator>Colin Higgins</dc:creator>
    <dc:date>2013-04-05T20:53:07Z</dc:date>
    <item>
      <title>NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139563#M358802</link>
      <description>&lt;P&gt;Is it possible to NAT an address within a subnet that does not have a corresponding interface (or loopback) on the device that is performing that NAT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to NAT an address of a machine within a firewalled vlan on my FWSM like so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upstream router----------FWSM Vlan100--------FWSM Vlan200&lt;/P&gt;&lt;P&gt;172.29.89.35-------------&amp;gt;172.29.89.36----------&amp;gt;172.29.87.133&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to present 172.29.87.133 as 172.25.100.100 to traffic coming in from the upstream router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This network 172.25.100.x does not exist anywhere on the FWSM, but the router routes to it through 172.29.89.36&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I do this?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:24:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139563#M358802</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-12T01:24:19Z</dc:date>
    </item>
    <item>
      <title>NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139564#M358803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if I understood you correctly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean that the following is true&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Theres a network 172.29.89.x/yy between the Upstream Router and the FWSM Vlan100 interface connected to it&lt;/LI&gt;&lt;LI&gt;You have a network 172.29.87.x/yy on the FWSM connected to Vlan200&lt;/LI&gt;&lt;LI&gt;You have a route telling that a network 172.25.100.x/yy is found through the FWSM Vlan100 (172.29.89.36)&lt;/LI&gt;&lt;LI&gt;You want to NAT the host 172.29.87.133 located on Vlan200 to the IP address 172.25.100.100 when its crossing the FWSM towards the Upstream Router&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is correct then I dont see any problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to configure the the NAT just fine. Since the Upstream router has a route for that NAT address pointing towards the FWSM then all should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 20:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139564#M358803</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-05T20:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139565#M358804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can do that. Ofcourse that will depend of Proxy-ARP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if you do not have a route you could do it with proxy-arp, without Proxy ARP then you must enter a route on the upstream router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as it's supported you can play with that &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 20:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139565#M358804</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T20:42:17Z</dc:date>
    </item>
    <item>
      <title>NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139566#M358805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, thanks for the quick replies!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what is happening:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I take the NAT out, I can ping the host from an upstream router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I put it back in and try to ping the host at its natted address, I don't get any reply, although I see an entry in the ACL and if I do a show xlate interface &lt;INTERFACE&gt; I see the mapping.&lt;/INTERFACE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT statement is set up like this (see info above)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (VLAN200,VLAN100) 172.25.100.100 172.29.87.133 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure why it isn't working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 20:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139566#M358805</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2013-04-05T20:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139567#M358806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have the route, NAT and ACL rules configured I cant think of many reasons for this to not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a lot of other NAT configurations on the FWSM and could you share them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139567#M358806</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-05T21:03:08Z</dc:date>
    </item>
    <item>
      <title>NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139568#M358807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first question would be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a route to the Unnused IP adtdress on the upstream router?&lt;/P&gt;&lt;P&gt;Remember, the route it's not required BUT you have to be sure that the router learn the MAC address of this host via the interface connecting to the FWSM ( via Proxy-arp)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could even do a static map but the easiest way to go is to create the route as Jouni suggested&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139568#M358807</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T21:12:51Z</dc:date>
    </item>
    <item>
      <title>NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139569#M358810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, figured it out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does indeed work: I had to clear the ARP entry AND the xlate entry on the interface for the host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The FWSM had a bad entry--once those were cleared, the host responded to the natted address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks guys&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Apr 2013 01:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139569#M358810</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2013-04-06T01:05:02Z</dc:date>
    </item>
    <item>
      <title>NAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139570#M358813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear that everything is working for you &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Apr 2013 01:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-issue/m-p/2139570#M358813</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-06T01:07:06Z</dc:date>
    </item>
  </channel>
</rss>

