<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT syntax - upgrading to 8.3+ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-syntax-upgrading-to-8-3/m-p/2186822#M360847</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you will need multiple NAT configurations to get these to work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You didnt list all the configurations needed to determine the complete configuration. I will list details under each section&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1.)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;We dont know behind which interface the destination networks are located....I will presume "External"&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First 4 ACL rules&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network SOURCE-NETWORKS&lt;/P&gt;&lt;P&gt; network-object 172.10.35.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.36.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.37.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.38.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network REMOTE-NETWORKS&lt;/P&gt;&lt;P&gt; network-object 172.10.18.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Internal,External) source static SOURCE-NETWORKS SOURCE-NETWORKS destination static REMOTE-NETWORKS REMOTE-NETWORKS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2 Bottom rules&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group REMOTE-NETWORKS-2&lt;/P&gt;&lt;P&gt; network-object 172.10.60.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.61.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Internal,External) source static any any destination static REMOTE-NETWORKS-2 REMOTE-NETWORKS-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;We dont know towards which interfaces networks this NAT is supposed to be done. I presume "Internal"&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network NETWORK-172.10.0.0-12&lt;/P&gt;&lt;P&gt; subnet 172.10.0.0 255.240.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network NETWORK-10.255.254-0-23&lt;/P&gt;&lt;P&gt; subnet 10.255.254.0 255.255.254.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (External,Internal) source static NETWORK-10.255.254.0-23 NETWORK-10.255.254.0-23 destination static NETWORK-172.10.0.0-12 NETWORK-172.10.0.0-12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3.)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;You provided only the source address configuration. We dont know if this is Dynamic NAT or Dynamic PAT&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Below is a Dynamic PAT using interface "External" IP address&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network PAT-SOURCE-ADDRESS&lt;/P&gt;&lt;P&gt; network-object 10.255.255.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Internal,External) after-auto source dynamic PAT-SOURCE-ADDRESS interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please rate the answer if the information was helpfull. Also if this answered your question please mark the question as answered. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ask more if needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT: Edited the "outside" to "External"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Mar 2013 21:07:40 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-03-04T21:07:40Z</dc:date>
    <item>
      <title>NAT syntax - upgrading to 8.3+</title>
      <link>https://community.cisco.com/t5/network-security/nat-syntax-upgrading-to-8-3/m-p/2186821#M360846</link>
      <description>&lt;P&gt;Looking at the changes in NAT syntax after the upgrade.... how would I do the following in 8.3+?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;access-list Encrypt extended permit ip 172.10.35.0 255.255.255.0 172.10.18.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Encrypt extended permit ip 172.10.36.0 255.255.255.0 172.10.18.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Encrypt extended permit ip 172.10.37.0 255.255.255.0 172.10.18.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Encrypt extended permit ip 172.10.38.0 255.255.255.0 172.10.18.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Encrypt extended permit ip any 172.10.60.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Encrypt extended permit ip any 172.10.61.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;nat (Internal) 0 access-list Encrypt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;access-list External_nat0_outbound extended permit ip 10.255.255.0 255.255.255.0 172.10.0.0 255.240.0.0 &lt;/P&gt;&lt;P&gt;access-list External_nat0_outbound extended permit ip 10.255.254.0 255.255.254.0 172.10.0.0 255.240.0.0 &lt;/P&gt;&lt;P&gt;nat (External) 0 access-list External_nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)&lt;/P&gt;&lt;P&gt;nat (Internal) 1 10.255.255.0 255.255.255.0&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-syntax-upgrading-to-8-3/m-p/2186821#M360846</guid>
      <dc:creator>aelsbernd</dc:creator>
      <dc:date>2019-03-12T01:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT syntax - upgrading to 8.3+</title>
      <link>https://community.cisco.com/t5/network-security/nat-syntax-upgrading-to-8-3/m-p/2186822#M360847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you will need multiple NAT configurations to get these to work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You didnt list all the configurations needed to determine the complete configuration. I will list details under each section&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1.)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;We dont know behind which interface the destination networks are located....I will presume "External"&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First 4 ACL rules&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network SOURCE-NETWORKS&lt;/P&gt;&lt;P&gt; network-object 172.10.35.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.36.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.37.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.38.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network REMOTE-NETWORKS&lt;/P&gt;&lt;P&gt; network-object 172.10.18.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Internal,External) source static SOURCE-NETWORKS SOURCE-NETWORKS destination static REMOTE-NETWORKS REMOTE-NETWORKS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2 Bottom rules&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group REMOTE-NETWORKS-2&lt;/P&gt;&lt;P&gt; network-object 172.10.60.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.10.61.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Internal,External) source static any any destination static REMOTE-NETWORKS-2 REMOTE-NETWORKS-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;We dont know towards which interfaces networks this NAT is supposed to be done. I presume "Internal"&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network NETWORK-172.10.0.0-12&lt;/P&gt;&lt;P&gt; subnet 172.10.0.0 255.240.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network NETWORK-10.255.254-0-23&lt;/P&gt;&lt;P&gt; subnet 10.255.254.0 255.255.254.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (External,Internal) source static NETWORK-10.255.254.0-23 NETWORK-10.255.254.0-23 destination static NETWORK-172.10.0.0-12 NETWORK-172.10.0.0-12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3.)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;You provided only the source address configuration. We dont know if this is Dynamic NAT or Dynamic PAT&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Below is a Dynamic PAT using interface "External" IP address&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network PAT-SOURCE-ADDRESS&lt;/P&gt;&lt;P&gt; network-object 10.255.255.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Internal,External) after-auto source dynamic PAT-SOURCE-ADDRESS interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please rate the answer if the information was helpfull. Also if this answered your question please mark the question as answered. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ask more if needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT: Edited the "outside" to "External"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 21:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-syntax-upgrading-to-8-3/m-p/2186822#M360847</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-04T21:07:40Z</dc:date>
    </item>
  </channel>
</rss>

