<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA - NAT to Dst - FQDN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164486#M361042</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe we use wccp, however, I'm new to ASAs, so I'm not 100% sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think we're getting beyond the realms of my original question of why you can't use a FQDN when NATting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your responses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Mar 2013 17:09:12 GMT</pubDate>
    <dc:creator>Alex Sykes</dc:creator>
    <dc:date>2013-03-01T17:09:12Z</dc:date>
    <item>
      <title>ASA - NAT to Dst - FQDN</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164482#M361038</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me why you cannot set up a NAT rule on the ASAs with the destination address being a FQDN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to allow some internal addresses to bypass our proxy to go to an external address and thought this would be the best way to do it, but the FQDN&amp;nbsp; opetion isn't there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164482#M361038</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2019-03-12T01:08:16Z</dc:date>
    </item>
    <item>
      <title>ASA - NAT to Dst - FQDN</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164483#M361039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have some device in front of the ASA controlling which traffic goes through proxy or how is the NAT going to be used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont seem you can use a "object network" with "fqdn" in NAT configurations as you say though I have never even tried before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 15:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164483#M361039</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-01T15:00:03Z</dc:date>
    </item>
    <item>
      <title>ASA - NAT to Dst - FQDN</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164484#M361040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your quick reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use a BlueCoat proxy device for all our web traffic and this is what I want to bypass which I can do if I put in an ACL and corresponding NAT rule allowing me to do so, but only for a ho&lt;SPAN style="font-size: 10pt;"&gt;st, a range of addresses of a network, but not FQDN. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I was curious as to why the FQDN option isn't there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;We have nothing in front of the ASA controlling which traffic goes through the proxy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 16:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164484#M361040</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2013-03-01T16:37:44Z</dc:date>
    </item>
    <item>
      <title>ASA - NAT to Dst - FQDN</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164485#M361041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are we talking about a configuration where the ASA has a "wccp" configuration that determines which traffic is handled with the Bluecoat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wouldnt it then be possible to evade the host and its certain destination from proxy by configuring a "deny ip" statement in the "wccp" ACL used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I might have misunderstood the situation and I dont deal with that much with proxy setup while we do have a few ASA + Irontport setups where ASA uses "wccp"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 17:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164485#M361041</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-01T17:00:35Z</dc:date>
    </item>
    <item>
      <title>ASA - NAT to Dst - FQDN</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164486#M361042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe we use wccp, however, I'm new to ASAs, so I'm not 100% sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think we're getting beyond the realms of my original question of why you can't use a FQDN when NATting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your responses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 17:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164486#M361042</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2013-03-01T17:09:12Z</dc:date>
    </item>
    <item>
      <title>ASA - NAT to Dst - FQDN</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164487#M361043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Even though you can configure FQDNs inside the objects you can't use them in a nat configuration, the ASA won't let you do it, he will even tell you that it's not supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try it and confirm it. Nothing will happen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 21:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164487#M361043</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-01T21:15:06Z</dc:date>
    </item>
    <item>
      <title>Can you confirm if this is</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164488#M361044</link>
      <description>&lt;P&gt;Can you confirm if this is still the case for NAT to DST FQDN? or are there any versions of software that can do this?&lt;/P&gt;
&lt;P&gt;or Did you find a workaround?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 13:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/2164488#M361044</guid>
      <dc:creator>nstewart</dc:creator>
      <dc:date>2017-07-20T13:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can you confirm if this is</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/3719668#M361045</link>
      <description>&lt;P&gt;ASA still does not support to NAT based on FQDN, the closest would be to configure the NAT rule and route the traffic with PBR, however, you need to keep the list of public IPs that the domain resolves to.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 23:59:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/3719668#M361045</guid>
      <dc:creator>ripicado</dc:creator>
      <dc:date>2018-10-04T23:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can you confirm if this feature is supported in Cisco Firepower Firewalls?</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/3765855#M361048</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please confirm if the feature of&amp;nbsp;&amp;nbsp;NAT to dynamic IPs or NAT to FQDN is supported in Cisco Firepower Firewalls. If not, then please suggest workaround for the same.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 14:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/3765855#M361048</guid>
      <dc:creator>sandeeplugani</dc:creator>
      <dc:date>2018-12-18T14:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - NAT to Dst - FQDN</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/4771078#M1097603</link>
      <description>&lt;P&gt;It seems is now possible if you upgrade to 9.17+, as per&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/release/notes/asarn917.html#:~:text=Twice%20NAT%20support%20for%20fully%2Dqualified%20domain%20name%20(FQDN)%20objects%20as%20the%20translated%20(mapped)%20destination" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/release/notes/asarn917.html#:~:text=Twice%20NAT%20support%20for%20fully%2Dqualified%20domain%20name%20(FQDN)%20objects%20as%20the%20translated%20(mapped)%20destination&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 11:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-to-dst-fqdn/m-p/4771078#M1097603</guid>
      <dc:creator>gabarrio</dc:creator>
      <dc:date>2023-02-08T11:15:59Z</dc:date>
    </item>
  </channel>
</rss>

