<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 8.6 allow publishing to only one range of Public IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-6-allow-publishing-to-only-one-range-of-public-ip/m-p/2186949#M386985</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to use some other software than 8.6(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the command &lt;STRONG&gt;"arp permit-nonconnected"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow the ASA to populate its ARP table with nonconnected networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to use this command you will need another software. Check this Cisco Release Notes section and especially the bottom section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp623913table623908" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P&gt; ARP cache additions for non-connected subnets &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp623940"&gt;&lt;/A&gt;&lt;P&gt; The ASA ARP cache only contains entries from directly-connected subnets&amp;nbsp; by default. You can now enable the ARP cache to also include&amp;nbsp; non-directly-connected subnets. We do not recommend enabling this&amp;nbsp; feature unless you know the security risks. This feature could&amp;nbsp; facilitate denial of service (DoS) attack against the ASA; a user on any&amp;nbsp; interface could send out many ARP replies and overload the ASA ARP&amp;nbsp; table with false entries. &lt;/P&gt;&lt;A name="wp623948"&gt;&lt;/A&gt;&lt;P&gt; You may want to use this feature if you use: &lt;/P&gt;&lt;A name="wp623949"&gt;&lt;/A&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Secondary subnets. &lt;/P&gt;&lt;A name="wp623950"&gt;&lt;/A&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Proxy ARP on adjacent routes for traffic forwarding. &lt;/P&gt;&lt;A name="wp623951"&gt;&lt;/A&gt;&lt;P&gt; We introduced the following command: &lt;STRONG&gt;arp permit-nonconnected&lt;/STRONG&gt;. &lt;/P&gt;&lt;A name="wp623953"&gt;&lt;/A&gt;&lt;P&gt; &lt;EM&gt;This feature is not available in 8.5(1), 8.6(1), or 8.7(1).&lt;/EM&gt; &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other option is to ask the ISP to route the nonconnected network towards the ASA directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can check an explanation from a NAT 8.3+ document I created here on CSC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/docs/DOC-31116"&gt;https://supportforums.cisco.com/docs/DOC-31116#MULTIPLE-SUBNETS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to mark the question as answered if it did or ask more if needed &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Apr 2013 17:11:00 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-04-20T17:11:00Z</dc:date>
    <item>
      <title>ASA 8.6 allow publishing to only one range of Public IP</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-allow-publishing-to-only-one-range-of-public-ip/m-p/2186948#M386984</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would someone comfirm that the versions 8.6 and up don't allow publishing to more then one public range if IP addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have ASA5520 version 8.4 in deployment and there I can NAT to 3 different ranges of public IP-s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With same configuration on ASA5525-X version 8.6 it will NAT only the range that the outside interface belongs to.&lt;/P&gt;&lt;P&gt;Also tried the 9.0 version with the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-allow-publishing-to-only-one-range-of-public-ip/m-p/2186948#M386984</guid>
      <dc:creator>Lulzim Islami</dc:creator>
      <dc:date>2019-03-12T01:32:11Z</dc:date>
    </item>
    <item>
      <title>ASA 8.6 allow publishing to only one range of Public IP</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-allow-publishing-to-only-one-range-of-public-ip/m-p/2186949#M386985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to use some other software than 8.6(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the command &lt;STRONG&gt;"arp permit-nonconnected"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow the ASA to populate its ARP table with nonconnected networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to use this command you will need another software. Check this Cisco Release Notes section and especially the bottom section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp623913table623908" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P&gt; ARP cache additions for non-connected subnets &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp623940"&gt;&lt;/A&gt;&lt;P&gt; The ASA ARP cache only contains entries from directly-connected subnets&amp;nbsp; by default. You can now enable the ARP cache to also include&amp;nbsp; non-directly-connected subnets. We do not recommend enabling this&amp;nbsp; feature unless you know the security risks. This feature could&amp;nbsp; facilitate denial of service (DoS) attack against the ASA; a user on any&amp;nbsp; interface could send out many ARP replies and overload the ASA ARP&amp;nbsp; table with false entries. &lt;/P&gt;&lt;A name="wp623948"&gt;&lt;/A&gt;&lt;P&gt; You may want to use this feature if you use: &lt;/P&gt;&lt;A name="wp623949"&gt;&lt;/A&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Secondary subnets. &lt;/P&gt;&lt;A name="wp623950"&gt;&lt;/A&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Proxy ARP on adjacent routes for traffic forwarding. &lt;/P&gt;&lt;A name="wp623951"&gt;&lt;/A&gt;&lt;P&gt; We introduced the following command: &lt;STRONG&gt;arp permit-nonconnected&lt;/STRONG&gt;. &lt;/P&gt;&lt;A name="wp623953"&gt;&lt;/A&gt;&lt;P&gt; &lt;EM&gt;This feature is not available in 8.5(1), 8.6(1), or 8.7(1).&lt;/EM&gt; &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other option is to ask the ISP to route the nonconnected network towards the ASA directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can check an explanation from a NAT 8.3+ document I created here on CSC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/docs/DOC-31116"&gt;https://supportforums.cisco.com/docs/DOC-31116#MULTIPLE-SUBNETS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to mark the question as answered if it did or ask more if needed &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Apr 2013 17:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-allow-publishing-to-only-one-range-of-public-ip/m-p/2186949#M386985</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-20T17:11:00Z</dc:date>
    </item>
    <item>
      <title>ASA 8.6 allow publishing to only one range of Public IP</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-allow-publishing-to-only-one-range-of-public-ip/m-p/2186950#M386986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your clear explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Valdet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Apr 2013 13:00:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-allow-publishing-to-only-one-range-of-public-ip/m-p/2186950#M386986</guid>
      <dc:creator>Lulzim Islami</dc:creator>
      <dc:date>2013-04-21T13:00:23Z</dc:date>
    </item>
  </channel>
</rss>

