<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT between two interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107130#M393282</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your feedbacks. I setup a new transfer network and placed all management interfaces behind the transfer network into a new management network. Before I access the network I do NAT. So I can access the ASAs and other devices.&lt;/P&gt;&lt;P&gt;Thanks for help.&lt;BR /&gt;Brgds,&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jan 2013 12:58:54 GMT</pubDate>
    <dc:creator>MaDe</dc:creator>
    <dc:date>2013-01-10T12:58:54Z</dc:date>
    <item>
      <title>NAT between two interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107125#M393277</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would ask if it is possible to do NAT between two Interfaces on the same device?&lt;BR /&gt;The problem is that I need access from my inside lan to the management interface on the ASA. We will not manage the ASA over the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my current NAT statement:&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;nat (inside,mgmt) source static 172.20.200.0-24 192.168.3.222 destination static 192.168.3.0-24 192.168.3.0-24 unidirectional&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my PacketTracer output:&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Phase: 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Type: ROUTE-LOOKUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Subtype: input&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;in&amp;nbsp;&amp;nbsp; 192.168.3.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp; mgmt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Phase: 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Type: ACCESS-LIST&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Subtype: log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;access-group inside in interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;access-list inside extended permit ip 172.20.200.0 255.255.255.0 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Phase: 3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Type: IP-OPTIONS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Subtype:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Phase: 4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Type: NAT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Subtype:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;nat (inside,mgmt) source static 172.20.200.0-24 192.168.3.222 destination static 192.168.3.0-24 192.168.3.0-24 unidirectional&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Static translate 172.20.200.1/0 to 192.168.3.222/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;&lt;STRONG&gt;Phase: 5&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Type: USER-STATISTICS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Subtype: user-statistics&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;&lt;STRONG&gt;Phase: 6&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Type: FLOW-CREATION&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Subtype:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Result: ALLOW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Additional Information:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;New flow created with id 244039047, packet dispatched to next module&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 8pt;"&gt;&lt;STRONG&gt;Result:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;input-interface: inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;input-status: up&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;input-line-status: up&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;output-interface: mgmt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;output-status: up&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;output-line-status: up&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: arial, helvetica, sans-serif;"&gt;Action: allow&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So NAT seems to be working correct. I can reach other devices behind the mgmt network this is no problem. But I cant access the ASA on the mgmt interface 192.168.3.2. &lt;BR /&gt;Clould it be a problem with the traffic flow? Because in the PacketTracer output I see on Phase1 a Route-Lookup and later on Phase4 the NAT statement. &lt;/P&gt;&lt;P&gt;Is there a way to get this working?&lt;BR /&gt;Many thanks for your feedback.&lt;BR /&gt;Brgds,&lt;/P&gt;&lt;P&gt;Markus &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107125#M393277</guid>
      <dc:creator>MaDe</dc:creator>
      <dc:date>2019-03-12T00:44:23Z</dc:date>
    </item>
    <item>
      <title>NAT between two interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107126#M393278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding its not possible to connect to an ASA interface through interface other than the interface where the IP address is located.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words you are not able to connect from behind "inside" to the IP address of "mgmt" interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to find you a link to some Cisco documentation stating this. (I have never really had to find it though)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 10:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107126#M393278</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-08T10:26:16Z</dc:date>
    </item>
    <item>
      <title>NAT between two interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107127#M393279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to allow access to it. As you need to state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 192.168.3.0 255.255.255.0 mgnt &amp;lt;-- on what interface its not a nat problem just an managment access issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 13:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107127#M393279</guid>
      <dc:creator>danielciscoswart</dc:creator>
      <dc:date>2013-01-08T13:14:55Z</dc:date>
    </item>
    <item>
      <title>NAT between two interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107128#M393280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried to lab this on a test firewall and with the same type of configuration it didnt work for me atleast.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean connecting from a network behind one interface to another interfaces IP address for firewall management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 13:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107128#M393280</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-08T13:33:14Z</dc:date>
    </item>
    <item>
      <title>NAT between two interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107129#M393281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thats correct is you are on say the inside subnet then you would need to connect to the firewall on the interface facing the inside. If you want to connect to the managment interface you need to connect onto the managment subnetwork and then connect to the management facing interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cant connect to the management interface from the inside network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 13:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107129#M393281</guid>
      <dc:creator>danielciscoswart</dc:creator>
      <dc:date>2013-01-08T13:37:51Z</dc:date>
    </item>
    <item>
      <title>NAT between two interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107130#M393282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your feedbacks. I setup a new transfer network and placed all management interfaces behind the transfer network into a new management network. Before I access the network I do NAT. So I can access the ASAs and other devices.&lt;/P&gt;&lt;P&gt;Thanks for help.&lt;BR /&gt;Brgds,&lt;/P&gt;&lt;P&gt;Markus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2013 12:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-between-two-interfaces/m-p/2107130#M393282</guid>
      <dc:creator>MaDe</dc:creator>
      <dc:date>2013-01-10T12:58:54Z</dc:date>
    </item>
  </channel>
</rss>

