<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static translation from dmz to inside on Asa 8.6 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087513#M393839</link>
    <description>&lt;P&gt;Recently upgraded to an Asa 5512x from a pix 515e. I have an Ipswitch secure MoveIT server on the dmz1 interface that needs to be accessed from both the inside and outside interfaces. I have setup a static nat from the outside to the dmz1 and it works, I can also connect from the inside interface. Now I need the MoveIT server to access the DNS server and email server on the inside interface so it can send notifications. On the pix I just created a static from the inside to the dmz1 using its own IP address - static (inside,dmz1) 192.168.1.7 192.168.1.7 net mask 255.255.255.255. I would then add the access-list to allow. How would I set this up with the Asa 8.6 commands?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:40:00 GMT</pubDate>
    <dc:creator>dkemptonmcs</dc:creator>
    <dc:date>2019-03-12T00:40:00Z</dc:date>
    <item>
      <title>static translation from dmz to inside on Asa 8.6</title>
      <link>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087513#M393839</link>
      <description>&lt;P&gt;Recently upgraded to an Asa 5512x from a pix 515e. I have an Ipswitch secure MoveIT server on the dmz1 interface that needs to be accessed from both the inside and outside interfaces. I have setup a static nat from the outside to the dmz1 and it works, I can also connect from the inside interface. Now I need the MoveIT server to access the DNS server and email server on the inside interface so it can send notifications. On the pix I just created a static from the inside to the dmz1 using its own IP address - static (inside,dmz1) 192.168.1.7 192.168.1.7 net mask 255.255.255.255. I would then add the access-list to allow. How would I set this up with the Asa 8.6 commands?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:40:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087513#M393839</guid>
      <dc:creator>dkemptonmcs</dc:creator>
      <dc:date>2019-03-12T00:40:00Z</dc:date>
    </item>
    <item>
      <title>static translation from dmz to inside on Asa 8.6</title>
      <link>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087514#M393840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Donald,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to have identity nat you can use the following syntax:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,dmz1) source static obj-192.168.1.7 obj-192.168.1.7 destinatination static obj-remote-net obj-remote-net&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Eugene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2012 23:29:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087514#M393840</guid>
      <dc:creator>Eugene Korneychuk</dc:creator>
      <dc:date>2012-12-21T23:29:22Z</dc:date>
    </item>
    <item>
      <title>static translation from dmz to inside on Asa 8.6</title>
      <link>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087515#M393841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a common mistake to forget adding 'route-lookup' and 'no-proxy-arp'&amp;nbsp; to such identity NAT statements. From 8.4 you can experience strange errors if you don't use them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Dec 2012 14:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087515#M393841</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2012-12-22T14:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: static translation from dmz to inside on Asa 8.6</title>
      <link>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087516#M393842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to make sure, this wouldn't interfere with another static nat I have coming in from the outside to the same internal IP address of 192.168.1.7? It looks like your using twice nat correct?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Dec 2012 15:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087516#M393842</guid>
      <dc:creator>dkemptonmcs</dc:creator>
      <dc:date>2012-12-22T15:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: static translation from dmz to inside on Asa 8.6</title>
      <link>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087517#M393843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default operation of the new ASAs/Softwares is that you dont configure NAT if you dont need one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you for example have the following interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;outside&lt;/LI&gt;&lt;LI&gt;lan1&lt;/LI&gt;&lt;LI&gt;lan2&lt;/LI&gt;&lt;LI&gt;dmz&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want the lan1, lan2 and dmz to communicate between eachother with the actual IP addresses, you dont configure any type of NAT between them (even the ones that you used to do with the old software with the "static" commands)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only situations where I have configured Twice NAT is when I have configured a L2L VPN or there is migrated some old 8.2 or below software Policy NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to my understanding you would probably have a new type of Static NAT for the dmz1 server towards outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network DMZ-STATIC&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.7&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (dmz1,outside) static x.x.x.x dns&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the same server to communicate with other networks behind the firewall (LAN networks) you shouldnt really need any addiotional NAT configurations. Only have the access-rules permit the traffic if it already doesnt do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can always post some configurations if you want someone to take a look through them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Dec 2012 17:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087517#M393843</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-22T17:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: static translation from dmz to inside on Asa 8.6</title>
      <link>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087518#M393844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, works great. A lot easier to use the new Asa. Just need to learn the syntax. Thank you.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Dec 2012 13:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-translation-from-dmz-to-inside-on-asa-8-6/m-p/2087518#M393844</guid>
      <dc:creator>dkemptonmcs</dc:creator>
      <dc:date>2012-12-23T13:47:45Z</dc:date>
    </item>
  </channel>
</rss>

