<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT question/solution request in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-question-solution-request/m-p/2122265#M394474</link>
    <description>&lt;P&gt;Hi.&amp;nbsp; I have the following scenario and not sure how to build a NAT for it.&amp;nbsp; Using OS 8.3(2)&amp;nbsp; ASA 5510 secplus lic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a device on Outside interface that ONLY can talk to devices on its own broadcast domain, but I have a device on the Inside interface that must be able to talk to this device on the Outside interface.&amp;nbsp; I'm thinking I can set up a NAT for this device on the Inside interface to appear to be on the Outside interface.&amp;nbsp; Networks and hosts below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;nameif Inside (routed interface connecting to the trusted side networks)&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.21.250.92 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;nameif outside (layer 2 network with the "outside" interface being the gateway)&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 192.14.225.1 255.255.255.128&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;host 192.14.225.121 (device that can only talk on its own broadcast domain - can't set a default gateway on it)&lt;/P&gt;&lt;P&gt;host 192.51.14.38 (device that 192.14.225.121 needs to be able to talk to, that's coming from the Inside interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I have the 192.51.14.38 appear to be 192.14.225.5, so that 192.14.225.121 can talk to it?&amp;nbsp; Any other ideas or configurations for a solution would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:34:38 GMT</pubDate>
    <dc:creator>aaronkite</dc:creator>
    <dc:date>2019-03-12T00:34:38Z</dc:date>
    <item>
      <title>NAT question/solution request</title>
      <link>https://community.cisco.com/t5/network-security/nat-question-solution-request/m-p/2122265#M394474</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; I have the following scenario and not sure how to build a NAT for it.&amp;nbsp; Using OS 8.3(2)&amp;nbsp; ASA 5510 secplus lic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a device on Outside interface that ONLY can talk to devices on its own broadcast domain, but I have a device on the Inside interface that must be able to talk to this device on the Outside interface.&amp;nbsp; I'm thinking I can set up a NAT for this device on the Inside interface to appear to be on the Outside interface.&amp;nbsp; Networks and hosts below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;nameif Inside (routed interface connecting to the trusted side networks)&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.21.250.92 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;nameif outside (layer 2 network with the "outside" interface being the gateway)&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 192.14.225.1 255.255.255.128&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;host 192.14.225.121 (device that can only talk on its own broadcast domain - can't set a default gateway on it)&lt;/P&gt;&lt;P&gt;host 192.51.14.38 (device that 192.14.225.121 needs to be able to talk to, that's coming from the Inside interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I have the 192.51.14.38 appear to be 192.14.225.5, so that 192.14.225.121 can talk to it?&amp;nbsp; Any other ideas or configurations for a solution would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question-solution-request/m-p/2122265#M394474</guid>
      <dc:creator>aaronkite</dc:creator>
      <dc:date>2019-03-12T00:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question/solution request</title>
      <link>https://community.cisco.com/t5/network-security/nat-question-solution-request/m-p/2122266#M394475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont you already have some default PAT configuration that does translation for networks behind interface "Inside" to the interface IP address of "outside" which is directly connected as far as host 192.14.225.121 is conserned? Then again looking that both of the networks are public I guess you wouldnt really have need for a PAT configuration between Inside and outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not I guess one solution might be (object names might be better as something else &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network MAPPED-192.14.225.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.14.225.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network MAPPED-192.14.225.5-DEST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 194.14.225.121&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network MAPPED-192.14.225.5-SOURCE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.51.14.38&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (Inside,outside) source static MAPPED-192.14.225.5-SOURCE MAPPED-192.14.225.5 destination static MAPPED-192.14.225.5-DEST MAPPED-192.14.225.5-DEST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems a bit complex but should work I guess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From left to right&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Source interface&lt;/LI&gt;&lt;LI&gt;Destination interface&lt;/LI&gt;&lt;LI&gt;Static source address&lt;/LI&gt;&lt;LI&gt;Static mapped address&lt;/LI&gt;&lt;LI&gt;Static destination address twice as no change regarding its translation is done.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to my understanding this NAT should only apply for the source host 192.51.14.38 when the destination is 192.14.225.121&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2012 16:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question-solution-request/m-p/2122266#M394475</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-07T16:04:40Z</dc:date>
    </item>
    <item>
      <title>NAT question/solution request</title>
      <link>https://community.cisco.com/t5/network-security/nat-question-solution-request/m-p/2122267#M394476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Brilliant!&amp;nbsp; works perfectly thanks so much!&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2012 16:45:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question-solution-request/m-p/2122267#M394476</guid>
      <dc:creator>aaronkite</dc:creator>
      <dc:date>2012-12-07T16:45:52Z</dc:date>
    </item>
  </channel>
</rss>

