<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create a nat from outside to inside and using services in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135400#M395232</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Eduardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to translate an inside user to an outside ip using services or do you want to translate a specific outside user on an specific port to an inside ip on a specific service??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I was clear &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Nov 2012 00:46:06 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-11-23T00:46:06Z</dc:date>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135399#M395228</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how to create a static nat from outside to inside and using services, this is a firewall 5545x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135399#M395228</guid>
      <dc:creator>Julio E. Moisa</dc:creator>
      <dc:date>2019-03-12T00:26:52Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135400#M395232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Eduardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to translate an inside user to an outside ip using services or do you want to translate a specific outside user on an specific port to an inside ip on a specific service??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I was clear &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2012 00:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135400#M395232</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-23T00:46:06Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135401#M395235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JCarvaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response, actually i would like to translate an outside public IP to a specific inside ip address and using a X port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was very easy on the previous IOS 8.2 but currently Im working with IOS 8.6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 03:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135401#M395235</guid>
      <dc:creator>Julio E. Moisa</dc:creator>
      <dc:date>2012-11-26T03:30:39Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135402#M395238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can you paste your NAT configuration? I understand that you want to translate - private ip to public ip (static nat).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example your private ip is - 10.10.10.10 and public ip is: 100.100.100.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then try this:&lt;/P&gt;&lt;P&gt;static (inside,outside) 100.100.100.100 10.10.10.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it will help you..!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Siraj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 06:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135402#M395238</guid>
      <dc:creator>Sirajhussain</dc:creator>
      <dc:date>2012-11-26T06:15:43Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135403#M395241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Eduardomoi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are some basic configurations you need to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here in the example a public ip 117.1.1.1 is natted to private ip 192.168.5.6 wih some services&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Natting the public ip with private ip&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) &lt;STRONG&gt;117.1.1.1&lt;/STRONG&gt; 192.168.5.6 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;U need to understand which ports u need to allow, are they TCP or UDP or both?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here in the below example both TCP and UDP are allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create an object group for TCP and UDP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Allow the service as per the requirement with the help of access lists and note that source can be any u can modify as per the requirement of urs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the below example &lt;STRONG&gt;port ranges in between 12000 and 29999 are allowed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out extended permit object-group TCPUDP any host 117.1.1.1 range 12000 29999 &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; port ranges in between 8000 and 9000&amp;nbsp; are allowed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out extended permit object-group TCPUDP any host 117.1.1.1 range 8000 9000 &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;port for specific service called sip is allowed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out extended permit udp any host 117.1.1.1 eq sip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;port for specific service called sip with port number 5060 is allowed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;access-list acl_out extended permit udp any host 117.1.1.1 eq 5060&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please dont forget to rate the helpful posts and if u feel the answer is correct please do the query answered. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;BR /&gt;Thanveer &lt;BR /&gt;"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 06:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135403#M395241</guid>
      <dc:creator>Muhammad Thanveer</dc:creator>
      <dc:date>2012-11-26T06:58:47Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135404#M395243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to add since it is 5545-x which works on 8.6 and 9.x&amp;nbsp; IOS so nat commands are different on this , below is what can help you:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network 10.0.0.10 (external ip)&lt;/P&gt;&lt;P&gt;host 10.0.0.10&lt;/P&gt;&lt;P&gt;object network 192.168.25.10 (internal ip)&lt;/P&gt;&lt;P&gt;host 192.168.25.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside,inside) source static 10.0.0.10 10.0.0.10 destination static 192.168.25.10 192.168.25.10 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 11:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135404#M395243</guid>
      <dc:creator>Riyasat Ali</dc:creator>
      <dc:date>2012-11-26T11:06:54Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135405#M395247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Riyasat Ali,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your prompt response, actually my conf is like the following but currently is not working the static nat from outside to inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,provider1) source dynamic INSIDEGROUP interface&lt;/P&gt;&lt;P&gt;nat (inside,provider2) source dynamic INSIDEGROUP interface&lt;/P&gt;&lt;P&gt;nat (provider1,inside) source static 10.0.0.10 10.0.0.10 destination static 192.168.25.10 192.168.25.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran the sh nat command but there are no hits for it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 14:10:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135405#M395247</guid>
      <dc:creator>Julio E. Moisa</dc:creator>
      <dc:date>2012-11-26T14:10:39Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135406#M395253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do u see any hit count on outside access-list for this traffic( as you need access-list since traffic is initiating from outside zone)&amp;nbsp; , if not , then provide me the access list what u have , source ip from whr u initiating the traffic , destination ip and translated ip .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and also try to change the sequence of this nat as following :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (provider1,inside)&amp;nbsp; 1 source static 10.0.0.10 10.0.0.10 destination static 192.168.25.10 192.168.25.10&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 14:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135406#M395253</guid>
      <dc:creator>Riyasat Ali</dc:creator>
      <dc:date>2012-11-26T14:19:39Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135407#M395258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, the ACL is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit ip any host 10.0.0.10&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 17:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135407#M395258</guid>
      <dc:creator>Julio E. Moisa</dc:creator>
      <dc:date>2012-11-26T17:08:35Z</dc:date>
    </item>
    <item>
      <title>How to create a nat from outside to inside and using services</title>
      <link>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135408#M395263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed the sequence and it is not working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 07:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-create-a-nat-from-outside-to-inside-and-using-services/m-p/2135408#M395263</guid>
      <dc:creator>Julio E. Moisa</dc:creator>
      <dc:date>2012-11-27T07:07:03Z</dc:date>
    </item>
  </channel>
</rss>

