<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 8.6 nat and access list for mail server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037514#M396351</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please modify the acl as follows and let me know the result&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host 192.168.240.130 eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Harish&lt;/P&gt;&lt;P&gt;Please rate all helpful posts!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Oct 2012 17:05:04 GMT</pubDate>
    <dc:creator>Harish Balakrishnan</dc:creator>
    <dc:date>2012-10-31T17:05:04Z</dc:date>
    <item>
      <title>ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037513#M396349</link>
      <description>&lt;P&gt;Trying to figure this all out. I'm getting untranslated hits. I posted the config I have so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.1.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.240.253 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host 10.1.1.4 eq smtp&lt;/P&gt;&lt;P&gt;access-group incoming in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network smtp-inside&lt;/P&gt;&lt;P&gt;host 192.168.240.130&lt;/P&gt;&lt;P&gt;nat (inside,outside) static smtp-outside service tcp smtp smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object group smtp-outside&lt;/P&gt;&lt;P&gt;host 10.1.1.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SHOW ACCESS-LIST INCOMING&lt;/P&gt;&lt;P&gt;access-list incoming line 1 extended permit tcp any host 10.1.1.4 eq smtp (hitcnt=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SHOW NAT&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;/P&gt;&lt;P&gt;1 (inside) to (outside) source static smtp-inside smtp-outside&amp;nbsp;&amp;nbsp; service tcp smtp smtp &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PING 192.168.240.130&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 192.168.240.130, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037513#M396349</guid>
      <dc:creator>dave love</dc:creator>
      <dc:date>2019-03-12T00:16:54Z</dc:date>
    </item>
    <item>
      <title>ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037514#M396351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please modify the acl as follows and let me know the result&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host 192.168.240.130 eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Harish&lt;/P&gt;&lt;P&gt;Please rate all helpful posts!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 17:05:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037514#M396351</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-10-31T17:05:04Z</dc:date>
    </item>
    <item>
      <title>ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037515#M396354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to hit the mail server from the outside in this is the inside host.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 14:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037515#M396354</guid>
      <dc:creator>dave love</dc:creator>
      <dc:date>2012-11-01T14:12:37Z</dc:date>
    </item>
    <item>
      <title>ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037516#M396360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Harish said you need to point the private IP, since 8.3 the ACL setup changed ( This means NAT goes first than the ACL check, that is why you must point the private ip address)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So do it like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host 192.168.240.130 eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 18:44:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037516#M396360</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-01T18:44:02Z</dc:date>
    </item>
    <item>
      <title>ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037517#M396362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks that worked. But now how do I make multiple port numbers for the same host? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It only allows one to one this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV align="left"&gt;&lt;SPAN style="color: #1c3387;"&gt;object network smtp-inside&lt;BR /&gt; host 192.168.240.130&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P align="left"&gt;nat (inside,outside) static smtp-outside service tcp smtp smtp &lt;/P&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;I need to say http, https, smtp all to the same host.&lt;/P&gt;&lt;DIV style="color: #000000; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-left; text-transform: none; white-space: normal; widows: 2; font-size: medium;"&gt;&lt;SPAN style="color: #1c3387;"&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 17:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037517#M396362</guid>
      <dc:creator>dave love</dc:creator>
      <dc:date>2012-11-06T17:50:49Z</dc:date>
    </item>
    <item>
      <title>ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037518#M396363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;well just do the same thing but change the services, and on the ACL make reference to the new services,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts and if you do not have any other question please mark it as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 18:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037518#M396363</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-06T18:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037519#M396366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SO I don't use static tcp statements anymore. I just make separate object networks then assign them the port numbers via access lists. Do all the nat statements now need to be binded to the object groups? before I just made static statements now it seems I need to go into the object network and place the nat statement in there each time.I'm not sure I understand what nat statements mean outside of the object networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example that is working:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV align="left" style="color: #000000; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-transform: none; white-space: normal; widows: 2; font-size: medium;"&gt;&lt;SPAN style="color: #1c3387;"&gt;object network smtp-outside&lt;/SPAN&gt;&lt;P align="left" style="color: #000000; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-transform: none; white-space: normal; widows: 2; font-size: medium;"&gt;host 10.1.1.4&lt;/P&gt;&lt;DIV&gt;&lt;SPAN style="color: #1c3387;"&gt; &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network smtp-inside&lt;BR style="color: #1c3387;" /&gt;host 192.168.240.130&lt;/P&gt;&lt;P&gt;nat (inside,outside) static smtp-outside&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming extended permit tcp any object smtp-inside eq smtp&lt;/P&gt;&lt;P&gt;access-list incoming extended permit tcp any object smtp-inside eq 2500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 14:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037519#M396366</guid>
      <dc:creator>dave love</dc:creator>
      <dc:date>2012-11-07T14:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.6 nat and access list for mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037520#M396368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside an object group there can only be a nat command, so you will need to create different object networks containing the same IP or use Twice Nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have those 2 options, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that I could help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 17:34:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-6-nat-and-access-list-for-mail-server/m-p/2037520#M396368</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-07T17:34:35Z</dc:date>
    </item>
  </channel>
</rss>

