<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting up PAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031262#M398697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeas you are correct, i hope the earlier nat also port based not the ip to IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Sep 2012 13:30:40 GMT</pubDate>
    <dc:creator>Harish Balakrishnan</dc:creator>
    <dc:date>2012-09-27T13:30:40Z</dc:date>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031257#M398692</link>
      <description>&lt;P&gt;Client has a block of 5 static IP's for the ISP.&amp;nbsp; They currently have them all in use and set up with static nat (Inside,outside) commands.&amp;nbsp; They are adding a new web application and ftp server that will need to be accessed from the outside.&amp;nbsp; Is it possible to use one public&amp;nbsp; IP address and just use PAT to get to everything?&amp;nbsp; If so, how would I set that up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is a portion of the config that they have now, if I use PAT, does this all need removed and changed?&amp;nbsp; I'm really confused on how this would all work, any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.0 &lt;/P&gt;&lt;P&gt;subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.2.0 &lt;/P&gt;&lt;P&gt;subnet 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.3.0 &lt;/P&gt;&lt;P&gt;subnet 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.2 &lt;/P&gt;&lt;P&gt;host 192.168.1.2&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.7 &lt;/P&gt;&lt;P&gt;host 192.168.1.7&lt;/P&gt;&lt;P&gt;object network obj_any &lt;/P&gt;&lt;P&gt;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_192.168.2.0_24 &lt;/P&gt;&lt;P&gt;subnet 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.2&lt;/P&gt;&lt;P&gt;nat (inside,outside) static xx.xx.xx.203 dns&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.7&lt;/P&gt;&lt;P&gt;nat (inside,outside) static xx.xx.xx.201 dns&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic xx.xx.xx.204&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031257#M398692</guid>
      <dc:creator>sonitadmin</dc:creator>
      <dc:date>2019-03-12T00:00:03Z</dc:date>
    </item>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031258#M398693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sonit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; if you have one public IP free and the new app lication are in different servers ( different private IP's) you can do port based natting to allow communication from outside.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 13:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031258#M398693</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-09-27T13:18:14Z</dc:date>
    </item>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031259#M398694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Currently there are no public IP's free.&amp;nbsp; I am trying to consolidate by using PAT.&amp;nbsp; Can this be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 13:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031259#M398694</guid>
      <dc:creator>sonitadmin</dc:creator>
      <dc:date>2012-09-27T13:21:39Z</dc:date>
    </item>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031260#M398695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as that port is not in use by the internal server that is mapped with the public IP address I think it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure you use a Manual NAT so it will take precedence over the Object NAT configuration you have in place. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static &lt;PRIVATE_IP&gt;&lt;PUBLIC_IP&gt; service &lt;SERVICE&gt; &lt;SERVICE&gt;&lt;/SERVICE&gt;&lt;/SERVICE&gt;&lt;/PUBLIC_IP&gt;&lt;/PRIVATE_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Make sure you create all the required groups (network-ojects, object-service)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 13:22:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031260#M398695</guid>
      <dc:creator>Luis Silva Benavides</dc:creator>
      <dc:date>2012-09-27T13:22:26Z</dc:date>
    </item>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031261#M398696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; So let's say that I have a public IP 50.50.50.50 that is already in a static nat command to internal 192.168.1.2 and access list setup to allow pop, http, https, and smtp to this server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot setup the above and tell it to use the same 50.50.50.50 address for http but point it to another server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 13:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031261#M398696</guid>
      <dc:creator>sonitadmin</dc:creator>
      <dc:date>2012-09-27T13:28:05Z</dc:date>
    </item>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031262#M398697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeas you are correct, i hope the earlier nat also port based not the ip to IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 13:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031262#M398697</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-09-27T13:30:40Z</dc:date>
    </item>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031263#M398698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; So with all the current IP's in use to a port (static nat command) already, would it be easier to get a bigger block and just change IP's?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 13:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031263#M398698</guid>
      <dc:creator>sonitadmin</dc:creator>
      <dc:date>2012-09-27T13:36:23Z</dc:date>
    </item>
    <item>
      <title>Setting up PAT</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031264#M398699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; If it urgent, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can select one public IP which is not using for web/ftp and that can be used for setting up the existing and the new appkications based on port..&lt;/P&gt;&lt;P&gt;for example your 50.50.50.50 is being used for only smtp but it is natted to IP to IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that has to be changed&amp;nbsp; 3 different port based nat, for smtp ( existing), ftp &amp;amp; web ( new)..&lt;/P&gt;&lt;P&gt;getting a new pool or expanding the pool, is really depend on your provider&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 13:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-pat/m-p/2031264#M398699</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-09-27T13:44:04Z</dc:date>
    </item>
  </channel>
</rss>

