<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 nat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025124#M399469</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi varun,&lt;/P&gt;&lt;P&gt;Thank you for the reply, vendor has many networks &amp;amp; I found out that they will be accessing a &lt;BR /&gt;single server 10.1.1.6, I have made following changes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;object-group network vendor_network&lt;BR /&gt; network-object 10.160.8.0 255.255.255.0 &lt;BR /&gt; network-object 10.194.5.0 255.255.255.0 &lt;BR /&gt; network-object 10.196.8.0 255.255.255.0 &lt;BR /&gt; network-object 10.216.28.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt; object network network_1&lt;BR /&gt;&amp;nbsp; subnet 10.1.1.6 255.255.255.255&lt;BR /&gt;!&lt;BR /&gt;nat (outside,inside) source static vendor_network vendor_network destination static network_1 network_1&lt;BR /&gt;!&lt;BR /&gt;access-list external extended permit ip &lt;VENDOR_NETWORK&gt; &lt;SUBNET&gt; host 10.1.1.6 - entry for each vendor network&lt;BR /&gt;!&lt;/SUBNET&gt;&lt;/VENDOR_NETWORK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if changes will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2012 14:32:32 GMT</pubDate>
    <dc:creator>marktaylor47</dc:creator>
    <dc:date>2012-09-12T14:32:32Z</dc:date>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025120#M399461</link>
      <description>&lt;P&gt;I have a 5505 between a vendor router &amp;amp; my company network, vendor is not able to access devices on internal network. I am also not able to access the firewall via asdm, please see attached config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025120#M399461</guid>
      <dc:creator>marktaylor47</dc:creator>
      <dc:date>2019-03-11T23:52:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025121#M399463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are using a very old incompatible version of ASDM, you woudl need to upgrade the ASDM to the latest 6.4.9, and yours is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asdm image disk0:/&lt;STRONG&gt;asdm-524.bin&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no configuration in teh file which would give access of your internal network to the outside vendor, what machines does the vendor need to access?? You would need to put a NAT for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 03:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025121#M399463</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-12T03:32:39Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025122#M399465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vendor need access to&amp;nbsp; servers on 10.1.1.0 &amp;amp; 10.88.10.0 networks, new to firewalls, can you give an example of nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 11:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025122#M399465</guid>
      <dc:creator>marktaylor47</dc:creator>
      <dc:date>2012-09-12T11:43:40Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025123#M399468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can definitely give this a try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network vendor_network&lt;/P&gt;&lt;P&gt; subnet xx.xx.xx.xx &lt;SUBNET mask=""&gt;&lt;/SUBNET&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network network_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 10.1.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network network_2&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 10.88.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside,inside) source static vendor_network vendor_network destination static network_1 network_1&lt;/P&gt;&lt;P&gt;nat (outside,inside) source static vendor_network vendor_network destination static network_2 network_2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list external extended permit ip &lt;VENDOR_NETWORK&gt; &lt;SUBNET&gt; 10.1.1.0 255.255.255.0&lt;/SUBNET&gt;&lt;/VENDOR_NETWORK&gt;&lt;/P&gt;&lt;P&gt;access-list external extended permit ip &lt;VENDOR_NETWORK&gt; &lt;SUBNET&gt; 10.88.10.0 255.255.255.0&lt;/SUBNET&gt;&lt;/VENDOR_NETWORK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group external in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 11:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025123#M399468</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-12T11:59:43Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025124#M399469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi varun,&lt;/P&gt;&lt;P&gt;Thank you for the reply, vendor has many networks &amp;amp; I found out that they will be accessing a &lt;BR /&gt;single server 10.1.1.6, I have made following changes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;object-group network vendor_network&lt;BR /&gt; network-object 10.160.8.0 255.255.255.0 &lt;BR /&gt; network-object 10.194.5.0 255.255.255.0 &lt;BR /&gt; network-object 10.196.8.0 255.255.255.0 &lt;BR /&gt; network-object 10.216.28.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt; object network network_1&lt;BR /&gt;&amp;nbsp; subnet 10.1.1.6 255.255.255.255&lt;BR /&gt;!&lt;BR /&gt;nat (outside,inside) source static vendor_network vendor_network destination static network_1 network_1&lt;BR /&gt;!&lt;BR /&gt;access-list external extended permit ip &lt;VENDOR_NETWORK&gt; &lt;SUBNET&gt; host 10.1.1.6 - entry for each vendor network&lt;BR /&gt;!&lt;/SUBNET&gt;&lt;/VENDOR_NETWORK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if changes will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 14:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025124#M399469</guid>
      <dc:creator>marktaylor47</dc:creator>
      <dc:date>2012-09-12T14:32:32Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025125#M399470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is the correct configuration that you would need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 14:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025125#M399470</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-12T14:35:59Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025126#M399471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again for your help, I will be applying the changes tomorrow &amp;amp; let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 14:42:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025126#M399471</guid>
      <dc:creator>marktaylor47</dc:creator>
      <dc:date>2012-09-12T14:42:43Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025127#M399472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do I have to remove following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic Inside_Internal interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thnks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 15:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025127#M399472</guid>
      <dc:creator>marktaylor47</dc:creator>
      <dc:date>2012-09-12T15:44:10Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025128#M399473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No you need not remove it, thats for internal users to access outside resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 15:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025128#M399473</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-12T15:46:08Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025129#M399474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I started ASDM, it gave me an error message to downgrade to 8.2 as not enough RAM. I downgraded &amp;amp; nat statements are gone, I tried to add but it doesn't give me the options, what will be the config for 8.2(5) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 17:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025129#M399474</guid>
      <dc:creator>marktaylor47</dc:creator>
      <dc:date>2012-09-12T17:18:17Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025130#M399475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please send nat for 8.2.5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 10:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat/m-p/2025130#M399475</guid>
      <dc:creator>marktaylor47</dc:creator>
      <dc:date>2012-09-13T10:57:35Z</dc:date>
    </item>
  </channel>
</rss>

