<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Additional Public IPs added to my outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959553#M401385</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have run out of public facing IP addresses and I need more.&lt;/P&gt;&lt;P&gt;Assuming I have been issued 1.1.1.0/24 and my new/additional range/subnet issued is 2.2.2/0/24 - Can I carry on with the same configuration on my ASA5510 and just add static NAT for new services in the 2.2.2.0/24 range.&lt;/P&gt;&lt;P&gt;i.e.existing config&lt;/P&gt;&lt;P&gt;route 0.0.0.0 0.0.0.0 1.1.1.254 (upstream ISP)&lt;/P&gt;&lt;P&gt;Interface outside ip address 1.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT 2.2.2.1 to 10.1.2.3&lt;/P&gt;&lt;P&gt;or, assume my ISP will deliver 2.2.2.1 to my outside interface (1.1.1.1.1/24) and if my NAT is in place it will get delivered to 10.1.2.3 inside.&lt;/P&gt;&lt;P&gt;or, put another way I dont need change my set-up as I just static route to my ISP!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS? &lt;/P&gt;&lt;P&gt;my real public IP is a /27 can I use my broadcast address (its a legit public IP address)?&lt;/P&gt;&lt;P&gt;i.e 1.2.3.0/27 = 1.2.3.1 to 1.2.3.31&lt;/P&gt;&lt;P&gt;Outside interface = 1.2.3.1/27&lt;/P&gt;&lt;P&gt;Can I use 1.2.3.31 and NAT it to an internal server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:36:56 GMT</pubDate>
    <dc:creator>geraghtyconor</dc:creator>
    <dc:date>2019-03-11T23:36:56Z</dc:date>
    <item>
      <title>Additional Public IPs added to my outside interface</title>
      <link>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959553#M401385</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have run out of public facing IP addresses and I need more.&lt;/P&gt;&lt;P&gt;Assuming I have been issued 1.1.1.0/24 and my new/additional range/subnet issued is 2.2.2/0/24 - Can I carry on with the same configuration on my ASA5510 and just add static NAT for new services in the 2.2.2.0/24 range.&lt;/P&gt;&lt;P&gt;i.e.existing config&lt;/P&gt;&lt;P&gt;route 0.0.0.0 0.0.0.0 1.1.1.254 (upstream ISP)&lt;/P&gt;&lt;P&gt;Interface outside ip address 1.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT 2.2.2.1 to 10.1.2.3&lt;/P&gt;&lt;P&gt;or, assume my ISP will deliver 2.2.2.1 to my outside interface (1.1.1.1.1/24) and if my NAT is in place it will get delivered to 10.1.2.3 inside.&lt;/P&gt;&lt;P&gt;or, put another way I dont need change my set-up as I just static route to my ISP!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS? &lt;/P&gt;&lt;P&gt;my real public IP is a /27 can I use my broadcast address (its a legit public IP address)?&lt;/P&gt;&lt;P&gt;i.e 1.2.3.0/27 = 1.2.3.1 to 1.2.3.31&lt;/P&gt;&lt;P&gt;Outside interface = 1.2.3.1/27&lt;/P&gt;&lt;P&gt;Can I use 1.2.3.31 and NAT it to an internal server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959553#M401385</guid>
      <dc:creator>geraghtyconor</dc:creator>
      <dc:date>2019-03-11T23:36:56Z</dc:date>
    </item>
    <item>
      <title>Additional Public IPs added to my outside interface</title>
      <link>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959554#M401386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can use that for the NAT/PAT but make sure that proper routing is done from your end and ISP end to route the new Public IP pool. In your ISP router both the subnets 1.1.1.0/24 and 2.2.2.0/24 routed and advertised properly as well as from your LAN. If so you can use the additional public ip for your purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given information helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2012 11:17:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959554#M401386</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-08-01T11:17:35Z</dc:date>
    </item>
    <item>
      <title>Additional Public IPs added to my outside interface</title>
      <link>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959555#M401387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I would add the new outside IP 2.2.2.2 as a secondary IP on the 1.1.1.1 interface and add NAT rules. I don't believe the static default route would change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, you can't use a network or broadcast IP in a block for anything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2012 15:18:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959555#M401387</guid>
      <dc:creator>paclark01</dc:creator>
      <dc:date>2012-08-01T15:18:03Z</dc:date>
    </item>
    <item>
      <title>Additional Public IPs added to my outside interface</title>
      <link>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959556#M401388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Earlier i dint gone through your query completely. Your another query&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my real public IP is a /27 can I use my broadcast address (its a legit public IP address)?&lt;/P&gt;&lt;P&gt;i.e 1.2.3.0/27 = 1.2.3.1 to 1.2.3.31&lt;/P&gt;&lt;P&gt;Outside interface = 1.2.3.1/27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use 1.2.3.1-30 not the 31 neither .0 for your NAT/PAT. In any scenario you cannot use the Network id and Broadcast address. Peter clark is right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2012 04:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/additional-public-ips-added-to-my-outside-interface/m-p/1959556#M401388</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-08-02T04:30:18Z</dc:date>
    </item>
  </channel>
</rss>

