<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about configuration of  NAT on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036531#M403087</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you don't want or don't need to NAT it on the ASA, you don't have to.&lt;/P&gt;&lt;P&gt;However, the router needs to have static route for the private IP that the ASA assigns to the internal host pointing towards the ASA outside interface that connects to the router if the ASA doesn't perform NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would also need to configure static NAT to itself on the ASA, or if you are not configuring any NATing at all on the ASA and runs version 8.2 or below, you can disable nat-control (no nat-control).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Oct 2012 03:53:02 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-10-23T03:53:02Z</dc:date>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036530#M403086</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ASA config with DHCP and its providing IP to users.&lt;/P&gt;&lt;P&gt;ASA is connected to 3550 switch it has direct connection or say default static route&lt;/P&gt;&lt;P&gt;From 3550 switch&amp;nbsp; connection goes to Router and it does the NAT&amp;nbsp;&amp;nbsp; and has connection to outside world.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is do i need to configure the NAT inside&amp;nbsp; and global (outside ) on the ASA&amp;nbsp; or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding NAT is done by router which has connection to ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036530#M403086</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T00:12:42Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036531#M403087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you don't want or don't need to NAT it on the ASA, you don't have to.&lt;/P&gt;&lt;P&gt;However, the router needs to have static route for the private IP that the ASA assigns to the internal host pointing towards the ASA outside interface that connects to the router if the ASA doesn't perform NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would also need to configure static NAT to itself on the ASA, or if you are not configuring any NATing at all on the ASA and runs version 8.2 or below, you can disable nat-control (no nat-control).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 03:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036531#M403087</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-23T03:53:02Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036532#M403088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you are doing the NAT on an external router then you do not need to perform NAT on the ASA, so just disable NAT-control. Then packets will be able to go through the box with no need of a NAT rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also just to let you know as soon as you set a NAT rule on an interface, traffic comming from that particular interface will need to get natted even if you have nat control off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 03:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036532#M403088</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-23T03:54:15Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036533#M403089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for replied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested like this&amp;nbsp; config the NAT on ASA&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then as per your reply run the command no nat-control as ASA ver is 8.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But nat config is still there in ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did sh xlate it shows &lt;/P&gt;&lt;P&gt;ciscoasa# sh xlate&lt;/P&gt;&lt;P&gt;27 in use, 371 most used&lt;/P&gt;&lt;P&gt;PAT Global 192.168.11.2(33396) Local 192.168.1.5(57177)&lt;/P&gt;&lt;P&gt;PAT Global 192.168.11.2(61657) Local 192.168.1.5(57176)&lt;/P&gt;&lt;P&gt;PAT Global 192.168.11.2(52259) Local 192.168.1.5(57175)&lt;/P&gt;&lt;P&gt;PAT Global 192.168.11.2(30453) Local 192.168.1.5(57174)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did clear xlate still there is output from the sh xlate &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is how we test that ASA is nating or not ?&lt;/P&gt;&lt;P&gt;Which commands can tell us that ASA is doing NAT ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036533#M403089</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-10-23T04:03:07Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036534#M403090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah, if you are running version 8.4, then the command: nat-control doesn't exist anymore. It's only available from version 8.2 or below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls run the following command:&lt;/P&gt;&lt;P&gt;sh nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you can see whether it's NATing or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:07:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036534#M403090</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-23T04:07:17Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036535#M403091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface inside:&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 192.168.1.0 255.255.255.0 inside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 192.168.1.0 255.255.255.0 outside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (192.168.11.2 [Interface PAT])&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 9916, untranslate_hits = 264&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 192.168.1.0 255.255.255.0 _internal_loopback any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;ciscoasa#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we tell from here if ASA is natting ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:10:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036535#M403091</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-10-23T04:10:16Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036536#M403092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The answer is yes, it is NATing to the ASA outside interface address which is 192.168.11.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the output, here is the statement that says the translation:&lt;/P&gt;&lt;P&gt;match ip inside 192.168.1.0 255.255.255.0 outside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (192.168.11.2 [Interface PAT])&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt; translate_hits = 9916&lt;/STRONG&gt;, untranslate_hits = 264&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036536#M403092</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-23T04:13:55Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036537#M403093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we do sh nat&amp;nbsp; output shows 3 match statements if you please tell me what is purpose of 3 statements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:23:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036537#M403093</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-10-23T04:23:14Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036538#M403094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a look at the interface, you can check the interface direction that it has been configured:&lt;/P&gt;&lt;P&gt;- First statement, &lt;/P&gt;&lt;P&gt;match ip &lt;STRONG&gt;inside &lt;/STRONG&gt;192.168.1.0 255.255.255.0 &lt;STRONG&gt;inside &lt;/STRONG&gt;any&lt;/P&gt;&lt;P&gt;--&amp;gt; traffic from inside to inside, and there is no translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Second statement:&lt;/P&gt;&lt;P&gt;match ip &lt;STRONG&gt;inside &lt;/STRONG&gt;192.168.1.0 255.255.255.0 &lt;STRONG&gt;outside &lt;/STRONG&gt;any&lt;/P&gt;&lt;P&gt;--&amp;gt; traffic from inside to outside, and there is translation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Third statement:&lt;/P&gt;&lt;P&gt;match ip &lt;STRONG&gt;inside &lt;/STRONG&gt;192.168.1.0 255.255.255.0 &lt;STRONG&gt;_internal_loopback&lt;/STRONG&gt; any&lt;/P&gt;&lt;P&gt;--&amp;gt; traffic from inside to loopback address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036538#M403094</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-23T04:36:18Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036539#M403095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for all the answers on ASA&amp;nbsp; NAT.&lt;/P&gt;&lt;P&gt;Its always good to learn about new Technologies if Someone like you can answer the questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036539#M403095</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-10-23T04:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036540#M403096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are welcome, Mahesh.&lt;/P&gt;&lt;P&gt;Appreciate all the ratings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036540#M403096</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-23T04:43:50Z</dc:date>
    </item>
    <item>
      <title>Question about configuration of  NAT on ASA</title>
      <link>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036541#M403097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again now.&lt;/P&gt;&lt;P&gt;Seems i am good for today now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 04:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-configuration-of-nat-on-asa/m-p/2036541#M403097</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2012-10-23T04:44:06Z</dc:date>
    </item>
  </channel>
</rss>

