<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static NAT through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393889#M417480</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your patience and assistance with this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have already configured network objects where possible but unfortunately some are hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Apr 2010 12:32:32 GMT</pubDate>
    <dc:creator>KeithN123</dc:creator>
    <dc:date>2010-04-19T12:32:32Z</dc:date>
    <item>
      <title>Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393879#M417463</link>
      <description>&lt;P&gt;I have configured a static NAT through my ASA, which for some&lt;/P&gt;&lt;P&gt;reason does not work - I believe the problem is with the NAT or&lt;/P&gt;&lt;P&gt;der rather than the rule itself but I would be most grateful if someone&lt;/P&gt;&lt;P&gt;could assist me in diagnosing the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from command line the rule is ::-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (UKSCMGMT,management) 10.20.20.20 192.168.1.2 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my theory is that anything with a destination address of 10.20.20.20 would be seen as 192.168.1.2 on teh UKSCMGMT interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;looking at ASDM the rule looks like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; trans address&lt;/P&gt;&lt;P&gt;Static&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; blank&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; management&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.20.20.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are some EXEMPT rules relating to 192.168.1.2 - but they are host to host and should not affect the static translation.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393879#M417463</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2020-02-21T11:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393880#M417465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please share the following configuration:&lt;/P&gt;&lt;P&gt;sh run interface --&amp;gt; would like to see the security level&lt;/P&gt;&lt;P&gt;sh run static --&amp;gt; depending on the security level above, need to check the current static statement&lt;/P&gt;&lt;P&gt;sh run nat --&amp;gt; also need to check if the NAT exemption overlaps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2010 10:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393880#M417465</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-08T10:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393881#M417467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;both interfaces have a security level of 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the show run static command gives the following =&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (UKSCMGMT,management) LS-NAT-P-NAG02 ls-mpd-p-nag02 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have now removed all the Exempt statements and ticked the "Enable traffic through the firewall without translation" box&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attached is a packet trace of the rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you for taking the time to look at this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2010 12:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393881#M417467</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2010-04-08T12:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393882#M417469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If they are the same security level, you would need to add the following:&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2010 12:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393882#M417469</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-08T12:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393883#M417470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have already apllied this command - but I still see the same error ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2010 12:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393883#M417470</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2010-04-08T12:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393884#M417472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your goal to perform NAT for communication between the 2 networks that has the same security level? Also, if you don't mind posting your config that would help. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Apr 2010 05:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393884#M417472</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-09T05:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393885#M417474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - I am unable to post the configuration - but would you be able to clarify the use of the checkbox&lt;/P&gt;&lt;P&gt;"Enable traffice throught the firewall without address translation"&amp;nbsp;&amp;nbsp; -&amp;nbsp; &lt;/P&gt;&lt;P&gt;If I check this box.&amp;nbsp; Does that mean I no longer need to specifiy any network exemption&lt;/P&gt;&lt;P&gt;, and only configure the real NATted addresses?&amp;nbsp;&amp;nbsp; Can I safely configure "no nat-control" and remove all EXEMPT configuration ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Apr 2010 09:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393885#M417474</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2010-04-19T09:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393886#M417476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "no nat-control" will only work if you have no NAT statement at all configured (including the dynamic NAT). As soon as you have 1 NAT statement, the "no nat-control" will not take effect anymore, and you will still need to configure NAT exemption.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Apr 2010 10:13:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393886#M417476</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-19T10:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393887#M417478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;many thanks fior the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So that means that even though I have only&lt;/P&gt;&lt;P&gt;a few NAT statements (probably 15 or 20) I will have to configure every single&lt;/P&gt;&lt;P&gt;EXEMPT host or network that exists - of which there are hundreds ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already configured the firewall this way but I was looking for way to tidy up the enormous amount of exempt rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Apr 2010 11:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393887#M417478</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2010-04-19T11:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393888#M417479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, absolutely correct. You can configure NAT exemption per network instead of per each host. If you have hosts which can be grouped into a subnet, configure it as network statements instead.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Apr 2010 11:48:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393888#M417479</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-19T11:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT through ASA</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393889#M417480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your patience and assistance with this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have already configured network objects where possible but unfortunately some are hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Apr 2010 12:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-through-asa/m-p/1393889#M417480</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2010-04-19T12:32:32Z</dc:date>
    </item>
  </channel>
</rss>

