<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Public Pool, 2 ASAs, Static NAT ... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993316#M434655</link>
    <description>&lt;P&gt;I am looking for help on a mixture of Routing and Switching and Firewalling ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have a router connected to the ISP ... the router is also connected to a switch.&amp;nbsp; Into that switch I have pugged two ASAs.&amp;nbsp; A 5505 and 5520.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was given a /27 (255.255.255.224), 30 address block from the ISP.&amp;nbsp; Let's say the last octet of the router is .1, the ASA#1 is .2, and ASA #2 is .3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I wan't to use the rest of the addresses for Static NAT (the IP addresses are publically registered to their own domain names).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I use any of the rest of the addresses .4 through .30, on either ASA in Static NAT (1 to 1 translation)?&amp;nbsp; Possibly even move them back and forth between ASAs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does the router know which as ASA it needs to forward the packet to if it is destined for .12 for example?&amp;nbsp; Does the ASA send out an ARP message for each of its static addresses that it is using?&amp;nbsp; They packets aren't broadcast to the subnet, are they?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is this a Layer 3 problem.&amp;nbsp; Do I have to segment my /27 into two /28's on my router (requiring an additional interface and use of another IP address)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to debate if I could possibly model this in GNS3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS the reason for doing this is for dissaster recovery, moving servers between racks without changing IP address scheme (the private addressing scheme behind each ASA is identical), etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much for the help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;CCNP, CCDP, CCIP, ASA Specialist&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:16:39 GMT</pubDate>
    <dc:creator>msunderland78</dc:creator>
    <dc:date>2019-03-11T23:16:39Z</dc:date>
    <item>
      <title>Public Pool, 2 ASAs, Static NAT ...</title>
      <link>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993316#M434655</link>
      <description>&lt;P&gt;I am looking for help on a mixture of Routing and Switching and Firewalling ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have a router connected to the ISP ... the router is also connected to a switch.&amp;nbsp; Into that switch I have pugged two ASAs.&amp;nbsp; A 5505 and 5520.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was given a /27 (255.255.255.224), 30 address block from the ISP.&amp;nbsp; Let's say the last octet of the router is .1, the ASA#1 is .2, and ASA #2 is .3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I wan't to use the rest of the addresses for Static NAT (the IP addresses are publically registered to their own domain names).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I use any of the rest of the addresses .4 through .30, on either ASA in Static NAT (1 to 1 translation)?&amp;nbsp; Possibly even move them back and forth between ASAs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does the router know which as ASA it needs to forward the packet to if it is destined for .12 for example?&amp;nbsp; Does the ASA send out an ARP message for each of its static addresses that it is using?&amp;nbsp; They packets aren't broadcast to the subnet, are they?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is this a Layer 3 problem.&amp;nbsp; Do I have to segment my /27 into two /28's on my router (requiring an additional interface and use of another IP address)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to debate if I could possibly model this in GNS3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS the reason for doing this is for dissaster recovery, moving servers between racks without changing IP address scheme (the private addressing scheme behind each ASA is identical), etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much for the help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;CCNP, CCDP, CCIP, ASA Specialist&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993316#M434655</guid>
      <dc:creator>msunderland78</dc:creator>
      <dc:date>2019-03-11T23:16:39Z</dc:date>
    </item>
    <item>
      <title>Public Pool, 2 ASAs, Static NAT ...</title>
      <link>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993317#M434656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I use any of the rest of the addresses .4 through .30, on either ASA&amp;nbsp; in Static NAT (1 to 1 translation)?&amp;nbsp; Possibly even move them back and&amp;nbsp; forth between ASAs?&lt;/P&gt;&lt;P&gt;--&amp;gt; YES you can&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does the router know which as ASA it needs to forward the packet to&amp;nbsp; if it is destined for .12 for example?&amp;nbsp; Does the ASA send out an ARP&amp;nbsp; message for each of its static addresses that it is using?&amp;nbsp; They packets&amp;nbsp; aren't broadcast to the subnet, are they?&lt;/P&gt;&lt;P&gt;--&amp;gt; YES, the ASA will send out an ARP to tell the router that it has that particular static address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is this a Layer 3 problem.&amp;nbsp; Do I have to segment my /27 into two&amp;nbsp; /28's on my router (requiring an additional interface and use of another&amp;nbsp; IP address)?&lt;/P&gt;&lt;P&gt;--&amp;gt; NO, you don't have to segment the /27 into /28&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 02:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993317#M434656</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-08T02:23:51Z</dc:date>
    </item>
    <item>
      <title>Public Pool, 2 ASAs, Static NAT ...</title>
      <link>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993318#M434657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is exactly what I was looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We figured out while we had partially disabled the Static NAT addresses we were translating, we had not fully disabled them on the first of the two ASAs.&amp;nbsp; So when we tried to the use them on the second, the switch still thought the first had the address (since it did).&amp;nbsp; The minute we fully disabled it, the CAM table updated ... and whalla, it began working correctly on the second ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is good to know Static NAT resolves via ARP.&amp;nbsp; I had a hard time finding any good documentation on Static NAT ARP resolution.&amp;nbsp; Does such a thing exsist?&amp;nbsp; Maybe it is just in the RFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THANKS AGAIN!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 15:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993318#M434657</guid>
      <dc:creator>msunderland78</dc:creator>
      <dc:date>2012-06-08T15:16:55Z</dc:date>
    </item>
    <item>
      <title>Public Pool, 2 ASAs, Static NAT ...</title>
      <link>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993319#M434658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to know all is working. Thanks for the update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what you are looking for &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s8.html#wp1517975"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s8.html#wp1517975&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 15:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/public-pool-2-asas-static-nat/m-p/1993319#M434658</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-08T15:24:00Z</dc:date>
    </item>
  </channel>
</rss>

