<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring Dyn Nat on different subnet than the outside network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908452#M437746</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no issue. The ISP should route all the packets to the new public IP to the ASA's outside IP.&lt;/P&gt;&lt;P&gt;You have to split the groups that will be nat-ed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 May 2012 18:02:56 GMT</pubDate>
    <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
    <dc:date>2012-05-03T18:02:56Z</dc:date>
    <item>
      <title>Configuring Dyn Nat on different subnet than the outside network</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908451#M437745</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have to add some nating configuration to the ones that we already have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually we nat all the inside traffic from our ASA 5520 to the outside public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently add a new public IP network from our ISP.&amp;nbsp; We want to nat a specific inside subnet to an IP from that new public IP network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We add a new network object rules for our inside subnet we wanted to nat from&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also add our nat instance into the same object group : nat (inside,outside) dynamic [Public IP Address]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other configuration we should add to make it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note : we compare with another ASA 5520 we have and everything seems to be the same except that the public IP address is on the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also look at the ASA next hop, to make sure the packet are routed to the new public IP network.&amp;nbsp; Everything seems to be ok too !&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:01:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908451#M437745</guid>
      <dc:creator>netadmincsm</dc:creator>
      <dc:date>2019-03-11T23:01:52Z</dc:date>
    </item>
    <item>
      <title>Configuring Dyn Nat on different subnet than the outside network</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908452#M437746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no issue. The ISP should route all the packets to the new public IP to the ASA's outside IP.&lt;/P&gt;&lt;P&gt;You have to split the groups that will be nat-ed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 18:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908452#M437746</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-05-03T18:02:56Z</dc:date>
    </item>
    <item>
      <title>Configuring Dyn Nat on different subnet than the outside network</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908453#M437747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a specific ACL that I need to open ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 18:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908453#M437747</guid>
      <dc:creator>netadmincsm</dc:creator>
      <dc:date>2012-05-03T18:38:05Z</dc:date>
    </item>
    <item>
      <title>Configuring Dyn Nat on different subnet than the outside network</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908454#M437748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My understanding is that the ASA is used for internet access - this means the traffic is initialized on inside and going to outside. Your ASA is already configured for this - meaning that all the required inside hosts are allowed to access-l the internet - the nat will make different translations based on your rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you configured the new nat rule on the same object-group , I do belive that the old one was overwritten. Can you check that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 18:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908454#M437748</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-05-03T18:48:00Z</dc:date>
    </item>
    <item>
      <title>Configuring Dyn Nat on different subnet than the outside network</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908455#M437749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the delay.&amp;nbsp; It's been very busy around here!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes the old one is overwritten.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 18:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dyn-nat-on-different-subnet-than-the-outside-network/m-p/1908455#M437749</guid>
      <dc:creator>netadmincsm</dc:creator>
      <dc:date>2012-05-09T18:54:33Z</dc:date>
    </item>
  </channel>
</rss>

