<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA source ip configuration for servers in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050851#M438522</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is running 8.2(2) .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if i can get the steps to achieve it. thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Sep 2012 05:59:45 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2012-09-07T05:59:45Z</dc:date>
    <item>
      <title>ASA source ip configuration for servers</title>
      <link>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050849#M438520</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the following flow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN Server ( 192.168.100.5 &amp;amp; 100.11 ) -----&amp;gt; Switch -------&amp;gt; ASA ---------&amp;gt; Internet ------------&amp;gt; Destination Host&lt;/P&gt;&lt;P&gt;The ASA's outside interface has Internet IP 202.87.65.22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When both Lan servers initiate a connection to the remote destination host, they are only recognised at the destination with individual Internet IP's as given.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e, 192.168.100.5 is only recognised as 202.87.65.35&amp;nbsp; &amp;amp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.100.11 is only recognised as 202.87.65.36&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The destination doesn't recognise the request if the source is not from above Internet IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do i ensure and configure the ASA such that; traffic from both these lan servers go out with their Internet IP's only, rather than taking the ASA's &lt;/P&gt;&lt;P&gt;outside interface IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050849#M438520</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T23:51:15Z</dc:date>
    </item>
    <item>
      <title>ASA source ip configuration for servers</title>
      <link>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050850#M438521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Policy nat (8.2) or Twice Nat with destination on (8.3 or higher)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version are you running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Rate all the answers, that is more important for us than a thanks?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 05:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050850#M438521</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-09-07T05:53:02Z</dc:date>
    </item>
    <item>
      <title>ASA source ip configuration for servers</title>
      <link>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050851#M438522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is running 8.2(2) .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if i can get the steps to achieve it. thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 05:59:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050851#M438522</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2012-09-07T05:59:45Z</dc:date>
    </item>
    <item>
      <title>ASA source ip configuration for servers</title>
      <link>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050852#M438523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are using pre 8.3 code, then you would need the following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 202.87.65.35 192.168.100.5&lt;/P&gt;&lt;P&gt;static (inside,outside) 202.87.65.36 192.168.100.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip any host 202.87.65.35&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip any host 202.87.65.36&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would only need the access-list if you also want the outside destination host to access your internal server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 06:02:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050852#M438523</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-09-07T06:02:42Z</dc:date>
    </item>
    <item>
      <title>ASA source ip configuration for servers</title>
      <link>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050853#M438524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets go with the Policy nat as per your request is based on destination&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test permit ip host 192.168.100.5 host destination_host_ip&lt;/P&gt;&lt;P&gt;nat (inside) 10 access-list test&lt;/P&gt;&lt;P&gt;global (outside) 10&amp;nbsp; 202.87.65.35&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test2 permit ip host&amp;nbsp; 192.168.100.11&amp;nbsp; host destination_host_ip&lt;/P&gt;&lt;P&gt;nat (inside) 11 access-list&amp;nbsp; test2&lt;/P&gt;&lt;P&gt;global (outside) 11 202.87.65.36&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Remember to rate all the answers,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 06:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-source-ip-configuration-for-servers/m-p/2050853#M438524</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-09-07T06:27:22Z</dc:date>
    </item>
  </channel>
</rss>

