<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM : Can same security level command create identity nat? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-can-same-security-level-command-create-identity-nat/m-p/1999205#M439226</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the topic : Can same security level command create identity nat? I found identity nat when show xlate debug command although no configuration related to identitiy nat for those subnet ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My brief configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- same security level intra interface is enable&lt;/P&gt;&lt;P&gt;- xlate-baypass is enable&lt;/P&gt;&lt;P&gt;- NAT examption for some subnet &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:42:43 GMT</pubDate>
    <dc:creator>phatrachit</dc:creator>
    <dc:date>2019-03-11T23:42:43Z</dc:date>
    <item>
      <title>FWSM : Can same security level command create identity nat?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-can-same-security-level-command-create-identity-nat/m-p/1999205#M439226</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the topic : Can same security level command create identity nat? I found identity nat when show xlate debug command although no configuration related to identitiy nat for those subnet ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My brief configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- same security level intra interface is enable&lt;/P&gt;&lt;P&gt;- xlate-baypass is enable&lt;/P&gt;&lt;P&gt;- NAT examption for some subnet &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:42:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-can-same-security-level-command-create-identity-nat/m-p/1999205#M439226</guid>
      <dc:creator>phatrachit</dc:creator>
      <dc:date>2019-03-11T23:42:43Z</dc:date>
    </item>
    <item>
      <title>FWSM : Can same security level command create identity nat?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-can-same-security-level-command-create-identity-nat/m-p/1999206#M439227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To my knowlege the FWSM creates a xlate for all connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/cfgnat_f.html"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/cfgnat_f.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -28.799999237060547px; background-color: #ffffff;" width="1" /&gt;&lt;/P&gt;&lt;P&gt;"Even if you do not configure NAT, the FWSM continues to create translation sessions for all traffic automatically. In this case, the translation is from the real address to the same real address. See the &lt;/P&gt;&lt;P&gt; &lt;STRONG style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -28.799999237060547px; background-color: #ffffff;"&gt;show xlate &lt;/STRONG&gt;command to view translation sessions."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2012 22:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-can-same-security-level-command-create-identity-nat/m-p/1999206#M439227</guid>
      <dc:creator>rleivaoc</dc:creator>
      <dc:date>2012-08-15T22:02:13Z</dc:date>
    </item>
    <item>
      <title>FWSM : Can same security level command create identity nat?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-can-same-security-level-command-create-identity-nat/m-p/1999207#M439228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi rleivaoc,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's true that FWSM will create a xlate for all connections but it wouldn't show up anymore if xlate-bypass enabled. I mean traffic that pass through FWSM because FWSM NAT on Hardware not Software like ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 01:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-can-same-security-level-command-create-identity-nat/m-p/1999207#M439228</guid>
      <dc:creator>phatrachit</dc:creator>
      <dc:date>2012-08-16T01:15:46Z</dc:date>
    </item>
  </channel>
</rss>

