<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic fwms nat outside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwms-nat-outside/m-p/1883866#M452326</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I can say is that I suggest using the NAT/GLOBAL statements only for the interfaces that "head out" of your local networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never do PAT configurations between my own interfaces. Like DMZs and different LAN segments. I only do the PAT configurations towards OUTSIDE and perhaps some 3rd party connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why not just allow the traffic between INSIDE and DMZ unnated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Apr 2012 12:36:05 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-04-22T12:36:05Z</dc:date>
    <item>
      <title>fwms nat outside</title>
      <link>https://community.cisco.com/t5/network-security/fwms-nat-outside/m-p/1883865#M452322</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone can help me with this problem please&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;I have FWSM Firewall Version 3.2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I want to use &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 10.0.0.0 255.0.0.0 outside &lt;/P&gt;&lt;P&gt;global (INSIDE) 1 192.168.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in order to use dynamic NAT from DMZ to INSIDE all other translation rules are not functioning from DMZ&lt;/P&gt;&lt;P&gt;i.e.all STATIC and NAT rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (INSIDE, STATIC) 192.168.0.0. 192.168.0.0. netmask 255.255.0.0. &lt;/P&gt;&lt;P&gt;nat (DMZ) 2 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;global (OUSIDE) 2 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that static nat has priority but it seems that nat with outside statement runs over all other translations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I remove no nat (DMZ) 1 10.0.0.0 255.0.0.0 outside everything goes back to normal and I can ping everything from DMZ as before&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have experience with this?&lt;/P&gt;&lt;P&gt;Am I doing something wrong or this is normal behavior?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;A.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwms-nat-outside/m-p/1883865#M452322</guid>
      <dc:creator>Antonio_1_2</dc:creator>
      <dc:date>2019-03-11T22:56:49Z</dc:date>
    </item>
    <item>
      <title>fwms nat outside</title>
      <link>https://community.cisco.com/t5/network-security/fwms-nat-outside/m-p/1883866#M452326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I can say is that I suggest using the NAT/GLOBAL statements only for the interfaces that "head out" of your local networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never do PAT configurations between my own interfaces. Like DMZs and different LAN segments. I only do the PAT configurations towards OUTSIDE and perhaps some 3rd party connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why not just allow the traffic between INSIDE and DMZ unnated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2012 12:36:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwms-nat-outside/m-p/1883866#M452326</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-04-22T12:36:05Z</dc:date>
    </item>
    <item>
      <title>fwms nat outside</title>
      <link>https://community.cisco.com/t5/network-security/fwms-nat-outside/m-p/1883867#M452328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use PAT so that I don't need to configure static routes on a large amount devices in LAN toward DMZ network. &lt;/P&gt;&lt;P&gt;Those LAN devices don't have default route toward firewall but to other router. &lt;/P&gt;&lt;P&gt;So in order for LAN devices to reach DMZ network I just need to configure PAT from DMZ to some LAN IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;A.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 15:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwms-nat-outside/m-p/1883867#M452328</guid>
      <dc:creator>Antonio_1_2</dc:creator>
      <dc:date>2012-04-23T15:09:53Z</dc:date>
    </item>
  </channel>
</rss>

