<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA static NAT problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-static-nat-problem/m-p/1892065#M457779</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have some issues with your design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly I am not used to a inside interface ( a lan), with IP address ending in&amp;nbsp;&amp;nbsp; .243, I am used to .1 &lt;/P&gt;&lt;P&gt;My knowledge is limited so it might be perfectly legitimate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly with a basic license at least on the ASA5505, the DMZ could only be used for DMZ or internet bound traffic.&lt;/P&gt;&lt;P&gt;The internal lan could reach the DMZ or the internet.&lt;/P&gt;&lt;P&gt;Make sure your license permits a fully functioning DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thirdly, I really dont care about your config at this point.&amp;nbsp; I would like to know in words, what your requirements are first.&amp;nbsp; Then we can look at implementation.&amp;nbsp; What is it that you need in your work environement in concepts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 25 Mar 2012 23:29:19 GMT</pubDate>
    <dc:creator>llamaw0rksE</dc:creator>
    <dc:date>2012-03-25T23:29:19Z</dc:date>
    <item>
      <title>ASA static NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-problem/m-p/1892064#M457775</link>
      <description>&lt;P&gt;Dear boss &lt;/P&gt;&lt;P&gt; I m using ASA5510 for DMZ. Please see my attached diagram and configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif local&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.243 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.0.0.2 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.29.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZTOLocal extended permit ip host 192.168.0.241 192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,local) 192.168.0.241 172.29.1.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group DMZTOLocal out interface local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My out side NAT is ok. I get local&amp;nbsp; to DMZ&amp;nbsp; ie 192.168.0.0/16 to 192.168.0.241(172.29.1.5),&amp;nbsp; but not getting 172.29.1.5 to 192.168.0.0/16. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can i do if i want to get DMZ to Local ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanking You &lt;/P&gt;&lt;P&gt;shahid&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-problem/m-p/1892064#M457775</guid>
      <dc:creator>shahid_duet</dc:creator>
      <dc:date>2019-03-11T22:46:30Z</dc:date>
    </item>
    <item>
      <title>ASA static NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-problem/m-p/1892065#M457779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have some issues with your design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly I am not used to a inside interface ( a lan), with IP address ending in&amp;nbsp;&amp;nbsp; .243, I am used to .1 &lt;/P&gt;&lt;P&gt;My knowledge is limited so it might be perfectly legitimate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly with a basic license at least on the ASA5505, the DMZ could only be used for DMZ or internet bound traffic.&lt;/P&gt;&lt;P&gt;The internal lan could reach the DMZ or the internet.&lt;/P&gt;&lt;P&gt;Make sure your license permits a fully functioning DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thirdly, I really dont care about your config at this point.&amp;nbsp; I would like to know in words, what your requirements are first.&amp;nbsp; Then we can look at implementation.&amp;nbsp; What is it that you need in your work environement in concepts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Mar 2012 23:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-problem/m-p/1892065#M457779</guid>
      <dc:creator>llamaw0rksE</dc:creator>
      <dc:date>2012-03-25T23:29:19Z</dc:date>
    </item>
    <item>
      <title>ASA static NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-problem/m-p/1892066#M457783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; your: &lt;/P&gt;&lt;P&gt;access-list DMZTOLocal extended permit ip host 192.168.0.241 192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will still not allow access from DMZ---&amp;gt;Local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZTOLocal extended permit ip host 172.29.1.5 192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and apply this to your&amp;nbsp; DMZ interface in&amp;nbsp; access-group DMZTOLOCAL in interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, fire up your packet tracer in ASDM and see what drops your traffic, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dennis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 01:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-problem/m-p/1892066#M457783</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2012-03-26T01:00:21Z</dc:date>
    </item>
  </channel>
</rss>

