<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 with Static VLAN NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937984#M458276</link>
    <description>&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;I am saravanan from Utah. One of our customers has asked us to nat from the LAN to the Voice LAN based on destination IP address in order to access a public phone server thorugh a vendor mangaed voice router..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internet for everything else&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Inside ------------------------&amp;gt; ASA 5510 -----------------&amp;gt; Voice router&amp;nbsp; ------&amp;gt;&amp;nbsp; outsdie to public phone server only&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;10.10.1.0/20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.7/320&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.1/24&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Voice-------------------------&amp;gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;172.16.20.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.254/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Here the ASA5510 has an interface in both networks and the inside network can ping the voice network through the firewall by using nonat acls. The phone server can only talk to the 172.16.20.0/24 network. So I need to nat the 10.10.1.0/20 network to the Voice interface on the ASA 172.16.20.254/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;So I think I need the follwoing static but I get the error below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (Inside,Voice) interface 10.10.0.0 netmask 255.255.240.0&lt;/P&gt;&lt;P&gt;WARNING: All traffic destined to the IP address of the Voice interface is being redirected.&lt;/P&gt;&lt;P&gt;WARNING: Users will not be able to access any service enabled on the Voice interface.&lt;/P&gt;&lt;P&gt;ERROR: Invalid netmask with interface option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style-type: none;"&gt;Sanitized ASA Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;ASA Version 8.2(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.1.7 255.255.252.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.2&lt;/P&gt;&lt;P&gt; vlan 2&lt;/P&gt;&lt;P&gt; nameif Voice&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.16.20.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip 10.10.0.0 255.255.240.0 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip 172.16.20.0 255.255.255.0 10.10.0.0 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit gre any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit gre any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit udp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Outside) 10 interface&lt;/P&gt;&lt;P&gt;nat (Inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (Inside) 10 10.10.0.0 255.255.240.0&lt;/P&gt;&lt;P&gt;nat (Voice) 0 access-list nonat&lt;/P&gt;&lt;P&gt;access-group Inside_in in interface Inside&lt;/P&gt;&lt;P&gt;access-group Voice_in in interface Voice&lt;/P&gt;&lt;P&gt;static(inside,Voice)10.10.0.0 255.255.240.0 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;route Inside XX.XX.XX.XX XXX.XXX.XXX.XXX 172.16.20.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Any help would be appreaciated!&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:40:40 GMT</pubDate>
    <dc:creator>DavidReisner</dc:creator>
    <dc:date>2019-03-11T22:40:40Z</dc:date>
    <item>
      <title>ASA 5510 with Static VLAN NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937984#M458276</link>
      <description>&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;I am saravanan from Utah. One of our customers has asked us to nat from the LAN to the Voice LAN based on destination IP address in order to access a public phone server thorugh a vendor mangaed voice router..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internet for everything else&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Inside ------------------------&amp;gt; ASA 5510 -----------------&amp;gt; Voice router&amp;nbsp; ------&amp;gt;&amp;nbsp; outsdie to public phone server only&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;10.10.1.0/20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.7/320&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.1/24&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Voice-------------------------&amp;gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;172.16.20.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.254/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Here the ASA5510 has an interface in both networks and the inside network can ping the voice network through the firewall by using nonat acls. The phone server can only talk to the 172.16.20.0/24 network. So I need to nat the 10.10.1.0/20 network to the Voice interface on the ASA 172.16.20.254/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;So I think I need the follwoing static but I get the error below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (Inside,Voice) interface 10.10.0.0 netmask 255.255.240.0&lt;/P&gt;&lt;P&gt;WARNING: All traffic destined to the IP address of the Voice interface is being redirected.&lt;/P&gt;&lt;P&gt;WARNING: Users will not be able to access any service enabled on the Voice interface.&lt;/P&gt;&lt;P&gt;ERROR: Invalid netmask with interface option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style-type: none;"&gt;Sanitized ASA Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;ASA Version 8.2(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.1.7 255.255.252.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.2&lt;/P&gt;&lt;P&gt; vlan 2&lt;/P&gt;&lt;P&gt; nameif Voice&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.16.20.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip 10.10.0.0 255.255.240.0 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip 172.16.20.0 255.255.255.0 10.10.0.0 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit gre any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list Voice_in extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit gre any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list Inside_in extended permit udp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Outside) 10 interface&lt;/P&gt;&lt;P&gt;nat (Inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (Inside) 10 10.10.0.0 255.255.240.0&lt;/P&gt;&lt;P&gt;nat (Voice) 0 access-list nonat&lt;/P&gt;&lt;P&gt;access-group Inside_in in interface Inside&lt;/P&gt;&lt;P&gt;access-group Voice_in in interface Voice&lt;/P&gt;&lt;P&gt;static(inside,Voice)10.10.0.0 255.255.240.0 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;route Inside XX.XX.XX.XX XXX.XXX.XXX.XXX 172.16.20.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Any help would be appreaciated!&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937984#M458276</guid>
      <dc:creator>DavidReisner</dc:creator>
      <dc:date>2019-03-11T22:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Static VLAN NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937985#M458278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static(inside,inside) 10.10.0.0 255.255.255.240 10.10.0.0 255.255.240.0&lt;/P&gt;&lt;P&gt;Static(voice,voice) 172.16.20.0 255.255.255.0 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Mar 2012 06:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937985#M458278</guid>
      <dc:creator>zac192000</dc:creator>
      <dc:date>2012-03-11T06:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Static VLAN NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937986#M458280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply. The only commands that the ASA will take similar to what you put are:&lt;/P&gt;&lt;P&gt;static (Inside,Inside) 10.10.0.0 10.10.0.0 netmask 255.255.240.0&lt;/P&gt;&lt;P&gt;static (Voice,Voice) 172.16.20.0 172.16.20.0 netmask 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And after entering these it still doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, since I have the no nat in there for these same networks, wouldn't the ASA get confused when I add those two statics?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 00:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937986#M458280</guid>
      <dc:creator>DavidReisner</dc:creator>
      <dc:date>2012-03-12T00:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Static VLAN NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937987#M458282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No the statements that I send to you is for the traffic that is initiating from voice zone to voice zone and from inside zone to inside zone...&lt;/P&gt;&lt;P&gt;One thing you need to make sure....If your requirement is to NAT the traffic from inside to voice then you should not use nonat statments,because if NAT-Control is enabled then you have to NAT every traffic whether your source is from inside to inside or from voice to voice or from inside to voice or from voice to inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are using nonat from inside to voice and from voice to inside and at the same time you are using static 1 to 1 mapping for both networks.As per rules,acl will be checked first and traffic will never be natted and static mappings will never come into play.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you should remove your nonat statments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add the static statments that I mentioned you earlier ,remove the nonat statments and let me know .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 00:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937987#M458282</guid>
      <dc:creator>zac192000</dc:creator>
      <dc:date>2012-03-12T00:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Static VLAN NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937988#M458284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And use the correct subnet mask....I have written a different subnet mask in my first post and you ate using a different one....Just make sure....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 00:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937988#M458284</guid>
      <dc:creator>zac192000</dc:creator>
      <dc:date>2012-03-12T00:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Static VLAN NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937989#M458286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NAT-Control is not enabled&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 16:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-static-vlan-nat/m-p/1937989#M458286</guid>
      <dc:creator>DavidReisner</dc:creator>
      <dc:date>2012-03-19T16:44:54Z</dc:date>
    </item>
  </channel>
</rss>

