<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA_NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007519#M4889</link>
    <description>Hi Marvin.&lt;BR /&gt;&lt;BR /&gt;yes we are using Software Version 8.2(5)59. Can u please guide in the NAT statement which is the private address and which is the public address in old syntax.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Sathish</description>
    <pubDate>Tue, 07 Jan 2020 12:36:09 GMT</pubDate>
    <dc:creator>SathishkumarSaravanan0348</dc:creator>
    <dc:date>2020-01-07T12:36:09Z</dc:date>
    <item>
      <title>ASA_NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007500#M4887</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had given an task to implement the route in&amp;nbsp; Cisco ASA-55x0 device as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;static (Data-DFS,inside) 10.176.92.66 10.176.25.218 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;route Data-DFS 10.176.92.66 255.255.255.255 10.248.161.1 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this when I given question mark after parenthesis it showed as the global or mapped address and followed by the real host (10.176.25.218).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I assume it is similar to the static NAT which we perform in the router. (10.176.92.66- Inside global address,&amp;nbsp;10.176.25.218- Inside local address)&lt;/P&gt;&lt;P&gt;2. Below there is an route pointing towards the next hop 10.248.161.1. I need to find where the host is located. In cisco router or L3 switch I use command sh ip route to find the connected subnet.&lt;/P&gt;&lt;P&gt;In firewall what is an alternative method to locate the IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sathish&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:49:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007500#M4887</guid>
      <dc:creator>SathishkumarSaravanan0348</dc:creator>
      <dc:date>2020-02-21T17:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA_NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007516#M4888</link>
      <description>&lt;P&gt;Are you running ASA code version &amp;lt;8.3? If so you use an older nat command syntax.&lt;/P&gt;
&lt;P&gt;To see routes on ASA, simply use "show route".&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 12:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007516#M4888</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-01-07T12:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA_NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007519#M4889</link>
      <description>Hi Marvin.&lt;BR /&gt;&lt;BR /&gt;yes we are using Software Version 8.2(5)59. Can u please guide in the NAT statement which is the private address and which is the public address in old syntax.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Sathish</description>
      <pubDate>Tue, 07 Jan 2020 12:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007519#M4889</guid>
      <dc:creator>SathishkumarSaravanan0348</dc:creator>
      <dc:date>2020-01-07T12:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA_NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007569#M4890</link>
      <description>&lt;P&gt;In the old syntax, the mapped IP (public address) comes first, followed by the real IP (private address).&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;To configure regular static NAT, enter the following command:&lt;/P&gt;
&lt;P&gt;&lt;A target="_blank" name="wp1079835"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;SECTION&gt;
&lt;DIV class="tableContainer"&gt;
&lt;TABLE id="wp1079843table1079841" border="1" width="80%" cellspacing="0" cellpadding="2"&gt;&lt;CAPTION&gt;&amp;nbsp;&lt;/CAPTION&gt;
&lt;TBODY&gt;
&lt;TR align="left" valign="bottom"&gt;
&lt;TH scope="col"&gt;&lt;A target="_blank" name="wp1079843"&gt;&lt;/A&gt;
&lt;SECTION class="pCH1_CellHead1"&gt;Command&lt;/SECTION&gt;
&lt;/TH&gt;
&lt;TH scope="col"&gt;&lt;A target="_blank" name="wp1079845"&gt;&lt;/A&gt;
&lt;SECTION class="pCH1_CellHead1"&gt;Purpose&lt;/SECTION&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD&gt;&lt;A target="_blank" name="wp1079848"&gt;&lt;/A&gt;
&lt;P class="pExT_ExampleTable"&gt;&lt;STRONG class="cKeyword"&gt;static&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;EM class="cArgument"&gt;real_interface,mapped_interface&lt;/EM&gt;) {&lt;EM class="cArgument"&gt;mapped_ip&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cKeyword"&gt;interface&lt;/STRONG&gt;}&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;real_ip&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[&lt;STRONG class="cKeyword"&gt;netmask&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;mask&lt;/EM&gt;][&lt;STRONG class="cKeyword"&gt;dns&lt;/STRONG&gt;] [&lt;STRONG class="cKeyword"&gt;norandomseq&lt;/STRONG&gt;] [[&lt;STRONG class="cKeyword"&gt;tcp&lt;/STRONG&gt;]&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;tcp_max_conns&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[&lt;EM class="cArgument"&gt;emb_limit&lt;/EM&gt;]] [&lt;STRONG class="cKeyword"&gt;udp&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;udp_max_conns&lt;/EM&gt;]&lt;/P&gt;
&lt;A target="_blank" name="wp1080133"&gt;&lt;/A&gt;
&lt;P class="pExT_ExampleTable"&gt;&amp;nbsp;&lt;/P&gt;
&lt;A target="_blank" name="wp1079849"&gt;&lt;/A&gt;
&lt;P class="pExT_ExampleTable"&gt;&lt;STRONG class="cBold"&gt;Example&lt;/STRONG&gt;:&lt;/P&gt;
&lt;A target="_blank" name="wp1085114"&gt;&lt;/A&gt;
&lt;SECTION class="pEx1_Example1"&gt;
&lt;PRE&gt;hostname(config)# static (inside,outside) 
209.165.201.12 10.1.1.3 netmask 
255.255.255.255
&lt;/PRE&gt;
&lt;/SECTION&gt;
&lt;A target="_blank" name="wp1085109"&gt;&lt;/A&gt;
&lt;P class="pExT_ExampleTable"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;A target="_blank" name="wp1079855"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;Configures a persistent one-to-one address translation rule by mapping a real IP address to a mapped IP address.&lt;/P&gt;
&lt;A target="_blank" name="wp1084963"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cEmphasis"&gt;real_ifc&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;argument specifies the name of the interface connected to the real IP address network.&lt;/P&gt;
&lt;A target="_blank" name="wp1084964"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cEmphasis"&gt;mapped_ifc&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;argument specifies the name of the interface connected to the mapped IP address network.&lt;/P&gt;
&lt;A target="_blank" name="wp1084968"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cEmphasis"&gt;mapped_ip&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;argument specifies the address to which the real address is translated.&lt;/P&gt;
&lt;A target="_blank" name="wp1084969"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;interface&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;keyword uses the interface IP address as the mapped address. Use this keyword if you want to use the interface address, but the address is dynamically assigned using DHCP.&lt;/P&gt;
&lt;A target="_blank" name="wp1084982"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cEmphasis"&gt;real_ip&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;specifies the real address that you want to translate.&lt;/P&gt;
&lt;A target="_blank" name="wp1085030"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;netmask&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cEmphasis"&gt;mask&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;specifies the subnet mask for the real and mapped addresses. For single hosts, use 255.255.255.255. If you do not enter a mask, then the default mask for the IP address class is used, with one exception. If a host-bit is non-zero after masking, a host mask of 255.255.255.255 is used. If you use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;access-list&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;keyword instead of the real_ip, then the subnet mask used in the access list is also used for the mapped_ip.&lt;/P&gt;
&lt;A target="_blank" name="wp1085049"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;dns&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option rewrites the A record, or address record, in DNS replies that match this static. For DNS replies traversing from a mapped interface to any other interface, the A record is rewritten from the mapped value to the real value. Inversely, for DNS replies traversing from any interface to a mapped interface, the A record is rewritten from the real value to the mapped value.&lt;/P&gt;
&lt;A target="_blank" name="wp1085050"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;norandomseq&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;disables TCP ISN randomization protection.&lt;/P&gt;
&lt;A target="_blank" name="wp1085051"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;tcp&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cEmphasis"&gt;tcp_max_cons&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option specifies the maximum number of simultaneous TCP connections allowed to the local-host. (See the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cCN_CmdName"&gt;local-host&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command). (Idle connections are closed after the idle timeout specified by the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;timeout conn&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command.)&lt;/P&gt;
&lt;A target="_blank" name="wp1085052"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;EM class="cEmphasis"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;emb_limit&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is the maximum number of embryonic connections per host.&lt;/P&gt;
&lt;A target="_blank" name="wp1086617"&gt;&lt;/A&gt;
&lt;P class="pNT_NoteTable"&gt;&lt;STRONG&gt;Note&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="" width="1" height="2" /&gt;An embryonic limit applied using static NAT is applied to all connections to or from the real IP address, and not just connections between the specified interfaces. To apply limits to specific flows, see the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/conns_connlimits.html#wpxref78658" target="_blank" rel="noopener"&gt;"Configuring Connection Limits and Timeouts" section&lt;/A&gt;.&lt;/P&gt;
&lt;A target="_blank" name="wp1085053"&gt;&lt;/A&gt;
&lt;P class="pB1_Body1"&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;udp&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="cEmphasis"&gt;tcp_max_cons&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option specifies the maximum number of simultaneous UDP connections allowed to the local-host. (See the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cCN_CmdName"&gt;local-host&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command.) (Idle connections are closed after the idle timeout specified by the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cCN_CmdName"&gt;timeout conn&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command.)&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/nat_static.html#wp1080043" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/nat_static.html#wp1080043&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 13:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat/m-p/4007569#M4890</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-01-07T13:50:52Z</dc:date>
    </item>
  </channel>
</rss>

