<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Object-Group in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/object-group/m-p/1870665#M490144</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good to hear from you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today while I was doing some labs recreations, I could confirm that now object-groups are supported for the nat statements as well as the ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I will response to your first question on this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question1 :I m grouping {object network} to one object group for the Dynamic&amp;nbsp; PAT, But there is no option of dynamic after Nat (inside,outside) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;Answer 1: The correct syntax would be &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -nat (inside,outside) source dynamic outside-interface interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 2:&lt;/P&gt;&lt;P&gt;according to ur example what this command will do :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat (inside,outside) source dynamic 1.1.1.1-host 2.2.2.2-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This nat statement will nat with pat (dynamic) all the object network 1.1.1.1-host to the outside object network 2.2.2.2-host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps! any other question let me know,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts.&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Dec 2011 18:07:53 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2011-12-26T18:07:53Z</dc:date>
    <item>
      <title>Object-Group</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/1870662#M490139</link>
      <description>&lt;P&gt;Hello Dears&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m grouping {object network} to one object group for the Dynamic PAT, But there is no option of dynamic after Nat (inside,outside) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh run object-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network outside-interface&lt;/P&gt;&lt;P&gt; network-object object obj-20.20.20.0&lt;/P&gt;&lt;P&gt; network-object object obj-30-30-30-30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# object-group network outside-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config-network-object-group)# nat (inside,outside) ?&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;1-2147483647&amp;gt;&amp;nbsp; Position of NAT rule within before auto section&lt;/P&gt;&lt;P&gt;&amp;nbsp; after-auto&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Insert NAT rule after auto section&lt;/P&gt;&lt;P&gt;&amp;nbsp; source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source NAT parameters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/1870662#M490139</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2019-03-11T22:06:26Z</dc:date>
    </item>
    <item>
      <title>Object-Group</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/1870663#M490142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object-groups will be used for the ACLs, on the nat you cannot use them, you can use object networks (host,subnet, or range of ip addresses) and object services(Protocol, port)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The syntax will be like this:&lt;/P&gt;&lt;P&gt;object network 1.1.1.1-host&lt;/P&gt;&lt;P&gt;host 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network 2.2.2.2-host&lt;/P&gt;&lt;P&gt;host 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat (inside,outside) source dynamic 1.1.1.1-host 2.2.2.2-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 18:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/1870663#M490142</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-25T18:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Object-Group</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/1870664#M490143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;according to ur example what this command will do :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat (inside,outside) source dynamic 1.1.1.1-host 2.2.2.2-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And please find the attached file, Check the section { NAT &amp;amp; Interface PAT with additional PAT together}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think somebody has share wrong information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 19:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/1870664#M490143</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-25T19:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Object-Group</title>
      <link>https://community.cisco.com/t5/network-security/object-group/m-p/1870665#M490144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good to hear from you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today while I was doing some labs recreations, I could confirm that now object-groups are supported for the nat statements as well as the ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I will response to your first question on this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question1 :I m grouping {object network} to one object group for the Dynamic&amp;nbsp; PAT, But there is no option of dynamic after Nat (inside,outside) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;Answer 1: The correct syntax would be &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -nat (inside,outside) source dynamic outside-interface interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 2:&lt;/P&gt;&lt;P&gt;according to ur example what this command will do :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat (inside,outside) source dynamic 1.1.1.1-host 2.2.2.2-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This nat statement will nat with pat (dynamic) all the object network 1.1.1.1-host to the outside object network 2.2.2.2-host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps! any other question let me know,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts.&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Dec 2011 18:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/object-group/m-p/1870665#M490144</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-26T18:07:53Z</dc:date>
    </item>
  </channel>
</rss>

