<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Natting of subnet ip address exist over wan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862859#M490308</link>
    <description>&lt;P&gt;I have branch office having subnet 172.26.48.0/22 one ip from this subnet say 172.26.48.100 assigned toa server . now our erequirement to access this &lt;/P&gt;&lt;P&gt;server from outside mean from internet . tis branch office is coonected throuth leased line to main office. now main office has firewall and loacl subnet&lt;/P&gt;&lt;P&gt;in which server are there and natted to access over internet . we try to make it possible we got ping response of outised also but latency get stuck that&lt;/P&gt;&lt;P&gt;firewall looking to be in hang mode latency around 900 ms if natting is done otherwise 250-300 ms. what can we do , any alternat approach suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dig. attachement is there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rajat&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:05:49 GMT</pubDate>
    <dc:creator>r.kukreja</dc:creator>
    <dc:date>2019-03-11T22:05:49Z</dc:date>
    <item>
      <title>Natting of subnet ip address exist over wan</title>
      <link>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862859#M490308</link>
      <description>&lt;P&gt;I have branch office having subnet 172.26.48.0/22 one ip from this subnet say 172.26.48.100 assigned toa server . now our erequirement to access this &lt;/P&gt;&lt;P&gt;server from outside mean from internet . tis branch office is coonected throuth leased line to main office. now main office has firewall and loacl subnet&lt;/P&gt;&lt;P&gt;in which server are there and natted to access over internet . we try to make it possible we got ping response of outised also but latency get stuck that&lt;/P&gt;&lt;P&gt;firewall looking to be in hang mode latency around 900 ms if natting is done otherwise 250-300 ms. what can we do , any alternat approach suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dig. attachement is there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rajat&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:05:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862859#M490308</guid>
      <dc:creator>r.kukreja</dc:creator>
      <dc:date>2019-03-11T22:05:49Z</dc:date>
    </item>
    <item>
      <title>Natting of subnet ip address exist over wan</title>
      <link>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862860#M490309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Do you mean to say once nat is not there you get 250-300 ms from HQ to branch? If you firewall is oversubcribed then i would say it should add higher latency.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should look for a trace from outside and also CPU/ Memory utalization of firewall to check where extra latancy is getting added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 07:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862860#M490309</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-12-23T07:40:36Z</dc:date>
    </item>
    <item>
      <title>Natting of subnet ip address exist over wan</title>
      <link>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862861#M490310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; NO i mean we get normal response 250-300 ms HQ to outside link ping responsc of 4.2.2.2 . no branch included . if we nat branch ip mentioned above sudenly latency get high while pinging 4.2.2.2 so firewall does not behave normally in this case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;howwver if we remove natting command from firewall still we get latemcy after rebooting only it comes normal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;second it is possible or practical to nat ip of branch office in headquarter firewall. it is suggested by cisco ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rajat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 08:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862861#M490310</guid>
      <dc:creator>r.kukreja</dc:creator>
      <dc:date>2011-12-23T08:18:14Z</dc:date>
    </item>
    <item>
      <title>Natting of subnet ip address exist over wan</title>
      <link>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862862#M490311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; What firewall is it ?and what kind of behaviour do you seee HIGH CPU ? any logs in firewall ? I dont think just adding one more nat rule shuld cause any problem to your internet connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes thats all depend upon your network topology however no harm doing nat on HQ FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 08:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862862#M490311</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-12-23T08:23:10Z</dc:date>
    </item>
    <item>
      <title>Natting of subnet ip address exist over wan</title>
      <link>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862863#M490312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; my firewall mode 5510 version 7.0 iwill test once user are out and take logs and cpu processess output then post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your kind support&lt;/P&gt;&lt;P&gt;Rajat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 11:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natting-of-subnet-ip-address-exist-over-wan/m-p/1862863#M490312</guid>
      <dc:creator>r.kukreja</dc:creator>
      <dc:date>2011-12-23T11:11:19Z</dc:date>
    </item>
  </channel>
</rss>

