<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Lower security to higher security interface PAT. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815582#M491650</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we have PAT with nat and global statements for source natting a traffic from Lower security interface to Higher security? If nat &amp;amp; global can't achieve this, what are the Possibilities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;merci,&lt;/P&gt;&lt;P&gt;arun&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:59:41 GMT</pubDate>
    <dc:creator>arun.mohan</dc:creator>
    <dc:date>2019-03-11T21:59:41Z</dc:date>
    <item>
      <title>Lower security to higher security interface PAT.</title>
      <link>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815582#M491650</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we have PAT with nat and global statements for source natting a traffic from Lower security interface to Higher security? If nat &amp;amp; global can't achieve this, what are the Possibilities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;merci,&lt;/P&gt;&lt;P&gt;arun&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:59:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815582#M491650</guid>
      <dc:creator>arun.mohan</dc:creator>
      <dc:date>2019-03-11T21:59:41Z</dc:date>
    </item>
    <item>
      <title>Lower security to higher security interface PAT.</title>
      <link>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815583#M491656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you can do outside nat for it, you would need to use the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2011 09:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815583#M491656</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-12-06T09:53:32Z</dc:date>
    </item>
    <item>
      <title>Lower security to higher security interface PAT.</title>
      <link>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815584#M491657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Have you tried this to be working, coz in my case the i need to have the PAT for a particular port access needs to be PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;merci,&lt;/P&gt;&lt;P&gt;arun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2011 10:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815584#M491657</guid>
      <dc:creator>arun.mohan</dc:creator>
      <dc:date>2011-12-06T10:47:18Z</dc:date>
    </item>
    <item>
      <title>Lower security to higher security interface PAT.</title>
      <link>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815585#M491660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it works fine and is a supported config, but can you elaborate on your requirement a little bit more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2011 11:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815585#M491660</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-12-06T11:04:27Z</dc:date>
    </item>
    <item>
      <title>Lower security to higher security interface PAT.</title>
      <link>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815586#M491661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; oh ok great. Here is my case i need to NAT both the source and destination from one interface to the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For flow from MPLS --&amp;gt; Inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source on MPLS n/w: 192.168.1.100(source will be all RFC 1918 subnets)&lt;/P&gt;&lt;P&gt;Destination on MPLS nw: 10.1.1.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source on Inside n/w: 172.16.1.100(All 1918 subnet sources on MPLS will need to be translated to this IP)&lt;/P&gt;&lt;P&gt;Destination on Inside n/w: 172.31.2.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Destination NAT is achieve through Static command from the higher to Lower interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this info helpfull?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;merci,&lt;/P&gt;&lt;P&gt;arun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2011 11:21:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815586#M491661</guid>
      <dc:creator>arun.mohan</dc:creator>
      <dc:date>2011-12-06T11:21:56Z</dc:date>
    </item>
    <item>
      <title>Lower security to higher security interface PAT.</title>
      <link>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815587#M491662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you specify a group of IP address(es) in a nat command, then you must perform NAT on that group of addresses when they access any lower or same security level interface; you must apply a global command with the same NAT ID on each interface, or use a static command. NAT is not required for that group when it accesses a higher security interface because to perform NAT from outside to inside you must create a separate nat command using the outside keyword. If you do apply outside NAT, then the NAT requirements preceding come into effect for that group of addresses when they access all higher security interfaces. Traffic identified by a static command is not affected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 network netmaks outside&lt;/P&gt;&lt;P&gt;global (inside) 1 ip_address&amp;nbsp;&amp;nbsp; &amp;lt;--- used for PAT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2011 12:02:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/lower-security-to-higher-security-interface-pat/m-p/1815587#M491662</guid>
      <dc:creator>svaish</dc:creator>
      <dc:date>2011-12-06T12:02:41Z</dc:date>
    </item>
  </channel>
</rss>

