<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet Setup Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747490#M496232</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. You don't have to do any port forwaring. If the ASA listens on port 443 then the router will receive the traffic on port 443 for that 1-1 IP it will send that packet right to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just allow the ACL on the router to let 443 packets destined to the ASA's translated address for inbound connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Oct 2011 16:31:35 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2011-10-08T16:31:35Z</dc:date>
    <item>
      <title>Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747485#M496227</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have simple Internet setup(see attached).the ISP provided us with one public IP address only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The objective is to have the internal users access the Internet directly without proxy.Remote access VPN is also required (using cisco VPN client).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is : how can I do the configuration of :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1- The internal user to access the Internet : shall I do the PAT on the router ? &lt;/P&gt;&lt;P&gt;&amp;nbsp; 2- Remote access VPN : If I want to do it on the firewall , can I use the only public IP I have on the as the NAT IP of the ASA (for certain VPN ports), and at the same time use this public IP for PAT ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what are the option of doing this setup?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747485#M496227</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2019-03-11T21:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747486#M496228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer both of your questions at the same time - place the router behind the firewall and connect the ISP circuit directly to the firewall outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 13:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747486#M496228</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2011-10-08T13:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747487#M496229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Yes. You can PAT everyone to the outside interface of the ASA.&lt;/P&gt;&lt;P&gt;2. Once that is done, you can provide static 1-1 NAT for the ASA's outside IP on the router to one routable available IP provided by the ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 15:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747487#M496229</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-10-08T15:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747488#M496230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys, &lt;/P&gt;&lt;P&gt;Actually putting the router behind the firewall is not an option .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok kureli, you mean to do PAT on the AsA to the outside interface (private) IP , then NAT the outside IP of the ASA to the public IP of the router. Great , now what about VPN ? Can we just use the public IP that we have used for ASA outside NAT , for VPN ? I think we have to do port forwarding or some thing ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you think&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 16:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747488#M496230</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2011-10-08T16:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747489#M496231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Why is it not an option?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 16:19:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747489#M496231</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2011-10-08T16:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747490#M496232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. You don't have to do any port forwaring. If the ASA listens on port 443 then the router will receive the traffic on port 443 for that 1-1 IP it will send that packet right to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just allow the ACL on the router to let 443 packets destined to the ASA's translated address for inbound connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 16:31:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747490#M496232</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-10-08T16:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747491#M496233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew , actually the ISP provide the router with configuration , you are right putting the firewall first will solve the issue as we can do the PAT for user Internet access and termination of the VPN directly on the ASA outside.&lt;/P&gt;&lt;P&gt;Anyway , I will suggest that to the customer and see if it is acceptable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 18:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747491#M496233</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2011-10-08T18:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747492#M496234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi kureli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this will work as you stated , then the problem is solved .&lt;/P&gt;&lt;P&gt;Have you tried it before? Do you have any sample configuration ? It will be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 18:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747492#M496234</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2011-10-08T18:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747493#M496235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it will. Many companies have a toplogy similar to yours. This is very common. Don't have any sample though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Oct 2011 21:21:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747493#M496235</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-10-08T21:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747494#M496236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kureli ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried the setup in the LAB , I tested two senarios &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Senario 1:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the router : NAT ASA outside to the Router Public IP , and PAT ASA inside Users subnet to the same public IP of the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA :&amp;nbsp; Only No NAT the inside , no PAT , only VPN remote access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Router config:&lt;/EM&gt;&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; description to-ISP&lt;/P&gt;&lt;P&gt; ip address 1.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp; description to-ASA-Outside&lt;/P&gt;&lt;P&gt; ip address 172.16.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 1.1.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp; (1.1.1.2 is a test machine on the outside)&lt;/P&gt;&lt;P&gt;ip route 10.1.0.0 255.255.0.0 172.16.1.2 (172.16.1.2 is ASA outside)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface GigabitEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static 172.16.1.2 interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 1 permit 172.16.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;ASA Config:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 172.16.1.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.1.240 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network inside-subnet &lt;/P&gt;&lt;P&gt; subnet 10.1.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network inside-subnet&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 10.1.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 172.16.1.1 1&lt;/P&gt;&lt;P&gt;route inside 10.1.0.0 255.255.0.0 10.1.1.1&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The setup looks working , also the remote access VPN.But I had to do NAT/PAT on the router not on the ASA .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Senario 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the router : only NAT ASA outside to the Router Public IP &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA :&amp;nbsp; PAT the inside subnet&amp;nbsp; to ASA outside , and VPN remote access config.\&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Router Config:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;same basic config in senario1 and :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static 172.16.1.2 interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;ASA Config:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same basic config in senario1 and :&lt;/P&gt;&lt;P&gt;object network Inside-Subnet&lt;/P&gt;&lt;P&gt; subnet 10.1.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt; description Inside-Subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; object network Inside-Subnet&lt;/P&gt;&lt;P&gt; nat (any,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This did not work , and Also the VPN did not work , I may Have basic error somewhere !!.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any hint !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Oct 2011 09:02:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747494#M496236</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2011-10-09T09:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747495#M496237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ali,&lt;/P&gt;&lt;P&gt;Sorry I missed to read this line "ISP provided us with one public IP address only" in your requirement. You cannot do static 1-1 for the ASA to the routers g0/0 address. This is incorrect. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, this is still possible but, you would have to static PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. On the ASA PAT everyone to the outside interface IP (your config looks correct)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. On the router you can do &lt;/P&gt;&lt;P&gt;ip nat inside source list 120 interface g0/0&lt;/P&gt;&lt;P&gt;access-l 120 deny tcp 172.16.1.2 eq 443 any ---&amp;gt; (so it can take the static PAT)&lt;/P&gt;&lt;P&gt;access-l 120 per ip 172.16.1.2 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. ip nat inside source static tcp 172.16.1.2 443 int g0/0 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you like to do no "nat-control" on the ASA then all the inside guys the 10.x.x.x guys will look like themselves when they arrive on the router in that case you can do the following on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a. ip nt inside source list 120 int g0/0&lt;/P&gt;&lt;P&gt;access-l 120 per ip 10.1.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;ip nat inside source list 120 int g0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b. ip nat inside source static tcp 172.16.1.2 443 int g0/0 443&lt;/P&gt;&lt;P&gt;ip route 10.1.0.0 255.255.0.0 172.16.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it is clear. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Oct 2011 13:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747495#M496237</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-10-09T13:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747496#M496239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Kureli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ASA 8.3 , disabling nat-control is not an option .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will&amp;nbsp; try the setup again , and let you know ..I appreciate your great help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ali&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 05:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747496#M496239</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2011-10-10T05:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Setup Help</title>
      <link>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747497#M496240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hureli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just recap , The customer has no problem not to NAT the local user on the ASA , we can use identity NAT on ASA for them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the diagram , it shows the setup with the configuration , let me know please how it looks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 06:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-setup-help/m-p/1747497#M496240</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2011-10-10T06:40:21Z</dc:date>
    </item>
  </channel>
</rss>

