<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static nat versus dynamic nat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-versus-dynamic-nat/m-p/1734403#M496343</link>
    <description>&lt;P&gt;we are running 8.4(2) on the asa with the below configuration&lt;/P&gt;&lt;P&gt;we basically have a static for .7 on .25 and a nat for .7 for port direction&lt;/P&gt;&lt;P&gt;with manual nat that takes precedense over auto nat within the object group am I correct that I dont&lt;BR /&gt;need the dynamic statement and that its redundant?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network obj-10.X.0.25-02&lt;BR /&gt;host 10.X.0.25&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network obj-10.X.0.25&lt;BR /&gt;nat (any,INSIDE) static X.X.X.7 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.X.0.25-01&lt;BR /&gt;nat (INSIDE,OUTSIDE) static X.X.X.7 service tcp smtp smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.X.0.25-02&lt;BR /&gt;nat (INSIDE,OUTSIDE) dynamic X.X.X.7&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:34:50 GMT</pubDate>
    <dc:creator>JMCNEL</dc:creator>
    <dc:date>2019-03-11T21:34:50Z</dc:date>
    <item>
      <title>static nat versus dynamic nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-versus-dynamic-nat/m-p/1734403#M496343</link>
      <description>&lt;P&gt;we are running 8.4(2) on the asa with the below configuration&lt;/P&gt;&lt;P&gt;we basically have a static for .7 on .25 and a nat for .7 for port direction&lt;/P&gt;&lt;P&gt;with manual nat that takes precedense over auto nat within the object group am I correct that I dont&lt;BR /&gt;need the dynamic statement and that its redundant?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network obj-10.X.0.25-02&lt;BR /&gt;host 10.X.0.25&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network obj-10.X.0.25&lt;BR /&gt;nat (any,INSIDE) static X.X.X.7 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.X.0.25-01&lt;BR /&gt;nat (INSIDE,OUTSIDE) static X.X.X.7 service tcp smtp smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.X.0.25-02&lt;BR /&gt;nat (INSIDE,OUTSIDE) dynamic X.X.X.7&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-versus-dynamic-nat/m-p/1734403#M496343</guid>
      <dc:creator>JMCNEL</dc:creator>
      <dc:date>2019-03-11T21:34:50Z</dc:date>
    </item>
    <item>
      <title>static nat versus dynamic nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-versus-dynamic-nat/m-p/1734404#M496344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes thats right manual nat always takes precedence over auto nat. But I am not sure, the ones that you have pasted arer all auto nats.None of them is manual nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want all of them to work then keep the nats in this order:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.X.0.25-01&lt;BR /&gt;nat (INSIDE,OUTSIDE) static X.X.X.7 service tcp smtp smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.X.0.25-02&lt;BR /&gt;nat (INSIDE,OUTSIDE) dynamic X.X.X.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.X.0.25&lt;/P&gt;&lt;P&gt;nat (any,INSIDE) static X.X.X.7 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The idea is to keep the most specific ones on the top and general one on the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 15:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-versus-dynamic-nat/m-p/1734404#M496344</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-06T15:40:29Z</dc:date>
    </item>
  </channel>
</rss>

