<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic v8.3 and above &amp; NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805618#M496473</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For Static nat:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(inside, outside) 192.168.1.5 192.168.1.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;becomes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_test&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 192.168.1.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static obj_test obj-test&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------------&amp;gt; Manual nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_test&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 192.168.1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (inside,outside) static 192.168.1.5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------------&amp;gt; Auto nat (this is done inside the object only)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat exemption:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list exempt1 permit ip 192.168.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;nat(inside) 0 access-list exempt1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;becomes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_test1&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,any) source static obj_test1 obj_test1 destination static obj_any obj_any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I was able to clear your doubts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Oct 2011 16:13:22 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-10-05T16:13:22Z</dc:date>
    <item>
      <title>v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805613#M496457</link>
      <description>&lt;P&gt;I have looked in the books I have (Cisco ASA, PIX and FWSM; ASA 8.0) and googled a good bit but can't seem to find any specific mention of how to do NAT exemption with v8.4. It seems NAT exemption (NAT 0 access-list) was deprecated. Using ASDM, there's no corresponding menu item for this that is obvious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have public addresses inside the ASA and want to allow in/outbound connections using these IP's without NAT. The ASA is a 5550.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805613#M496457</guid>
      <dc:creator>Bob MacLean</dc:creator>
      <dc:date>2019-03-11T21:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805614#M496460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can refer to this doc, this might make it simple for you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any confusions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 15:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805614#M496460</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-05T15:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805615#M496463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, you would find good docs on the support forum as well, like these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/docs/DOC-9129"&gt;https://supportforums.cisco.com/docs/DOC-9129#comment-3934&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Video:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12324"&gt;https://supportforums.cisco.com/docs/DOC-12324&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 15:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805615#M496463</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-05T15:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805616#M496467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The pdf is a good document to have so thanks for putting it up, but there's nothing in it on NAT exemption. I have seen all these documents and none discuss NAT exemption (NAT 0 access-list).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically, how do you move from either of these 2 methods used to avoid NAT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(inside, outside) 192.168.1.5 192.168.1.5 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(note: the IP's involved here are actually public IP's, not private)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list exempt1 permit ip 192.168.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;nat(inside) 0 access-list exempt1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to 8.3 or higher NAT notation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 15:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805616#M496467</guid>
      <dc:creator>Bob MacLean</dc:creator>
      <dc:date>2011-10-05T15:54:29Z</dc:date>
    </item>
    <item>
      <title>v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805617#M496470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then, this might be what you are looking for:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-11639"&gt;https://supportforums.cisco.com/docs/DOC-11639&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 16:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805617#M496470</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-05T16:00:09Z</dc:date>
    </item>
    <item>
      <title>v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805618#M496473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For Static nat:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(inside, outside) 192.168.1.5 192.168.1.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;becomes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_test&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 192.168.1.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static obj_test obj-test&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------------&amp;gt; Manual nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_test&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 192.168.1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (inside,outside) static 192.168.1.5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------------&amp;gt; Auto nat (this is done inside the object only)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nat exemption:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list exempt1 permit ip 192.168.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;nat(inside) 0 access-list exempt1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;becomes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_test1&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,any) source static obj_test1 obj_test1 destination static obj_any obj_any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I was able to clear your doubts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 16:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805618#M496473</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-05T16:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805619#M496476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks. I have to add my vote to those who say this new syntax in 8.3+ is not great but so what, we have to adapt to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 16:41:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805619#M496476</guid>
      <dc:creator>Bob MacLean</dc:creator>
      <dc:date>2011-10-05T16:41:27Z</dc:date>
    </item>
    <item>
      <title>v8.3 and above &amp; NAT</title>
      <link>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805620#M496477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, thanks &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; I work with the 8.3 nat day in and day out and I feel it is far better than the earlier ones, it seems more logical, although yes there might be some things like creating objects but overall its a thumbs up from me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 16:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v8-3-and-above-nat/m-p/1805620#M496477</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-05T16:44:49Z</dc:date>
    </item>
  </channel>
</rss>

