<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity NAT - nat 0 with PIX firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/identity-nat-nat-0-with-pix-firewall/m-p/506516#M499794</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The difference is that your internal hosts are still protected by the firewall's adaptive security algorithm. Traffic from outside to inside is allowed only if there is a matching xlate entry. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know packets will not flow without you using some form of NAT or static statements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Jul 2006 18:09:47 GMT</pubDate>
    <dc:creator>atif.awan</dc:creator>
    <dc:date>2006-07-03T18:09:47Z</dc:date>
    <item>
      <title>Identity NAT - nat 0 with PIX firewall</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-nat-0-with-pix-firewall/m-p/506515#M499793</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I uderstand nat 0 doesn't translate anything, the same IP appears on both sides of the firewall. This could be the case if we are having registered IP addresses on the inside and outside.&lt;/P&gt;&lt;P&gt;If the packets just flow from one interface to another what the difference it makes from the simple routing then? Wouldn't the packets flow without any nat 0 statements?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-nat-0-with-pix-firewall/m-p/506515#M499793</guid>
      <dc:creator>augnevenok</dc:creator>
      <dc:date>2020-02-21T09:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT - nat 0 with PIX firewall</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-nat-0-with-pix-firewall/m-p/506516#M499794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The difference is that your internal hosts are still protected by the firewall's adaptive security algorithm. Traffic from outside to inside is allowed only if there is a matching xlate entry. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know packets will not flow without you using some form of NAT or static statements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2006 18:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-nat-0-with-pix-firewall/m-p/506516#M499794</guid>
      <dc:creator>atif.awan</dc:creator>
      <dc:date>2006-07-03T18:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT - nat 0 with PIX firewall</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-nat-0-with-pix-firewall/m-p/506517#M499795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a few lines from my PIX config:&lt;/P&gt;&lt;P&gt;-------------------------------------&lt;/P&gt;&lt;P&gt;;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 202.90.110.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 10.0.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 202.90.110.2 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_out in interface outside&lt;/P&gt;&lt;P&gt;access-list acl_out permit ip any interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A host (202.90.110.2) from the outside network is able to access an FTP server on the inside network. There is not NAT at all and packets flow. Is this correct?&lt;/P&gt;&lt;P&gt;Then I removed route statement and still able to access inside FTP from outside host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please someone cooment or explain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another question. Do I need to save configuration  and then maybe restart the PIX for config to become effective? In the above example I just removed nat and static statements not saving config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jul 2006 06:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-nat-0-with-pix-firewall/m-p/506517#M499795</guid>
      <dc:creator>augnevenok</dc:creator>
      <dc:date>2006-07-04T06:18:38Z</dc:date>
    </item>
  </channel>
</rss>

