<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DMZ internet access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743908#M530719</link>
    <description>&lt;P&gt;Hi I have the following config on a ASA&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still cannot reach the internet from the DMZ2. Just worndering if the following config when applied can help or conflict with the existing one. &lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;nat (dmz2,outside) dynamic interface&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:25:27 GMT</pubDate>
    <dc:creator>sindan</dc:creator>
    <dc:date>2019-03-11T21:25:27Z</dc:date>
    <item>
      <title>DMZ internet access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743908#M530719</link>
      <description>&lt;P&gt;Hi I have the following config on a ASA&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still cannot reach the internet from the DMZ2. Just worndering if the following config when applied can help or conflict with the existing one. &lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;nat (dmz2,outside) dynamic interface&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743908#M530719</guid>
      <dc:creator>sindan</dc:creator>
      <dc:date>2019-03-11T21:25:27Z</dc:date>
    </item>
    <item>
      <title>DMZ internet access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743909#M530721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure but I guess you got it upside down, you would need the following config to allow access to the internet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;nat (dmz2,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It woudl not conflict with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide me the following outputs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run access-group&lt;/P&gt;&lt;P&gt;show run nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suggestion:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the following,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (dmz2,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot use same object for two different auto-nat statements, if you do so, it would replace the first nat statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 18:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743909#M530721</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-15T18:39:21Z</dc:date>
    </item>
    <item>
      <title>DMZ internet access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743910#M530723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA# show run access-group&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group dmz_access_in in interface dmz&lt;/P&gt;&lt;P&gt;ASA#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA# sh run nat&lt;/P&gt;&lt;P&gt;object network JCV-EX1&lt;/P&gt;&lt;P&gt;nat (inside,outside) static obj2-x.x.x.99&lt;/P&gt;&lt;P&gt;object network JCV&lt;/P&gt;&lt;P&gt;nat (dmz,outside) static obj-x.x.x.101&lt;/P&gt;&lt;P&gt;object network default-pat&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network JCVTS&lt;/P&gt;&lt;P&gt;nat (any,any) static obj-x.x.x.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;still not sure what config is needed in order for DMZ2 to access the internet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 18:58:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743910#M530723</guid>
      <dc:creator>sindan</dc:creator>
      <dc:date>2011-09-15T18:58:32Z</dc:date>
    </item>
    <item>
      <title>DMZ internet access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743911#M530726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the config that you would need:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network&lt;STRONG&gt; default-pat-test&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (dmz2,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 19:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743911#M530726</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-15T19:02:43Z</dc:date>
    </item>
    <item>
      <title>DMZ internet access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743912#M530728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi..... did that work for you??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 22:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-internet-access/m-p/1743912#M530728</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-15T22:19:34Z</dc:date>
    </item>
  </channel>
</rss>

