<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Little Issue with NATing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704968#M534640</link>
    <description>&lt;P&gt;Kindly help me with this scenario. &lt;/P&gt;&lt;P&gt;On my ASA fiewall, I had allowed direct translation to other Networks, using Access List to filter.&lt;/P&gt;&lt;P&gt;Now I have been required to use NAT to reach some specific hosts on other Networks&lt;/P&gt;&lt;P&gt;I want to use a particular Public IP address (not tied to an interface) for this purpose, (that is many-to-one mapping).&lt;/P&gt;&lt;P&gt;But two issues always result when i try to do this.&lt;/P&gt;&lt;P&gt;1. Each time I map another network to this same single IP Address, it tells me there is NAT pool overlap.&lt;/P&gt;&lt;P&gt;([WARNING] nat (inside,outside) after-auto 1 source dynamic Network_Team NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;Pool (172.20.20.52) overlap with existing pool.)&lt;/P&gt;&lt;P&gt;2. Each time I apply the configurations, the previous internal networks that have been working fine, through the direct translation would stop accessing the outside Network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I make the internal Network to be able to access the Outside Network through the direct translation and through the NAT Rule when required, and also be able to map multiple internal networks to the same single IP address without overlapping warning?&lt;BR /&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are some of the errors I receive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic Network_Team NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;&lt;P&gt;[OK] no nat after-auto 1&lt;/P&gt;&lt;P&gt;[OK] object-group network DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt;[OK] network-object object Application_Team&lt;/P&gt;&lt;P&gt;[OK] network-object object Network_Team&lt;/P&gt;&lt;P&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic DM_INLINE_NETWORK_3 NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;&lt;P&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic Network_Team NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[OK] no nat after-auto 1&lt;BR /&gt;[OK] object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;[OK] network-object object Application_Team&lt;BR /&gt;[OK] network-object object Network_Team&lt;BR /&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic DM_INLINE_NETWORK_3 NAT_For_Gemalto description Gemalto Servers to be accessed&lt;BR /&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:05:37 GMT</pubDate>
    <dc:creator>sly007</dc:creator>
    <dc:date>2019-03-11T21:05:37Z</dc:date>
    <item>
      <title>Little Issue with NATing</title>
      <link>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704968#M534640</link>
      <description>&lt;P&gt;Kindly help me with this scenario. &lt;/P&gt;&lt;P&gt;On my ASA fiewall, I had allowed direct translation to other Networks, using Access List to filter.&lt;/P&gt;&lt;P&gt;Now I have been required to use NAT to reach some specific hosts on other Networks&lt;/P&gt;&lt;P&gt;I want to use a particular Public IP address (not tied to an interface) for this purpose, (that is many-to-one mapping).&lt;/P&gt;&lt;P&gt;But two issues always result when i try to do this.&lt;/P&gt;&lt;P&gt;1. Each time I map another network to this same single IP Address, it tells me there is NAT pool overlap.&lt;/P&gt;&lt;P&gt;([WARNING] nat (inside,outside) after-auto 1 source dynamic Network_Team NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;Pool (172.20.20.52) overlap with existing pool.)&lt;/P&gt;&lt;P&gt;2. Each time I apply the configurations, the previous internal networks that have been working fine, through the direct translation would stop accessing the outside Network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I make the internal Network to be able to access the Outside Network through the direct translation and through the NAT Rule when required, and also be able to map multiple internal networks to the same single IP address without overlapping warning?&lt;BR /&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are some of the errors I receive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic Network_Team NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;&lt;P&gt;[OK] no nat after-auto 1&lt;/P&gt;&lt;P&gt;[OK] object-group network DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt;[OK] network-object object Application_Team&lt;/P&gt;&lt;P&gt;[OK] network-object object Network_Team&lt;/P&gt;&lt;P&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic DM_INLINE_NETWORK_3 NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;&lt;P&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic Network_Team NAT_For_Gemalto description Gemalto Servers to be accessed&lt;/P&gt;&lt;P&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[OK] no nat after-auto 1&lt;BR /&gt;[OK] object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;[OK] network-object object Application_Team&lt;BR /&gt;[OK] network-object object Network_Team&lt;BR /&gt;[WARNING] nat (inside,outside) after-auto 1 source dynamic DM_INLINE_NETWORK_3 NAT_For_Gemalto description Gemalto Servers to be accessed&lt;BR /&gt;&amp;nbsp; Pool (172.20.20.52) overlap with existing pool.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704968#M534640</guid>
      <dc:creator>sly007</dc:creator>
      <dc:date>2019-03-11T21:05:37Z</dc:date>
    </item>
    <item>
      <title>Little Issue with NATing</title>
      <link>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704969#M534642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Policy based nat - using access-lists defined by source/destination would be a good place to start.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/prod_configuration_examples_list.html"&gt;http://www.cisco.com/en/US/products/ps6120/prod_configuration_examples_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 14:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704969#M534642</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2011-07-29T14:04:05Z</dc:date>
    </item>
    <item>
      <title>Little Issue with NATing</title>
      <link>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704970#M534645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Does ASA 8.4.1 support policy-based NATing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 16:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704970#M534645</guid>
      <dc:creator>sly007</dc:creator>
      <dc:date>2011-07-29T16:32:08Z</dc:date>
    </item>
    <item>
      <title>Little Issue with NATing</title>
      <link>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704971#M534648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sly007,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On this version you got to use twice Nat, On this you are going to nat a source IP to a Mapped IP regarding of the destination, And the destination could be natted if you want it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link where you will find how to set it up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/security/asa/asa84/configuration/guide/nat_rules.html"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa84/configuration/guide/nat_rules.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 17:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704971#M534648</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-07-29T17:14:46Z</dc:date>
    </item>
    <item>
      <title>Little Issue with NATing</title>
      <link>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704972#M534650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you Jcarvaja,&lt;/P&gt;&lt;P&gt;Attempts to launch the url returns with "Forbidden File or application"&lt;/P&gt;&lt;P&gt;Can you help please?&lt;BR /&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 22:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704972#M534650</guid>
      <dc:creator>sly007</dc:creator>
      <dc:date>2011-07-29T22:02:35Z</dc:date>
    </item>
    <item>
      <title>Little Issue with NATing</title>
      <link>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704973#M534652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Sly007&lt;/P&gt;&lt;P&gt;Try this ones :&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/partner/docs/security/asa/asa83/asdm63/configuration_guide/nat_rules.html"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa83/asdm63/configuration_guide/nat_rules.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/partner/docs/security/asa/asa83/configuration/guide/nat_rules.html"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa83/configuration/guide/nat_rules.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first one its for ASDM config and the second one using CLI&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 22:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/little-issue-with-nating/m-p/1704973#M534652</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-07-29T22:11:11Z</dc:date>
    </item>
  </channel>
</rss>

