<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX without address translation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434835#M534682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nat (outside) 0 is not needed.&lt;/P&gt;&lt;P&gt;with the other two nat () 0 statements, you are good to go&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 30 Jul 2005 21:05:41 GMT</pubDate>
    <dc:creator>nkhawaja</dc:creator>
    <dc:date>2005-07-30T21:05:41Z</dc:date>
    <item>
      <title>PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434834#M534681</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have PIX -ver. OS is 6.3(3)- with 3 interfaces: outside, inside and dmz.&lt;/P&gt;&lt;P&gt;PIX will be used in intranet without address translation. IP Address must be visible from any interface to any interface, no address translation is required.&lt;/P&gt;&lt;P&gt;For examlpe: Users will by on interface Ouside with IP range 10.0.0.0/8, servers will be on interace Inside (192.168.1.0/24) and other devices will be on interface dmz (172.16.0.0/16).&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;So I created access-list: &lt;/P&gt;&lt;P&gt;access-list all-ip-packet permit ip any any &lt;/P&gt;&lt;P&gt;and use command nat 0:&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list all-ip-packet &lt;/P&gt;&lt;P&gt;nat (dmz) 0 access-list all-ip-packet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question is:&lt;/P&gt;&lt;P&gt;Is it necessary to add row&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list all-ip-packet &lt;/P&gt;&lt;P&gt; or is possible to communicate from outside to inside (users to server)without this row?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434834#M534681</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2020-02-21T08:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434835#M534682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nat (outside) 0 is not needed.&lt;/P&gt;&lt;P&gt;with the other two nat () 0 statements, you are good to go&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Jul 2005 21:05:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434835#M534682</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-07-30T21:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434836#M534684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;I tried it, it works but I do not understand why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When packet goes from inside, PIX has this statement:&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list all-ip-packet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When packet goes from dmz, PIX has this statement:&lt;/P&gt;&lt;P&gt;nat (dmz) 0 access-list all-ip-packet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When packet goes from outside, PIX has no statement.&lt;/P&gt;&lt;P&gt;But It works. Can you explain it, please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Jul 2005 04:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434836#M534684</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2005-07-31T04:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434837#M534687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there anybody who understanded address translation using "nat () 0 access-list" or everybody is on holiday ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2005 10:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434837#M534687</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2005-08-01T10:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434838#M534692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;see this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/19.html" target="_blank"&gt;http://www.cisco.com/warp/public/110/19.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2005 15:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434838#M534692</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-08-01T15:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434839#M534696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;but this document does not respond my question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2005 05:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434839#M534696</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2005-08-02T05:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434840#M534700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure what you are questioning, the communication or the translation. Communication between the different interfaces has more to do with the security levels than the NAT statements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2005 17:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434840#M534700</guid>
      <dc:creator>jeff.carr</dc:creator>
      <dc:date>2005-08-02T17:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434841#M534701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One condition for working ASA is a address translation, and it must be set for case when address translation is not needed too. So It was created NAT exemption, I think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For exapmle,&lt;/P&gt;&lt;P&gt;When I put access-list on outside interface "permit ip any any", I must set a address translation "nat 0 access list" if I want to communicate from outiside to inside however real address translation not doing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;when I have &lt;/P&gt;&lt;P&gt;nat 0 (inside) access-list all_ip&lt;/P&gt;&lt;P&gt;nat 0 (dmz) access-list all_ip&lt;/P&gt;&lt;P&gt;access-list all_ip permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and communication start on outside interface. Which row do not translate addreses of inbound packets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would wait a row &lt;/P&gt;&lt;P&gt;nat 0 (outside) access-list all_ip&lt;/P&gt;&lt;P&gt;but it is not needed. It works without this row.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2005 18:12:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434841#M534701</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2005-08-02T18:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: PIX without address translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434842#M534709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i told you that if you just want to communicate from &lt;/P&gt;&lt;P&gt;inside to dmz or from dmz to inside, all you need is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 acl&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;static (inside,dmz) ip ip&lt;/P&gt;&lt;P&gt;or if you want only the communication to start from &lt;/P&gt;&lt;P&gt;inside and not from dmz you need&lt;/P&gt;&lt;P&gt;nat(inside) and global (dmz)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember there is not NAT (dmz) needed in either case. This is just the way it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now if you want to communicate from inside to outside and also from outside to inside&lt;/P&gt;&lt;P&gt;you need&lt;/P&gt;&lt;P&gt;nat (inside) 0 acl&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;static (inside,outside) ip ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if u want communication from inside to outside only all you need is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat(inside) and global (outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for dmz to outside communication &lt;/P&gt;&lt;P&gt;you need nat (dmz) 0 acl&lt;/P&gt;&lt;P&gt;static (dmz,outside)&lt;/P&gt;&lt;P&gt;or nat (dmz) and global outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RULE IS, you dont need translation from LOWER Security to HIGHER Security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The exception to above rule is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-1 if you are using no nat-control feature in PIX 7.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- You still want to translate the outside IP adresses&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2005 20:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-without-address-translation/m-p/434842#M534709</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-08-02T20:35:00Z</dc:date>
    </item>
  </channel>
</rss>

