<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic one inside source address statci nat to two outside interface ad in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686439#M535965</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the customer is trying to setup a dual isp on asa, here is a doc for it:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is another one:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-13015"&gt;https://supportforums.cisco.com/docs/DOC-13015&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jul 2011 03:23:38 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-07-15T03:23:38Z</dc:date>
    <item>
      <title>one inside source address statci nat to two outside interface address.</title>
      <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686437#M535963</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i have a problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; customer has a server which located in inside interace.&amp;nbsp;&amp;nbsp;&amp;nbsp; and an outside interface connected to ISPA.&amp;nbsp;&amp;nbsp;&amp;nbsp; cu config a static nat map inside server address to ISPA address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; one day customer install a new outside interface to ISPB, cu config new static nat ,map same server inside server address to ISPB address.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; the server will allways be vistited from outside interface and reply, custome want traffic coming from ISPA will return to ISPA, traffic coming from ISPB will return to ISPB. &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; but i found it is difficult implement this on ASA5580.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; i want use route-map on static nat, but it will not satisfy customer's request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; is there any new method .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; thank you&lt;/P&gt;&lt;P&gt;tom&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686437#M535963</guid>
      <dc:creator>fly</dc:creator>
      <dc:date>2019-03-11T20:59:06Z</dc:date>
    </item>
    <item>
      <title>one inside source address statci nat to two outside interface ad</title>
      <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686438#M535964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure whether this is possible but still just to give it a try , can you tell me the following things:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will the same server be able to access from both ISPA and ISPB?&lt;/P&gt;&lt;P&gt;the server would be needed to be natted to 2 public IP's?&lt;/P&gt;&lt;P&gt;from which interface do you want to access the internet for internal users?&lt;/P&gt;&lt;P&gt;what software version are you using for ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly let me know the answers for thses questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 03:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686438#M535964</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-15T03:21:48Z</dc:date>
    </item>
    <item>
      <title>one inside source address statci nat to two outside interface ad</title>
      <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686439#M535965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the customer is trying to setup a dual isp on asa, here is a doc for it:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is another one:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-13015"&gt;https://supportforums.cisco.com/docs/DOC-13015&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 03:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686439#M535965</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-15T03:23:38Z</dc:date>
    </item>
    <item>
      <title>one inside source address statci nat to two outside interface ad</title>
      <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686440#M535966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will the same server be able to access from both ISPA and ISPB?&lt;/P&gt;&lt;P&gt;//yes, same server be able to access from both ISPA and ISPB,&amp;nbsp; access traffic is coming from internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the server would be needed to be natted to 2 public IP's?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//yes static nat,&amp;nbsp;&amp;nbsp; the server will be visited from internet only.&amp;nbsp; will never orginate traffic by itself&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from which interface do you want to access the internet for internal users?&lt;/P&gt;&lt;P&gt;//custome want access traffic coming from ISPA will return to internet by ISBA interface,&lt;/P&gt;&lt;P&gt;access traffic coming from ISPB will return to internet by ISBB interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what software version are you using for ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//i m not sure the version of software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you!&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 03:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686440#M535966</guid>
      <dc:creator>fly</dc:creator>
      <dc:date>2011-07-15T03:31:48Z</dc:date>
    </item>
    <item>
      <title>one inside source address statci nat to two outside interface ad</title>
      <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686441#M535967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly follow this thread, and let me know if your requirement matches:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2093723"&gt;https://supportforums.cisco.com/thread/2093723?tstart=0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 06:52:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686441#M535967</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-15T06:52:51Z</dc:date>
    </item>
    <item>
      <title>one inside source address statci nat to two outside interface ad</title>
      <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686442#M535968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; it is not same sitiuation i have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; may i clear my problem again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; customer has one asa 5580, one inside interface, connect one inside server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; two outside interface, these two outside interface connect to internet. one connect to ISPA,one connect to ISPB.different address space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; custome config&amp;nbsp; two static map ,map same inside server to ISPA and ISPB address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the traffic is coming from internet( may be usa,europe,anywhere),&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; customer want implement this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; when traffic is coming from ISPA, return traffic to internet will pass through ISPA interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; when traffic is coming from ISPB,return traffic to internet&amp;nbsp; will pass through ISPB interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the server in inside interface will never originate traffic when there is no traffic from outside internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Tom&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; width: 1px; height: 1px; overflow: hidden; top: 0px; left: -10000px;"&gt;﻿&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 09:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686442#M535968</guid>
      <dc:creator>lichuan liu</dc:creator>
      <dc:date>2011-07-15T09:01:02Z</dc:date>
    </item>
    <item>
      <title>one inside source address statci nat to two outside interface ad</title>
      <link>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686443#M535969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understand your requirement, there is no need for internet access from inside to outside, but only access from outside to inside. So based on this we can try this configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say you configure two interfaces ISPA and ISPB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so for ISPA:&lt;/P&gt;&lt;P&gt;lets say the server IP is 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list policy_ispa permit ip any host 2.2.2.2&lt;/P&gt;&lt;P&gt;nat (ISPA) 1 access-list policy_ispa&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;static (inisde,ISPA) 2.2.2.2 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for ISPB:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list policy_ispb permit ip any host 2.2.2.2&lt;/P&gt;&lt;P&gt;nat (ISPB) 2 access-list policy_ispb&lt;/P&gt;&lt;P&gt;global (inside) 2 interface&lt;/P&gt;&lt;P&gt;static (inside,ISPB) 2.2.2.2 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might help us with it, and you would definitely need a route for it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route ISPA 0.0.0.0 0.0.0.0 &lt;NEXT hop="" for="" ispa="" interface=""&gt; 1&lt;/NEXT&gt;&lt;/P&gt;&lt;P&gt;route ISPB 0.0.0.0 0.0.0.0 &lt;NEXT hop="" for="" ispb="" interface=""&gt; 100&lt;/NEXT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't tested any such configuration, but by logic, it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jul 2011 10:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-inside-source-address-statci-nat-to-two-outside-interface/m-p/1686443#M535969</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-15T10:13:32Z</dc:date>
    </item>
  </channel>
</rss>

