<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515E - Clarify on NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-clarify-on-nat/m-p/483760#M557973</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you have PPTP connections coming into this PIX from the outside (all the vpdn commands down the bottom), and the two lines you're wanting to delete are for that.  I wouldn't recommend deleting them unless you're sure the PPTP connectivity is no longer allowed.  They specifically tell the PIX not to NAT traffic destined for the PPTP tunnel, which is the correct thing to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your other nat/global pair is fine.  The keyword "interface" in the global command tells the PIX to PAT everything to whatever IP address is configured on the outside interface, so leave it as is.  The nat statement having all zeroes simply means any packet coming in from the inside will be PAT'd as it goes out, regardless of its IP address.  If you like you can make this more specific to only cover your actual internal subnet with the command you specify above. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 May 2005 01:09:44 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2005-05-23T01:09:44Z</dc:date>
    <item>
      <title>PIX 515E - Clarify on NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-clarify-on-nat/m-p/483759#M557971</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;Pls find the attached files.&lt;/P&gt;&lt;P&gt;New to PIx firewal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;128.1.1.248 is not given by ISP.  &lt;/P&gt;&lt;P&gt;do let me know whether the following can be deleted: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)access-list inside_outbound_nat0_acl permit ip any 128.1.1.248 255.255.255.248 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)nat (inside) 0 access-list inside_outbound_nat0_acl &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this correct: &lt;/P&gt;&lt;P&gt;"global (outside) 10 interface" to be changed to "global (outside) 10 public interface IP" &lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;"nat (inside) 10 0.0.0.0 0.0.0.0 0 0" to be changed to "nat (inside) 10 128.1.1.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prashanth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-clarify-on-nat/m-p/483759#M557971</guid>
      <dc:creator>prashanth15</dc:creator>
      <dc:date>2020-02-21T08:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E - Clarify on NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-clarify-on-nat/m-p/483760#M557973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you have PPTP connections coming into this PIX from the outside (all the vpdn commands down the bottom), and the two lines you're wanting to delete are for that.  I wouldn't recommend deleting them unless you're sure the PPTP connectivity is no longer allowed.  They specifically tell the PIX not to NAT traffic destined for the PPTP tunnel, which is the correct thing to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your other nat/global pair is fine.  The keyword "interface" in the global command tells the PIX to PAT everything to whatever IP address is configured on the outside interface, so leave it as is.  The nat statement having all zeroes simply means any packet coming in from the inside will be PAT'd as it goes out, regardless of its IP address.  If you like you can make this more specific to only cover your actual internal subnet with the command you specify above. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 May 2005 01:09:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-clarify-on-nat/m-p/483760#M557973</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2005-05-23T01:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E - Clarify on NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-clarify-on-nat/m-p/483761#M557977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks gfullage for your explanation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Prashanth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 May 2005 06:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-clarify-on-nat/m-p/483761#M557977</guid>
      <dc:creator>prashanth15</dc:creator>
      <dc:date>2005-05-23T06:23:04Z</dc:date>
    </item>
  </channel>
</rss>

