<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2nd public IP address on 5510 that points nowhere internally in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609833#M559753</link>
    <description>&lt;P&gt;Will I break anything if I create a second IP address on the physical externa&lt;SPAN style="background-color: #f8fafd;"&gt;l interface of our ASA 5510?&amp;nbsp; I want to point it nowhere internally but want an active interface that can be vulnerability scanned but won't lead anywhere internally.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:08:02 GMT</pubDate>
    <dc:creator>clippersbaseball</dc:creator>
    <dc:date>2019-03-11T20:08:02Z</dc:date>
    <item>
      <title>2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609833#M559753</link>
      <description>&lt;P&gt;Will I break anything if I create a second IP address on the physical externa&lt;SPAN style="background-color: #f8fafd;"&gt;l interface of our ASA 5510?&amp;nbsp; I want to point it nowhere internally but want an active interface that can be vulnerability scanned but won't lead anywhere internally.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609833#M559753</guid>
      <dc:creator>clippersbaseball</dc:creator>
      <dc:date>2019-03-11T20:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609834#M559754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to clarify the ASA won't support secondary IP addresses.&lt;/P&gt;&lt;P&gt;Is this what you mean?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 21:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609834#M559754</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-16T21:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609835#M559757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my bad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 02:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609835#M559757</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2011-03-17T02:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609836#M559759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gurpreet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only have a single IP address assign to an interface on an ASA.&lt;/P&gt;&lt;P&gt;If you have another interface, you can assign another IP address to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA allows a configuration from a separate IP address on the outside when used for NAT.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the range 2.2.2.0/24 to NAT internal traffic to the Internet and having the outside IP as part of 1.1.1.0/24&lt;/P&gt;&lt;P&gt;This can be done if the outside router has a route pointing to the ASA to reach 2.2.2.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, if the ASA has an IP on the outside, you cannot assign another IP to that interface (as you can do with routers and is called secondary IP addresses).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 02:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609836#M559759</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-17T02:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609837#M559761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 02:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609837#M559761</guid>
      <dc:creator>lawsuites</dc:creator>
      <dc:date>2011-03-17T02:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609838#M559763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please add a simple drawing that explains what you're trying to accomplish and I'm sure we can help you out.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 04:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609838#M559763</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-17T04:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609839#M559765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure how Gupreet inched in my thread...but all I want to do is we have one physical interface off of our 5510 to our ISP with one IP address assigned to it.&amp;nbsp; I want to assign another IP address to that external interface (in the same subnet range for our ISP allocated range) so that we can run vulnerability scans to that IP address for special reasons.&amp;nbsp; I don't want that additional external address to NAT anywhere inside other than that external interface of the ASA.&amp;nbsp; I tried to assign another IP address and it looks like it will allow that but I'm not sure if doing that will break something else.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 12:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609839#M559765</guid>
      <dc:creator>clippersbaseball</dc:creator>
      <dc:date>2011-03-17T12:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609840#M559766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA won't support secondary IP addresses as mentioned before.&lt;/P&gt;&lt;P&gt;If the ASA has an IP address assigned to the outside interface, you cannot assign another IP to the same interface.&lt;/P&gt;&lt;P&gt;If you do... it will overwrite the current IP because the ASA will support a single IP on an interface only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't you run the vulnerability scan to the IP that is currently assigned to the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 13:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609840#M559766</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-17T13:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609841#M559767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Federico...we're just getting a constant flase positive on our current public address and the vendor that is scannig suggested doing this just to get by.&amp;nbsp; I've opened a TAC case and they verifed that the vulnerability was addressed in 1997.&amp;nbsp; We're running 8.2.2 code and the vendor continues to get the "OpenSSL SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG" error.&amp;nbsp; Again, TAC said that this was addressed a long time ago but the vendor scan keeps getting this message.&amp;nbsp; The vendor said to create another IP address and have it point to nothing so the scan will run without errors.&amp;nbsp; Should I NAT an internal address to anothe external address and have it NAT'd to an invalid internal host? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 15:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609841#M559767</guid>
      <dc:creator>clippersbaseball</dc:creator>
      <dc:date>2011-03-17T15:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: 2nd public IP address on 5510 that points nowhere internally</title>
      <link>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609842#M559769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's say the ASA has an outside IP 2.2.2.1 and an internal IP 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create a static NAT for example:&lt;/P&gt;&lt;P&gt;static (in,out) 2.2.2.2 1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above static will allow the ASA to receive traffic destined to 2.2.2.2 and forward it to 1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind that 2.2.2.2 in the above example is mapped to the internal host 1.1.1.2, so you're really scanning the&lt;/P&gt;&lt;P&gt;internal host.&lt;/P&gt;&lt;P&gt;All the ASA will do is received the traffic and send it inside (if the traffic is permitted by the ACL).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 15:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2nd-public-ip-address-on-5510-that-points-nowhere-internally/m-p/1609842#M559769</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-03-17T15:24:16Z</dc:date>
    </item>
  </channel>
</rss>

