<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: trying to understand static translation on the firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trying-to-understand-static-translation-on-the-firewall/m-p/1657749#M561335</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We changed the config and it's no longer available, but yes I agree with you that should of worked as I had this working in other environments, it is weird.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But my question is, what is the difference between the 2 methods of translations? why would you use one over the over?&amp;nbsp; how does the access-list translation work anyhow?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Jun 2011 19:37:36 GMT</pubDate>
    <dc:creator>network770</dc:creator>
    <dc:date>2011-06-02T19:37:36Z</dc:date>
    <item>
      <title>trying to understand static translation on the firewall</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-understand-static-translation-on-the-firewall/m-p/1657747#M561333</link>
      <description>&lt;P&gt;We are about to connect a remote office to our data center and we have an ASA on the Internet (at both sites) but the remote office we are connecting has a conflicting segment with the data center - 192.168.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so in order for the data center to talk to the remote office we did the following on the remote office firewall&amp;nbsp; :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.100.0 192.168.10.0 net 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with this we are expecting the data center to access the remote office using 192.168.100.0 and the firewall should translate it to 192.168.10.0 and that was not working, still not sure why... it's very strange, after doing some more reseach I ended doing this on the remote office firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.100.0 access-list VPN&lt;/P&gt;&lt;P&gt;access-list VPN extended permit ip object-group INTERNAL_NETWORK object-group REMOTE_SITE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where INTERNAL_NETWORK is an object group with the ip address of the remote office ip and REMOTE_SITE is the data center ip addresses&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;can someone please clarify, am I missing something with the translation?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-understand-static-translation-on-the-firewall/m-p/1657747#M561333</guid>
      <dc:creator>network770</dc:creator>
      <dc:date>2019-03-11T20:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: trying to understand static translation on the firewall</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-understand-static-translation-on-the-firewall/m-p/1657748#M561334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ronni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats weird, the first one should have done the trick. Would you please paste the command sh run static and show run nat? The first static should have done the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 18:40:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-understand-static-translation-on-the-firewall/m-p/1657748#M561334</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-06-02T18:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: trying to understand static translation on the firewall</title>
      <link>https://community.cisco.com/t5/network-security/trying-to-understand-static-translation-on-the-firewall/m-p/1657749#M561335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We changed the config and it's no longer available, but yes I agree with you that should of worked as I had this working in other environments, it is weird.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But my question is, what is the difference between the 2 methods of translations? why would you use one over the over?&amp;nbsp; how does the access-list translation work anyhow?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 19:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trying-to-understand-static-translation-on-the-firewall/m-p/1657749#M561335</guid>
      <dc:creator>network770</dc:creator>
      <dc:date>2011-06-02T19:37:36Z</dc:date>
    </item>
  </channel>
</rss>

