<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA NAT question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612258#M581310</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic would be sourced on the inside network&lt;/P&gt;&lt;P&gt;And would flow to the dmz.&lt;/P&gt;&lt;P&gt;If inside network is 192.168.0.x&lt;/P&gt;&lt;P&gt;and dmz is 172.16.1.x&lt;/P&gt;&lt;P&gt;Traffic would source at 192.168.0.3 and flow to 172.16.1.3&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Feb 2011 13:16:57 GMT</pubDate>
    <dc:creator>dlance</dc:creator>
    <dc:date>2011-02-24T13:16:57Z</dc:date>
    <item>
      <title>ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612254#M581306</link>
      <description>&lt;P&gt;We have a somewhat standard 3 interface dmz setup&lt;/P&gt;&lt;P&gt;inside---dmz---outside&lt;/P&gt;&lt;P&gt;we nat from inside to dmz for normal access of servers on dmz (with access rules)&lt;/P&gt;&lt;P&gt;we have one web server on dmz we dont want to nat to reach from inside&lt;/P&gt;&lt;P&gt;we would like to have 1 fixed ip address on inside network that always reaches this server as one fixed ip on the dmz&lt;/P&gt;&lt;P&gt;we do have some static rules for other servers to access on the inside from the dmz but I cant get a static to work for this server&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612254#M581306</guid>
      <dc:creator>dlance</dc:creator>
      <dc:date>2019-03-11T19:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612255#M581307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config guide for NAT exemption:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_bypassing.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_bypassing.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can share a copy of your sanitized running-config (specifically 'show run nat', 'show run global', 'show run static', and 'show run nat-control'), and the IP of the server you're having trouble with, we can give you a more specific solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Feb 2011 20:17:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612255#M581307</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-02-23T20:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612256#M581308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks but I dont want nat exemption&lt;/P&gt;&lt;P&gt;I want a fixed translation from 1 inside address to 1 dmz address&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Feb 2011 20:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612256#M581308</guid>
      <dc:creator>dlance</dc:creator>
      <dc:date>2011-02-23T20:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612257#M581309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dave...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can give more details of how you want the traffic flow to work. As i read your first response, it does sound like you want NAT exemption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want the inside IP Natted when going to the DMZ? What IP did you want natted and where does the source of the connection begin?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 00:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612257#M581309</guid>
      <dc:creator>Edward Dutra</dc:creator>
      <dc:date>2011-02-24T00:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612258#M581310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic would be sourced on the inside network&lt;/P&gt;&lt;P&gt;And would flow to the dmz.&lt;/P&gt;&lt;P&gt;If inside network is 192.168.0.x&lt;/P&gt;&lt;P&gt;and dmz is 172.16.1.x&lt;/P&gt;&lt;P&gt;Traffic would source at 192.168.0.3 and flow to 172.16.1.3&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 13:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612258#M581310</guid>
      <dc:creator>dlance</dc:creator>
      <dc:date>2011-02-24T13:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612259#M581311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So is there any reason the basic Static configuration wont help you here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;static (inside,dmz) 172.16.1.3 192.168.0.3 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above would NAT traffic from 192.168.0.3 to 172.16.1.3 when going out the DMZ interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is the traffic going to a server that has the IP 172.16.1.3? Are you natting one host or the entire inside network to the DMZ? What IP or pool of IPs did you want the inside host or host to have when going to the DMZ? &lt;!-- [DocumentBodyEnd:28cee18c-bd67-4ce9-881b-eecb983cc4ad] --&gt;&lt;!-- BEGIN attachments --&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;!-- END attachments --&gt;&lt;!-- END reply --&gt;&lt;/P&gt;&lt;P&gt;&lt;!-- END main body column --&gt;&lt;/P&gt;&lt;P&gt;&lt;!-- END main body --&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 18:49:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1612259#M581311</guid>
      <dc:creator>Edward Dutra</dc:creator>
      <dc:date>2011-02-24T18:49:35Z</dc:date>
    </item>
  </channel>
</rss>

