<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT query in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-query/m-p/1653665#M581750</link>
    <description>&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;folks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;i have a basic nat query on an asa 8.2 i'm hoping you can help with&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;i've a dynamic nat to translate all traffic from the inside to outside to the external interface's IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;i also have a number of inside to outside exempts for some public IPs i have on the inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;no nat-control is configured&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;my query is this&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;when i try to initiate a connection from an outside server to an inside server it fails and packet tracer tells me it due to nat (i have an ACL in place to allow traffic)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;if i configure a nat exemption from (outside, inside) if fails&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;if i configure a nat exemption from (inside, outside) if works&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why do i need the nat when no nat-control is enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks to anyone taking the time to read this or to post a reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greatly appreciated&lt;/P&gt;&lt;SPAN style="font-style: background-color: #f8fafd;; "&gt;&lt;P&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:53:07 GMT</pubDate>
    <dc:creator>mulhollandm</dc:creator>
    <dc:date>2019-03-11T19:53:07Z</dc:date>
    <item>
      <title>NAT query</title>
      <link>https://community.cisco.com/t5/network-security/nat-query/m-p/1653665#M581750</link>
      <description>&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;folks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;i have a basic nat query on an asa 8.2 i'm hoping you can help with&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;i've a dynamic nat to translate all traffic from the inside to outside to the external interface's IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;i also have a number of inside to outside exempts for some public IPs i have on the inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;no nat-control is configured&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;my query is this&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;when i try to initiate a connection from an outside server to an inside server it fails and packet tracer tells me it due to nat (i have an ACL in place to allow traffic)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;if i configure a nat exemption from (outside, inside) if fails&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;if i configure a nat exemption from (inside, outside) if works&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why do i need the nat when no nat-control is enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks to anyone taking the time to read this or to post a reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greatly appreciated&lt;/P&gt;&lt;SPAN style="font-style: background-color: #f8fafd;; "&gt;&lt;P&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-query/m-p/1653665#M581750</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2019-03-11T19:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAT query</title>
      <link>https://community.cisco.com/t5/network-security/nat-query/m-p/1653666#M581752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"no nat-control" is disabled as soon as you have a NAT statement on an interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would need to exempt inbound traffic, you will need to configure static (inside,outside) as normally you will configure static NAT from high security level to low security level, and the static NAT works bidirectionally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 22:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-query/m-p/1653666#M581752</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-18T22:54:55Z</dc:date>
    </item>
  </channel>
</rss>

