<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity NAT configuration for Remote Access VPN and Site to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649567#M589654</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Janardhan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is normal behavior. With the security plus license, interfaces Ethernet0/0 and Ethernet0/1 become gigabit interface but they are still referred to as "Ethernet" by the ASA. However, if you look at the output of 'show interface', you will see that the speed should be 1000 Mbps:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Interface &lt;STRONG style="color: #ff0000; "&gt;Ethernet0/0 &lt;/STRONG&gt;"outside", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, &lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;BW &lt;/SPAN&gt;&lt;SPAN style="color: #ff0000;"&gt;1000 Mbps&lt;/SPAN&gt;&lt;/STRONG&gt;, DLY 10 usec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auto-Duplex(Full-duplex), Auto-Speed(&lt;STRONG style="color: #ff0000; "&gt;1000 Mbps&lt;/STRONG&gt;)&lt;/PRE&gt;&lt;P&gt;This is documented in the licensing guide for the ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/license/license_management/license.html#wp1456941"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/license/license_management/license.html#wp1456941&lt;/A&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Although the Ethernet 0/0 and 0/1 ports are Gigabit Ethernet, they are still identified as "Ethernet" in the software. &lt;/PRE&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Mar 2011 17:46:31 GMT</pubDate>
    <dc:creator>mirober2</dc:creator>
    <dc:date>2011-03-11T17:46:31Z</dc:date>
    <item>
      <title>Identity NAT configuration for Remote Access VPN and Site to Site VPN</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649562#M589649</link>
      <description>&lt;P&gt;Dear Support-Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am try to configure ASA 5510 with 8.3 IOS version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My internal users are 192.168.2.0/24 and i configured dynamic PAT and are all internet .&lt;/P&gt;&lt;P&gt;Below is the my configuration:&lt;/P&gt;&lt;P&gt;object network SPM-INSIDE&lt;BR /&gt; subnet 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here i want configure identity NAT for remote access VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remote users IP pool is 10.10.10.0 to 10.10.10.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i know to configure NAT exemption in IOS 7.2 version. But here IOS 8.3 version. Will you help to configure NAT exemption for 192.168.2.0/24 to my remote pool( 10.10.10.0 to 10.10.10.10).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, also need to configure site to site VPN for IP's:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site A: 192.168.2.0/24&lt;/P&gt;&lt;P&gt;Site B: 192.168.3.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here also need to configure NAT exemption for above IPs in IOS 8.3 version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Janardhan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649562#M589649</guid>
      <dc:creator>Janardhan Meesala</dc:creator>
      <dc:date>2019-03-11T20:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT configuration for Remote Access VPN and Site to</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649563#M589650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Janardhan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example of the configuration you'd want to use for identity NAT. These lines assume your VPN connections terminate on the outside interface:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;object network obj-192.168.2.0&lt;BR /&gt; subnet 192.168.2.0 255.255.255.0&lt;BR /&gt;object network remote_pool&lt;BR /&gt; range 10.10.10.0 10.10.10.10&lt;BR /&gt;object network obj-192.168.3.0&lt;BR /&gt; subnet 192.168.3.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) source static obj-192.168.2.0 obj-192.168.2.0 destination static remote_pool remote_pool&lt;BR /&gt;nat (inside,outside) source static obj-192.168.2.0 obj-192.168.2.0 destination static obj-192.168.3.0 obj-192.168.3.0&lt;/PRE&gt;&lt;P&gt;These links may also help in the future:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-9129"&gt;https://supportforums.cisco.com/docs/DOC-9129&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-video-small" href="https://community.cisco.com/videos/1014"&gt;https://supportforums.cisco.com/videos/1014&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 16:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649563#M589650</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-03-10T16:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT configuration for Remote Access VPN and Site to</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649564#M589651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured Identiry NAT as your said.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this i configured Remote pool using the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool RPOOL 10.10.10.1-10.10.10.10 mask 255.255.255.0  if i enter&lt;/P&gt;&lt;P&gt;this command it shows error as " Addresses overlap with existing NAT"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly help me to solve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Janardhan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Thu, Mar 10, 2011 at 10:03 PM, mirober2 &amp;lt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 04:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649564#M589651</guid>
      <dc:creator>Janardhan Meesala</dc:creator>
      <dc:date>2011-03-11T04:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT configuration for Remote Access VPN and Site to</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649565#M589652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Janardhan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This error is caused by a known bug:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCtg99839 - Cannot Create a Network Range Object Overlapping with a Local Pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bug is still being worked on and hasn't been fixed yet. As a workaround, you could use the following config instead (the order of the commands is important):&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;no nat (inside,outside) source static obj-192.168.2.0 obj-192.168.2.0 destination static remote_pool remote_pool&lt;BR /&gt;no object network remote_pool&lt;BR /&gt;!&lt;BR /&gt;ip local pool RPOOL 10.10.10.1-10.10.10.10 mask 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;object-group network remote_pool&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.4&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.5&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.6&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.7&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.8&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.9&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network-object host 10.10.10.10&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) source static obj-192.168.2.0 obj-192.168.2.0 destination static remote_pool remote_pool&lt;/PRE&gt;&lt;P&gt;It would also be a good idea to open a TAC case for this issue so it can be linked to the bug, which in turn will help to get a fix available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 14:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649565#M589652</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-03-11T14:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT configuration for Remote Access VPN and Site to</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649566#M589653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was solved...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used sunet instead of range while creating 'remote-pool' network object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool RPOOL 10.10.10.1-10.10.10.10 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network remote-pool&lt;/P&gt;&lt;P&gt; subnet 10.10.10.0 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-192.168.2.0&lt;/P&gt;&lt;P&gt; subnet 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (management,outside) source static obj-192.168.2.0 obj-192.168.2.0&lt;/P&gt;&lt;P&gt;destination static remote-pool remote-pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally i have query ... i.e My firewall is ASA 5510..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As i studied in the dasheet its says that ASA 5510 totally had 5&lt;/P&gt;&lt;P&gt;fastethernet interfaces in base license. If we upgrade the license with&lt;/P&gt;&lt;P&gt;security plus than of them will become gigabit interafaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But here my problem is my firewall showing all interfaces are ethernet&lt;/P&gt;&lt;P&gt;interfaces....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will you explainn what is the problem..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Janardhan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Fri, Mar 11, 2011 at 7:41 PM, mirober2 &amp;lt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 17:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649566#M589653</guid>
      <dc:creator>Janardhan Meesala</dc:creator>
      <dc:date>2011-03-11T17:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT configuration for Remote Access VPN and Site to</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649567#M589654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Janardhan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is normal behavior. With the security plus license, interfaces Ethernet0/0 and Ethernet0/1 become gigabit interface but they are still referred to as "Ethernet" by the ASA. However, if you look at the output of 'show interface', you will see that the speed should be 1000 Mbps:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Interface &lt;STRONG style="color: #ff0000; "&gt;Ethernet0/0 &lt;/STRONG&gt;"outside", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is i82546GB rev03, &lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;BW &lt;/SPAN&gt;&lt;SPAN style="color: #ff0000;"&gt;1000 Mbps&lt;/SPAN&gt;&lt;/STRONG&gt;, DLY 10 usec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auto-Duplex(Full-duplex), Auto-Speed(&lt;STRONG style="color: #ff0000; "&gt;1000 Mbps&lt;/STRONG&gt;)&lt;/PRE&gt;&lt;P&gt;This is documented in the licensing guide for the ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/license/license_management/license.html#wp1456941"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/license/license_management/license.html#wp1456941&lt;/A&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Although the Ethernet 0/0 and 0/1 ports are Gigabit Ethernet, they are still identified as "Ethernet" in the software. &lt;/PRE&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 17:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649567#M589654</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-03-11T17:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT configuration for Remote Access VPN and Site to</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649568#M589657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seen the output sh inter eth 0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and showing speed as 100 mbps..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, is my firewall support trunk( ASA 5510 with base license)...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If support how to configure Router on a stick.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Janardhan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Fri, Mar 11, 2011 at 11:16 PM, mirober2 &amp;lt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Mar 2011 07:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-configuration-for-remote-access-vpn-and-site-to/m-p/1649568#M589657</guid>
      <dc:creator>Janardhan Meesala</dc:creator>
      <dc:date>2011-03-12T07:42:45Z</dc:date>
    </item>
  </channel>
</rss>

