<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505: NAT DMZ to non interface ip in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618342#M593464</link>
    <description>&lt;P&gt;I need to NAT the DMZ vlan to a non interface IP for internet access.&lt;/P&gt;&lt;P&gt;I was thinking of doing a static command&lt;/P&gt;&lt;P&gt;static (DMZ,outside) 192.168.1.1 1.2.3.4 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or if I need to do a global nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (DMZ) 2 &amp;lt;external IP&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list NoVPN_NAT&lt;/P&gt;&lt;P&gt;nat (DMZ) 2 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:39:32 GMT</pubDate>
    <dc:creator>jeffreymertz</dc:creator>
    <dc:date>2019-03-11T19:39:32Z</dc:date>
    <item>
      <title>ASA5505: NAT DMZ to non interface ip</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618342#M593464</link>
      <description>&lt;P&gt;I need to NAT the DMZ vlan to a non interface IP for internet access.&lt;/P&gt;&lt;P&gt;I was thinking of doing a static command&lt;/P&gt;&lt;P&gt;static (DMZ,outside) 192.168.1.1 1.2.3.4 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or if I need to do a global nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (DMZ) 2 &amp;lt;external IP&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list NoVPN_NAT&lt;/P&gt;&lt;P&gt;nat (DMZ) 2 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618342#M593464</guid>
      <dc:creator>jeffreymertz</dc:creator>
      <dc:date>2019-03-11T19:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505: NAT DMZ to non interface ip</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618343#M593465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to NAT a host or network to allow internet access, you can use dynamic NAT (nat/global)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static NAT is usually to allow inbound access like when you want to make a web server publicly available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jan 2011 22:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618343#M593465</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-24T22:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505: NAT DMZ to non interface ip</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618344#M593466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the outside need to initiate traffic to dmz host, you need use the static NAT.&lt;/P&gt;&lt;P&gt;Otherwise, the following should work&lt;/P&gt;&lt;P&gt;global (OUTSIDE_Interface_name) 2 &lt;EXTERNAL ip=""&gt;&lt;/EXTERNAL&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list NoVPN_NAT&lt;/P&gt;&lt;P&gt;nat (DMZ) 2 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jan 2011 22:11:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618344#M593466</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2011-01-24T22:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505: NAT DMZ to non interface ip</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618345#M593467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I was pretty sure I was close, but didn't feel like testing on a production unit.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jan 2011 01:31:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-nat-dmz-to-non-interface-ip/m-p/1618345#M593467</guid>
      <dc:creator>jeffreymertz</dc:creator>
      <dc:date>2011-01-25T01:31:19Z</dc:date>
    </item>
  </channel>
</rss>

