<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Nat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1613798#M593477</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In version 8.3 the static and global commands for NAT are gone.&lt;/P&gt;&lt;P&gt;The only command you need is the ''nat'' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT is performed for objects now so you should define the objects as well.&lt;/P&gt;&lt;P&gt;If I'm not mistaken to migrate a Policy NAT configuration to 8.3 you now use what is called Twice NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to this document:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Jan 2011 15:39:23 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2011-01-24T15:39:23Z</dc:date>
    <item>
      <title>Policy Nat</title>
      <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1613797#M593476</link>
      <description>&lt;P&gt;I would like to create the following situation on an ASA Firewall, but i can't get find a working solution on new firmware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incomming traffic on outside interface on ip 1.1.1.1 can be tcp/443 or tcp/80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If traffic is on tcp/80 NAT to 2.2.2.1 tcp/80&amp;nbsp; &lt;/P&gt;&lt;P&gt;if traffic is tcp/443 NAT to 2.2.2.2 tcp/443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In earlier vesion you could do this like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list SSL permit tcp host 2.2.2.2 eq 443 x.x.0.0 255.255.0.0 eq 443&lt;/P&gt;&lt;P&gt;static (Inside,Outside) tcp 1.1.1.1 443 access-list SSL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list HTTP permit tcp host 2.2.2.1 eq 80 x.x.0.0 255.255.0.0 eq 80&lt;/P&gt;&lt;P&gt;static (Inside,Outside) tcp 1.1.1.1 http access-list HTTP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to be deprecated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using ASA 8.3(2) , ASDM 6.3(4)50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx.,..&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:39:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-nat/m-p/1613797#M593476</guid>
      <dc:creator>eddiemeijer</dc:creator>
      <dc:date>2019-03-11T19:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Nat</title>
      <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1613798#M593477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In version 8.3 the static and global commands for NAT are gone.&lt;/P&gt;&lt;P&gt;The only command you need is the ''nat'' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT is performed for objects now so you should define the objects as well.&lt;/P&gt;&lt;P&gt;If I'm not mistaken to migrate a Policy NAT configuration to 8.3 you now use what is called Twice NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to this document:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jan 2011 15:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-nat/m-p/1613798#M593477</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-24T15:39:23Z</dc:date>
    </item>
  </channel>
</rss>

