<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Source &amp; Destination NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/source-destination-nat/m-p/1510217#M601096</link>
    <description>&lt;P&gt;Can anyone point to a Cisco document that cleary describes source and destination NAT, the differences between them, why you would use ource over destination &amp;amp; vice versa and any configuration examples on an ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:54:05 GMT</pubDate>
    <dc:creator>paultribe</dc:creator>
    <dc:date>2019-03-11T18:54:05Z</dc:date>
    <item>
      <title>Source &amp; Destination NAT</title>
      <link>https://community.cisco.com/t5/network-security/source-destination-nat/m-p/1510217#M601096</link>
      <description>&lt;P&gt;Can anyone point to a Cisco document that cleary describes source and destination NAT, the differences between them, why you would use ource over destination &amp;amp; vice versa and any configuration examples on an ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-destination-nat/m-p/1510217#M601096</guid>
      <dc:creator>paultribe</dc:creator>
      <dc:date>2019-03-11T18:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Source &amp; Destination NAT</title>
      <link>https://community.cisco.com/t5/network-security/source-destination-nat/m-p/1510218#M601109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source and destination NAT are relative to the interfaces on the ASA firewall. A couple of examples might help -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have a server on your LAN with a private address of 192.168.10.1 and you want to "present" it to the outside as 177.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) static (inside,outside) 177.10.10.1 192.168.10.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) traffic going from the server on the inside to the outside -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; the src IP is changed from 192.168.10.1 to 195.166.10.1&amp;nbsp;&amp;nbsp;&amp;nbsp; the destination IP is left as is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) traffic returning to the server from the outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; the src IP is left as is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; the destination IP is changed from 177.10.10.1 to 192.168.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You want to allow internal devices to access the 195.166.10.1 server on the internet. But you don't want to advertise 177.10.10.1 into your network. Instead you want to use 10.5.1.10 as the destination address -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) static (outside,inside) 10.5.1.10 195.166.10.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) traffic going from your internal clients with a destination IP of 10.5.1.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; the src IP is left alone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; the destination IP is changed from 10.5.1.10 to 195.166.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) traffic returning to your client from the outside server 195.166.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; the src IP is changed from 195.166.10.1 to 10.5.1.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; the destination IP is unchanged&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this has helped rather than add to the confusion &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Oct 2010 10:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-destination-nat/m-p/1510218#M601109</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-10-14T10:49:45Z</dc:date>
    </item>
  </channel>
</rss>

