<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Policy NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-policy-nat/m-p/135337#M601232</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem of overlapping address space can be solved using enhanced NAT/ bi-directional nat, which allows to to apply the NAT and global commands to the outside and inside interfaces respectively. The earlier restriction wrt placement of these commands are not valid any more. You could also see a related document at &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/707/vpn_pix_private.html" target="_blank"&gt;http://www.cisco.com/warp/public/707/vpn_pix_private.html&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Aug 2003 14:52:03 GMT</pubDate>
    <dc:creator>jsivulka</dc:creator>
    <dc:date>2003-08-14T14:52:03Z</dc:date>
    <item>
      <title>PIX Policy NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-policy-nat/m-p/135336#M601231</link>
      <description>&lt;P&gt;Is there anyone who worked with the Policy  NAT on PIX 6.3 (2)  ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a scenario where a central PIX vpn a remote site PIX .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to translate Remote site inside private addresses because they&lt;/P&gt;&lt;P&gt;conflict with another remote site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i want the Remote PIX to translate to a private pool for establishing the&lt;/P&gt;&lt;P&gt;vpn , and translate to the public outside interface address for internet&lt;/P&gt;&lt;P&gt;access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.19.0.0 CentralPIX ----- 206.x.x.58 RemotePIX 10.1.1.0&lt;/P&gt;&lt;P&gt;                                                     10.2.2.0 xlate 10.1.1.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remote PIX config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonatvpn permit ip 10.1.1.0 255.255.255.0 172.19.0.0&lt;/P&gt;&lt;P&gt;255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonatvpn&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.2.2.0 access-list nonatvpn 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 1 - ping internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;replies&lt;/P&gt;&lt;P&gt;PAT Global 206.x.x.58(1) Local 10.1.1.190 ICMP id 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 2 - ping vpn ( while ping internet is still running )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;replies  but  ping on internet stop responding&lt;/P&gt;&lt;P&gt;Global 10.2.2.190 Local 10.1.1.190&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it works but not simultaneously . Is this the normal behavior of that&lt;/P&gt;&lt;P&gt;functionnality  or did i miss something. I would like to have both access&lt;/P&gt;&lt;P&gt;at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-policy-nat/m-p/135336#M601231</guid>
      <dc:creator>mcaissie</dc:creator>
      <dc:date>2020-02-21T06:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Policy NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-policy-nat/m-p/135337#M601232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem of overlapping address space can be solved using enhanced NAT/ bi-directional nat, which allows to to apply the NAT and global commands to the outside and inside interfaces respectively. The earlier restriction wrt placement of these commands are not valid any more. You could also see a related document at &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/707/vpn_pix_private.html" target="_blank"&gt;http://www.cisco.com/warp/public/707/vpn_pix_private.html&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Aug 2003 14:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-policy-nat/m-p/135337#M601232</guid>
      <dc:creator>jsivulka</dc:creator>
      <dc:date>2003-08-14T14:52:03Z</dc:date>
    </item>
  </channel>
</rss>

