<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A question about nat configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/a-question-about-nat-configuration/m-p/1526179#M605704</link>
    <description>&lt;P&gt;I've been digging around in the IOS 12.4 on-line documentation and finding just enough information to make me ask more questions, that I can't find answers for.&amp;nbsp; Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a system with one external interface and many internal network interfaces.&amp;nbsp; For security we are looking at using RFC 1918 IP addresses for the internal networks and implementing nat for external routing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also for security reasons we need to ensure that only traffic for each specific subnet can route through its internal interface, both into and out of the router.&amp;nbsp; To me, it appears that we will need a separate access-list for each interface, is this correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have security mandates that require the use of the "IP access-list extended" format.&amp;nbsp; is that format compatible with nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can an IP nat pool support more than one IP source list (access-list) or do we need one pool for each list?&amp;nbsp; Can the IOS even support more than one pool?&amp;nbsp; If so, is there a limit to the number of pools that are supported?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another issue is that we will have some applications that require the end unit to have a routable IP address.&amp;nbsp; They will have their one dedicated internal interface, but everything shares the same external interface.&amp;nbsp; Can one external interface support both?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manuel Dennis&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:20:01 GMT</pubDate>
    <dc:creator>manuel.dennis</dc:creator>
    <dc:date>2019-03-11T19:20:01Z</dc:date>
    <item>
      <title>A question about nat configuration</title>
      <link>https://community.cisco.com/t5/network-security/a-question-about-nat-configuration/m-p/1526179#M605704</link>
      <description>&lt;P&gt;I've been digging around in the IOS 12.4 on-line documentation and finding just enough information to make me ask more questions, that I can't find answers for.&amp;nbsp; Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a system with one external interface and many internal network interfaces.&amp;nbsp; For security we are looking at using RFC 1918 IP addresses for the internal networks and implementing nat for external routing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also for security reasons we need to ensure that only traffic for each specific subnet can route through its internal interface, both into and out of the router.&amp;nbsp; To me, it appears that we will need a separate access-list for each interface, is this correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have security mandates that require the use of the "IP access-list extended" format.&amp;nbsp; is that format compatible with nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can an IP nat pool support more than one IP source list (access-list) or do we need one pool for each list?&amp;nbsp; Can the IOS even support more than one pool?&amp;nbsp; If so, is there a limit to the number of pools that are supported?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another issue is that we will have some applications that require the end unit to have a routable IP address.&amp;nbsp; They will have their one dedicated internal interface, but everything shares the same external interface.&amp;nbsp; Can one external interface support both?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manuel Dennis&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:20:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-question-about-nat-configuration/m-p/1526179#M605704</guid>
      <dc:creator>manuel.dennis</dc:creator>
      <dc:date>2019-03-11T19:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: A question about nat configuration</title>
      <link>https://community.cisco.com/t5/network-security/a-question-about-nat-configuration/m-p/1526180#M605707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A specific ACL applied to each interface. &lt;BR /&gt;IP access-list extended is the recommended way to go fully compatible with NAT. &lt;BR /&gt;Recommended configuration one pool for each ACL.&lt;BR /&gt;IOS can support many pools. &lt;BR /&gt;You can have a mix of public/private addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need clarification in something please let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 15:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-question-about-nat-configuration/m-p/1526180#M605707</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-08T15:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: A question about nat configuration</title>
      <link>https://community.cisco.com/t5/network-security/a-question-about-nat-configuration/m-p/1526181#M605709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The examples in the on-line documentation were somewhat limited. Your information is very helpful.&amp;nbsp; Thank you.&lt;/P&gt;&lt;P&gt;Manuel Dennis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 15:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/a-question-about-nat-configuration/m-p/1526181#M605709</guid>
      <dc:creator>manuel.dennis</dc:creator>
      <dc:date>2010-12-08T15:31:06Z</dc:date>
    </item>
  </channel>
</rss>

