<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA static pat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548775#M615264</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks KS , I was reading the document where below is mentioned .&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"DNS rewrite is not compatible with static Port Address Translation (PAT) because multiple PAT rules are applicable for each A-record, and the PAT rule to use is ambiguous. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please let me know exact meaning of above .though it says it is not compatible but does that mean it can be still used ? also what do we mean by "multiple PAT rules are applicable for each A-record"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Dec 2010 06:58:05 GMT</pubDate>
    <dc:creator>jvardhan29</dc:creator>
    <dc:date>2010-12-13T06:58:05Z</dc:date>
    <item>
      <title>ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548773#M615257</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would like to know if DNS doctoring is supported with static pat or only static nat .if it is supported with Static PAT does it support both (i.e interface as well as a free public ip ).below is an eg. in which i have mentioned the interface keyword in static statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,Public) tcp interface 25 10.10.1.1 25 dns&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:20:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548773#M615257</guid>
      <dc:creator>jvardhan29</dc:creator>
      <dc:date>2019-03-11T19:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548774#M615260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS doctoring is supported only in static 1-1 NAT. Not is static PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Dec 2010 13:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548774#M615260</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-11T13:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548775#M615264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks KS , I was reading the document where below is mentioned .&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"DNS rewrite is not compatible with static Port Address Translation (PAT) because multiple PAT rules are applicable for each A-record, and the PAT rule to use is ambiguous. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please let me know exact meaning of above .though it says it is not compatible but does that mean it can be still used ? also what do we mean by "multiple PAT rules are applicable for each A-record"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Dec 2010 06:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548775#M615264</guid>
      <dc:creator>jvardhan29</dc:creator>
      <dc:date>2010-12-13T06:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548776#M615266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any idea on below question related to static pat .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 10:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548776#M615266</guid>
      <dc:creator>jvardhan29</dc:creator>
      <dc:date>2010-12-23T10:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548777#M615269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA rewrites the DNS reply which contains the external IP address with the internal IP address. The DNS request and reply don't contain port numbers but one external IP address can translate to multiple inside addresses based on port numbers. This is the reason DNS doctoring is not supported.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To make a server on the inside available on it's outside IP address you can create this static:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,inside) tcp x.x.x.x 25 10.10.1.1 25 where x.x.x.x &lt;/STRONG&gt;is the IP address of your outside interface&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (inside) y interface&lt;/STRONG&gt; where y matches the &lt;STRONG&gt;nat (inside) y&lt;/STRONG&gt; statement&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way if a pc connects to the external IP address the destination address is translated to 10.10.1.1 and the source address is translated to the IP address of the inside interface. This is necessary because the returning traffic needs to go through the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 10:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548777#M615269</guid>
      <dc:creator>jgraafmans</dc:creator>
      <dc:date>2010-12-23T10:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548778#M615271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;static (inside,Public) tcp interface 25 10.10.1.1 25 dns&lt;/P&gt;&lt;P&gt;static (inside,Public) tcp interface 80 10.20.1.1 80 dns&lt;/P&gt;&lt;P&gt;static (inside,Public) tcp interface 8080 10.30.1.1 8080 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e-mail servers A record is mail.abc.com&lt;/P&gt;&lt;P&gt;webserver's A record is www.abc.com&lt;/P&gt;&lt;P&gt;8080 server's A record is apache.abc.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All resolving to the same interface IP address. Now the inside host wants to go to &lt;A href="https://community.cisco.com/www.abc.com" target="_blank"&gt;www.abc.com&lt;/A&gt; which the outside dns server resolves to the interface IP address with dns doctoring enabled which inside server will the ASA send the traffic to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This simply is not supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Dont' miss my ATE event: &lt;/SPAN&gt;&lt;A class="jive-link-community-small" href="https://community.cisco.com/community/netpro/ask-the-expert"&gt;https://supportforums.cisco.com/community/netpro/ask-the-expert&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 16:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548778#M615271</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-23T16:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548779#M615274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that is what i was looking for ! thanks to both .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have one more question , some of the configuration related to dns are mentioned below but i was not able to find why is "dns" used here for ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Private) 1 0.0.0.0 0.0.0.0 dns&lt;/P&gt;&lt;P&gt;global (Public) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also is there any possibility that in the below config at any point of time nat (Public) 3 access-list MYACL dns , being used ? i.e is the below config relevant or irrelevant ?what is the use of dns keyword here ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where MYACL access-list (consists of VPN clients network) coming to the ASA private network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Public) 3 access-list MYACL dns&lt;/P&gt;&lt;P&gt;access-list MYACL permit ip 172.16.10.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list NONAT permit ip any 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (Private) 0 access-list NONAT&lt;/P&gt;&lt;P&gt;global (Public) 3 interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 10:15:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548779#M615274</guid>
      <dc:creator>jvardhan29</dc:creator>
      <dc:date>2010-12-24T10:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548780#M615277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For both 1 and 2 the use of the keyword dns is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Honestly the use of it when used with static makes more sense than used in the nat statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May be in case of dynamic nat and not dynamic pat, this makes sense where the dns replies coming back from a dns server that contains the global address, it will be changed to the real ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 14:34:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548780#M615277</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-24T14:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA static pat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548781#M615279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for clarification !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 08:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-pat/m-p/1548781#M615279</guid>
      <dc:creator>jvardhan29</dc:creator>
      <dc:date>2010-12-27T08:54:26Z</dc:date>
    </item>
  </channel>
</rss>

