<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multiple hosts in policy nat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454161#M637751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can policy PAT traffic from just two hosts to the given IP address (this will only work outbound), but you cannot do it with the configuration above. The policy PAT would look somewhat like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (production) 11 access-list AL200&lt;/P&gt;&lt;P&gt;global (outside) 11 172.16.11.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Aug 2010 20:59:12 GMT</pubDate>
    <dc:creator>Andrew Ossipov</dc:creator>
    <dc:date>2010-08-10T20:59:12Z</dc:date>
    <item>
      <title>multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454156#M637746</link>
      <description>&lt;P&gt;how can i do this:&lt;/P&gt;&lt;P&gt;access-list AL200 permit ip host 172.16.11.27 Units 255.255.192.0 &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.27 Routers 255.255.255.248 &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.27 host IMSA &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.27 host EIserver&lt;/P&gt;&lt;P&gt;access-list AL200 permit ip host 172.16.11.26 host GGSNnew &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.26 Meterpool 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (production,outside) 172.16.11.200 access-list AL200 0 0&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:23:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454156#M637746</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2019-03-11T18:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454157#M637747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Forgot to mention that i need to do this on a Cisco PIX 506e&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 20:16:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454157#M637747</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2010-08-10T20:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454158#M637748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since static NAT creates one-to-one mappings by definition, you cannot translate the traffic from two hosts to the same IP. You need to either provision several mapped addresses for the static mapping or use dynamic policy NAT instead:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/mr.html#wp1032129"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/mr.html#wp1032129&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 20:52:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454158#M637748</guid>
      <dc:creator>Andrew Ossipov</dc:creator>
      <dc:date>2010-08-10T20:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454159#M637749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So what i am trying to do is not possible?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 20:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454159#M637749</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2010-08-10T20:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454160#M637750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so what you are trying to say it is not possible at all? i dont understand could you give me some directions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 20:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454160#M637750</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2010-08-10T20:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454161#M637751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can policy PAT traffic from just two hosts to the given IP address (this will only work outbound), but you cannot do it with the configuration above. The policy PAT would look somewhat like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (production) 11 access-list AL200&lt;/P&gt;&lt;P&gt;global (outside) 11 172.16.11.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 20:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454161#M637751</guid>
      <dc:creator>Andrew Ossipov</dc:creator>
      <dc:date>2010-08-10T20:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454162#M637752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you so much this worked as a charm.&lt;/P&gt;&lt;P&gt;What kind off problems could this give?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454162#M637752</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2010-08-10T21:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454163#M637753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad it helped! It is a fairly standard NAT configuration, so it should work without problems. The only caveat is that you cannot initiate reverse connections from outside between the hosts and subnets identified in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454163#M637753</guid>
      <dc:creator>Andrew Ossipov</dc:creator>
      <dc:date>2010-08-10T21:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454164#M637754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are unable to do this in PIX506 - 6.x code?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:13:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454164#M637754</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-10T21:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454165#M637755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont really understand your last post. Does this mean no traffic could come in on 172.16.11.200?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454165#M637755</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2010-08-10T21:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454166#M637756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct, you cannot initiate inbound connections to 172.16.11.200. This is the main property of dynamic PAT. In order to initiate inbound connections, you must have one-to-one mapping with either one IP per inside host or one port per inside service (static PAT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454166#M637756</guid>
      <dc:creator>Andrew Ossipov</dc:creator>
      <dc:date>2010-08-10T21:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454167#M637757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmmmm thats gonna be a problem cause these rules initiate from both sides:&lt;/P&gt;&lt;P&gt;access-list AL200 permit ip host 172.16.11.26 host TMGGSNnew &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.26 TMmeterpool 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i there a work-around for this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454167#M637757</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2010-08-10T21:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454168#M637758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The workaround is to dedicate one mapped (public) IP to each inside (private) host. I.e.:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list AL200 permit ip host 172.16.11.27 Units 255.255.192.0 &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.27 Routers 255.255.255.248 &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.27 host IMSA &lt;BR /&gt;access-list AL200 permit ip host 172.16.11.27 host EIserver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list AL201 permit ip host 172.16.11.26 host GGSNnew &lt;BR /&gt;access-list AL201 permit ip host 172.16.11.26 Meterpool 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (production,outside) 172.16.11.200 access-list AL200&lt;/P&gt;&lt;P&gt;static (production,outside) 172.16.11.201 access-list AL201&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454168#M637758</guid>
      <dc:creator>Andrew Ossipov</dc:creator>
      <dc:date>2010-08-10T21:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: multiple hosts in policy nat</title>
      <link>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454169#M637759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;172.16.11.201 doesnt have access to the VPNs... so thats a no go...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that on the old server we had 2 environments which went to 3 VPNS... all using the 200 NAT. Now we made two new server (1 goes to 2 vpns and 1 goes to the third). They still need to do so with the 200 NAT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2010 21:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-hosts-in-policy-nat/m-p/1454169#M637759</guid>
      <dc:creator>RvanRouwendaal</dc:creator>
      <dc:date>2010-08-10T21:29:26Z</dc:date>
    </item>
  </channel>
</rss>

