<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-rules/m-p/1488238#M640972</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are just changing the interface of the router from 192.9.200.253 to 10.10.10.10, as far as the NAT statement is concern, you do not need to change anything. All you need to do on the router is to configure route for 192.9.200.0/24 subnet to point towards the ASA external ip address (10.10.10.11).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you are having the following topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal network (192.9.200.0/24) -- (Inside) ASA (Outside) -- (Inside) router (Outside) -- Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA, you would need to configure NAT exemption, or a static statement to itself.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.9.200.0 192.9.200.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR/ alternatively&lt;/P&gt;&lt;P&gt;access-list nonat permit ip 192.9.200.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jun 2010 13:05:10 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-06-25T13:05:10Z</dc:date>
    <item>
      <title>NAT Rules</title>
      <link>https://community.cisco.com/t5/network-security/nat-rules/m-p/1488237#M640971</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At present I'm installing a ASA firewall between my 2811 router and the network.&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;The router at the moment has an internal ip address of 192.9.200.253 and has NAT rules set up. The 192.9.200.254 address is that of our exchange server. My question is this. If I change the internal interface of the router to 10.10.10.10 and the external interface of the ASA to 10.10.10.11 and the internal interface of the ASA has the 192.9.200.253 address, what do I do about the NAT rules? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;ip nat inside source route-map SDM_RMAP_1 interface Dialer1 overload&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;ip nat inside source static tcp 192.9.200.254 25 *.*.*.*25 route-map Deny-VPN extendable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;ip nat inside source static tcp 192.9.200.254 80 *.*.*.* 80 route-map Deny-VPN extendable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;ip nat inside source static tcp 192.9.200.254 143 *.*.*.* 143 route-map Deny-VPN extendable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;ip access-list extended Deny-VPN&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt; permit ip 192.9.200.0 0.0.1.255 6.0.0.0 0.0.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;access-list 105 remark SDM_ACL Category=2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;access-list 105 remark IPSec Rule&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip 192.9.200.0 0.0.0.255 6.0.0.0 0.0.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip 192.9.200.0 0.0.1.255 172.31.0.0 0.0.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;access-list 105 permit ip 192.9.200.0 0.0.0.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;route-map Deny-VPN deny 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt; match ip address Deny-VPN&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;route-map SDM_RMAP_1 permit 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt; match ip address 105&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;I've attached the complete config below &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri; "&gt;Egg&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rules/m-p/1488237#M640971</guid>
      <dc:creator>Eggzter100</dc:creator>
      <dc:date>2019-03-11T18:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Rules</title>
      <link>https://community.cisco.com/t5/network-security/nat-rules/m-p/1488238#M640972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are just changing the interface of the router from 192.9.200.253 to 10.10.10.10, as far as the NAT statement is concern, you do not need to change anything. All you need to do on the router is to configure route for 192.9.200.0/24 subnet to point towards the ASA external ip address (10.10.10.11).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you are having the following topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal network (192.9.200.0/24) -- (Inside) ASA (Outside) -- (Inside) router (Outside) -- Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA, you would need to configure NAT exemption, or a static statement to itself.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.9.200.0 192.9.200.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR/ alternatively&lt;/P&gt;&lt;P&gt;access-list nonat permit ip 192.9.200.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 13:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rules/m-p/1488238#M640972</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-25T13:05:10Z</dc:date>
    </item>
  </channel>
</rss>

