<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nat-control in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496691#M658944</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat-control (or no nat-control) is a way of enforcing the NAT requirements&lt;/P&gt;&lt;P&gt;on the Cisco Firewall (pre 8.3 code versions). If you configure nat-control,&lt;/P&gt;&lt;P&gt;then the firewall enforce the rule that every packet going from higher&lt;/P&gt;&lt;P&gt;security to lower security needs a NAT rule configured. If you configure "no&lt;/P&gt;&lt;P&gt;nat-control", then the firewall will not enforce the NAT requirement as long&lt;/P&gt;&lt;P&gt;as you have not configured any NAT rule for a specific traffic flow on that&lt;/P&gt;&lt;P&gt;interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example091&lt;/P&gt;&lt;P&gt;86a008046f31a.shtml#backinfo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 28 Aug 2010 22:17:52 GMT</pubDate>
    <dc:creator>Nagaraja Thanthry</dc:creator>
    <dc:date>2010-08-28T22:17:52Z</dc:date>
    <item>
      <title>nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496690#M658942</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Can someone explain me what is the use of command nat-control and no nat-controm on ASA. As I am newbie to ASA.&lt;/P&gt;&lt;P&gt;I tried to search a lot on internet but I didn't simple and explainative answer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can anyone help me out&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496690#M658942</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2019-03-11T18:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496691#M658944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat-control (or no nat-control) is a way of enforcing the NAT requirements&lt;/P&gt;&lt;P&gt;on the Cisco Firewall (pre 8.3 code versions). If you configure nat-control,&lt;/P&gt;&lt;P&gt;then the firewall enforce the rule that every packet going from higher&lt;/P&gt;&lt;P&gt;security to lower security needs a NAT rule configured. If you configure "no&lt;/P&gt;&lt;P&gt;nat-control", then the firewall will not enforce the NAT requirement as long&lt;/P&gt;&lt;P&gt;as you have not configured any NAT rule for a specific traffic flow on that&lt;/P&gt;&lt;P&gt;interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example091&lt;/P&gt;&lt;P&gt;86a008046f31a.shtml#backinfo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Aug 2010 22:17:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496691#M658944</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-28T22:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496692#M658945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your fast response&lt;/P&gt;&lt;P&gt;I would like to let you know that the link you provided is not available&lt;/P&gt;&lt;P&gt;What I understand from your explanation&amp;nbsp; when we dont want to use NAT from High Security-level interface to low security interface level. For instance. from inside to dmz.&lt;/P&gt;&lt;P&gt;Can you give me an example for further clarification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks I really appreciate &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Aug 2010 23:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496692#M658945</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2010-08-28T23:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496693#M658951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link again:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://tinyurl.com/dmvylq&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, essentially, when you disable nat-control, you are allowed to go from&lt;/P&gt;&lt;P&gt;higher security interface to lower security interface without NAT. For&lt;/P&gt;&lt;P&gt;example, let us say you have a public IP range on your inside network and&lt;/P&gt;&lt;P&gt;DMZ network. Then, you actually do not need any NAT. So, you could disable&lt;/P&gt;&lt;P&gt;NAT control. The other scenario I can think of is if you have firewall just&lt;/P&gt;&lt;P&gt;to protect different network segments and you have a different device that&lt;/P&gt;&lt;P&gt;is handling NAT. In that case, again you can use "no nat-control". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://tinyurl.com/6gcquh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Aug 2010 23:16:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496693#M658951</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-28T23:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496694#M658957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Assume that I have internal hosts and I want to allow them to access a Web Server residing in DMZ segment, And this server has Private IP address for eg:172.16.1.5. Therfore in that case I can use exempt nat, this is what explaination I got after surfing on the web.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advice. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Aug 2010 00:08:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496694#M658957</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2010-08-29T00:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496695#M658964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That depends upon your requirement. You could hide your internal clients&lt;/P&gt;&lt;P&gt;behind a DMZ address by using NAT (if you want it to be more secure) or you&lt;/P&gt;&lt;P&gt;can certainly use NAT exemption. One drawback of NAT exemption (access-list&lt;/P&gt;&lt;P&gt;based nat 0 configuration) is that it will allow bi-directional connection. &lt;/P&gt;&lt;P&gt;So, anybody from DMZ can open connections to your internal network. Dynamic&lt;/P&gt;&lt;P&gt;PAT on the DMZ interface will ensure that nobody is allowed to open an&lt;/P&gt;&lt;P&gt;unauthorized connection from DMZ to inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the reverse path, if you would like, you can force all your internal&lt;/P&gt;&lt;P&gt;clients to browse that server using its public IP as well. If you have an&lt;/P&gt;&lt;P&gt;internal DNS server that resolves all DNS queries for your domain, you have&lt;/P&gt;&lt;P&gt;the freedom of setting the A record for your website and set either public&lt;/P&gt;&lt;P&gt;IP or private IP based on your requirements. If you decide that you want to&lt;/P&gt;&lt;P&gt;use public IP, then you will need to use Static NAT. If you want to use&lt;/P&gt;&lt;P&gt;private IP, then you do not need to do anything. But if you want to use both&lt;/P&gt;&lt;P&gt;addresses, then you need to make use of policy-nat configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Aug 2010 00:17:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496695#M658964</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-29T00:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496696#M658970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;Great,It was quite informative. I will be very thankfull if you can give me some command reference to configure Dynamic and Static NAT and ACL lists to accomplish this configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Aug 2010 00:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496696#M658970</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2010-08-29T00:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496697#M658978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the links again:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://tinyurl.com/dmvylq&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://tinyurl.com/6gcquh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first link has few examples and corresponding configuration commands.&lt;/P&gt;&lt;P&gt;Second one is a command reference guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Aug 2010 00:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496697#M658978</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-29T00:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: nat-control</title>
      <link>https://community.cisco.com/t5/network-security/nat-control/m-p/1496698#M658994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I will implement in my environment and do some tests. I will keep you update.Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Aug 2010 00:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-control/m-p/1496698#M658994</guid>
      <dc:creator>samirshaikh52</dc:creator>
      <dc:date>2010-08-29T00:44:14Z</dc:date>
    </item>
  </channel>
</rss>

