<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Configuration using Natting -- require help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493676#M676469</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I am trying to do is that traffic initiated from the inside will use the PAT address and traffic initiated from the outside will use the static NAT. But in this case if traffic is initiated from inside it will still use the static NAT since static NAT is preferred above the PAT. Am I correct on that? If so then the pat address is not required&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Aug 2010 04:07:46 GMT</pubDate>
    <dc:creator>sidcracker</dc:creator>
    <dc:date>2010-08-17T04:07:46Z</dc:date>
    <item>
      <title>VPN Configuration using Natting -- require help</title>
      <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493674#M676463</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Router VPN has multiple VPNS that are initiated to the customers. The ASA handles the ACLS and Natting part of the VPN and the VPN device handles the policies and encryption/decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For each Site to Site VPN a new pool is assigned on the VPN interface for static natting and PAT. Example for VPN XYZ we would define a new pool 172.16.20.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All traffic via the VPN will be first entering the router VPN and then the ASA. All traffic not in the VPN will come directly from the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two hosts on the inside interface which needs to be access by the remote network of another site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am i correct to use the following configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ALL IP ADDRESS and NAMES HAVE BEEN CHANGED&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ON THE ASA FIREWALL&lt;/P&gt;&lt;P&gt;========================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***********************************************************************&lt;/P&gt;&lt;P&gt;Allowing the inside host to access the remote host&lt;/P&gt;&lt;P&gt;***********************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list site_to_site_vpn extended permit ip object-group inside_hosts host 192.168.0.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*************************************&lt;/P&gt;&lt;P&gt;To be natted to 172.16.20.20&lt;/P&gt;&lt;P&gt;*************************************&lt;/P&gt;&lt;P&gt;nat (inside) 100 access-list site_to_site-vpn&lt;/P&gt;&lt;P&gt;global (vpn) 100 172.16.20.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;Allowing the remote host 192.168.0.100 to access the inside hosts which is continuation of the above session&lt;/P&gt;&lt;P&gt;********************************************************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list vpn_to_asa extended permit tcp host 192.168.0.100 object-group inside_hosts range 700 800&lt;BR /&gt;access-list vpn_to_asa extended permit tcp host 192.168.0.100 object-group inside_hosts eq 234&lt;BR /&gt;access-list vpn_to_asa extended permit tcp host 192.168.0.100 object-group inside_hosts eq 567&lt;BR /&gt;access-list vpn_to_asa extended permit tcp host 192.168.0.100 object-group inside_hosts eq 911&lt;BR /&gt;access-list vpn_to_asa extended permit tcp host 192.168.0.100 object-group inside_hosts eq 2345&lt;BR /&gt;access-list vpn_to_asa extended permit tcp host 192.168.0.100 object-group inside_hosts eq 6456&lt;BR /&gt;access-list vpn_to_asa extended permit tcp host 192.168.0.100 object-group inside_hosts eq 543&lt;BR /&gt;access-list vpn_to_asa extended permit udp host 192.168.0.100 object-group inside_hosts eq 744&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(The access-list is mapped to the VPN interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*********************************************************************************************************************&lt;/P&gt;&lt;P&gt;When remote hosts are initiating connection, they will access the static nat to reach the inside hosts&lt;/P&gt;&lt;P&gt;*********************************************************************************************************************&lt;/P&gt;&lt;P&gt;access-list site_to_site_staticnat_1 extended permit ip host 192.168.20.10 host 192.168.0.100&lt;BR /&gt;access-list site_to_site_staticnat_2 extended permit ip host 192.168.20.11 host 192.168.0.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,vpn) 172.16.20.21 access-list site_to_site_staticnat_1&lt;BR /&gt;static (inside,vpn) 172.16.20.22 access-list site_to_site_staticnat_2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ON THE ROUTER VPN&lt;/P&gt;&lt;P&gt;====================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended site_to_site_vpn_cryptomap&lt;BR /&gt; permit ip 172.16.20.0 0.0.0.255 192.168.0.100 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (outside)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;192.168.20.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.18.0(VPN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |--------------------|-------------|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |-------------------------------------&lt;/P&gt;&lt;P&gt;------|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |20.20.20.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |-----------------|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Router VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |----------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |---------------------------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |------------------------------------|&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; 192.168.10.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.12.0&amp;nbsp;&amp;nbsp; (DMZ1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (DMZ 2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this configuration is correct..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493674#M676463</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2019-03-11T18:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration using Natting -- require help</title>
      <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493675#M676466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the configuration looks correct apart from the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 100 access-list site_to_site-vpn&lt;/P&gt;&lt;P&gt;global (vpn) 100 172.16.20.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not quite sure what the above is trying to achieve since you already have the static policy NAT configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 03:35:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493675#M676466</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-17T03:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration using Natting -- require help</title>
      <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493676#M676469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All I am trying to do is that traffic initiated from the inside will use the PAT address and traffic initiated from the outside will use the static NAT. But in this case if traffic is initiated from inside it will still use the static NAT since static NAT is preferred above the PAT. Am I correct on that? If so then the pat address is not required&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 04:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493676#M676469</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2010-08-17T04:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration using Natting -- require help</title>
      <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493677#M676474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are absolutely correct. Static policy NAT will take precedence over policy NAT, hence the PAT address becomes redundant unless you require all the other internal ip subnets but 192.168.20.10 and 192.168.20.11 to initiate connection towards 192.168.0.100, then in this case, they will get PATed to 172.16.20.20.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 04:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493677#M676474</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-17T04:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration using Natting -- require help</title>
      <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493678#M676479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your quick responses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 04:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493678#M676479</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2010-08-17T04:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration using Natting -- require help</title>
      <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493679#M676483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just another clarification.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The ACLS provided in the configuration should allow traffic from the remote end to access the internal hosts right? I dont need to add any other ACLS even if i remove the nat globals from the configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 04:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493679#M676483</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2010-08-17T04:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Configuration using Natting -- require help</title>
      <link>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493680#M676486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, that's right.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 04:55:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-configuration-using-natting-require-help/m-p/1493680#M676486</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-17T04:55:27Z</dc:date>
    </item>
  </channel>
</rss>

