<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nat outside inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412377#M684643</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, for the whole subnet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-172.16.16.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-188.156.65.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 188.156.65.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (inside,inside) static ojb-172.16.16.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Mar 2010 06:05:00 GMT</pubDate>
    <dc:creator>thorstenn</dc:creator>
    <dc:date>2010-03-30T06:05:00Z</dc:date>
    <item>
      <title>nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412370#M684636</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have two external ip ranges. From outside everything is reachable but from inside i cannot reach the external ip. But in some cases this is neccesary. i have an asa 55xx wit the latest os. How can i configure the asa to let internal clients reach the external ip ranges from inside? Do i need a static nat rule for this? Have someone an example for me? Thanks and regards.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412370#M684636</guid>
      <dc:creator>thorstenn</dc:creator>
      <dc:date>2019-03-11T17:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412371#M684637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;x.x.x.x = external ip&lt;/P&gt;&lt;P&gt;y.y.y.y = internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;static (inside,inside) x.x.x.x y.y.y.y netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Mar 2010 13:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412371#M684637</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2010-03-29T13:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412372#M684638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for asa version 8.3 these commands won`t work i think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Mar 2010 16:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412372#M684638</guid>
      <dc:creator>thorstenn</dc:creator>
      <dc:date>2010-03-29T16:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412373#M684639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;Old 8.2 and older Dynamic PAT:&lt;BR /&gt;&lt;BR /&gt;nat (inside) 1 0 0 &lt;BR /&gt; global (outside) 1 interface&lt;BR /&gt;&lt;BR /&gt;#################################&lt;BR /&gt;&lt;BR /&gt;New 8.3 dynamic PAT.&lt;BR /&gt; object network obj_any&lt;BR /&gt;&amp;nbsp;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic interface&lt;BR /&gt;&lt;BR /&gt;-KS&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 02:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412373#M684639</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-30T02:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412374#M684640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I wounder if you can show us more detail ? It's hard to tell where goes wrong without the configuration .&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 02:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412374#M684640</guid>
      <dc:creator>Lunzhicheng7</dc:creator>
      <dc:date>2010-03-30T02:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412375#M684641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For example i have an internal server with 172.16.16.10 with a service on port 5467 for an outside ip 188.156.65.100 with the same port. From a host inside the network with the ip 172.16.16.233 i can perform a "telnet 172.16.16.10 5467" session with an answer from the service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From outside everything fine too. But sometimes there is a need from internal to reach the external ip from INSIDE the lan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, a host with 172.16.16.233 need to telnet the "188.156.65.100 5467" from inside. And here is the problem, theres is no answer from the service. Do you understand what i mean? &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 188.156.65.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.16.16.1 255.255.0.0&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe for interest, if i look in the asa log while i perform a telnet from inside to the outside ip i see this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; Mar 30 2010&amp;nbsp;&amp;nbsp;&amp;nbsp; 03:30:50&amp;nbsp;&amp;nbsp;&amp;nbsp; 106563&amp;nbsp;&amp;nbsp;&amp;nbsp; 188.156.65.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.16.233&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny icmp src outside:188.156.65.1 dst inside:172.16.16.233 (type 5, code 1) by access-group "global_access" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp; Mar 30 2010&amp;nbsp;&amp;nbsp;&amp;nbsp; 03:30:50&amp;nbsp;&amp;nbsp;&amp;nbsp; 106556&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny IP spoof from (188.156.65.1) to 188.156.65.100 on interface outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 04:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412375#M684641</guid>
      <dc:creator>thorstenn</dc:creator>
      <dc:date>2010-03-30T04:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412376#M684642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;object network obj-188.156.65.100&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 188.156.65.100&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (inside,inside) static 172.16.16.233&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 05:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412376#M684642</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-30T05:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412377#M684643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, for the whole subnet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-172.16.16.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-188.156.65.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 188.156.65.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (inside,inside) static ojb-172.16.16.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 06:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412377#M684643</guid>
      <dc:creator>thorstenn</dc:creator>
      <dc:date>2010-03-30T06:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412378#M684644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are mapping the subnet, it will be translated sequentially, ie:&lt;/P&gt;&lt;P&gt;188.156.65.1 --&amp;gt; 172.16.16.1&lt;/P&gt;&lt;P&gt;188.156.65.2 --&amp;gt; 172.16.16.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have already configured specific translation before, you would need to do 1 IP address for whatever mapping you have configured earlier for the (inside,outside) translation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 06:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412378#M684644</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-30T06:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412379#M684645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not quite sure whether I misunderstood the meaning , In the case of your example , since your internal user (172.16.16.233) need to visit a internal server(172.16.16.10) , the traffic seems no need to go through the firewall , two ip address in the same subnet . If you want the internal users see the server as a Nated address , you may need to add one more translation entry "static (inside,inside) 188.156.65.100 172.16.16.10",meanwhile you need to add "same-security-traffic permit intra-interface"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 06:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412379#M684645</guid>
      <dc:creator>Lunzhicheng7</dc:creator>
      <dc:date>2010-03-30T06:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412380#M684646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok i tried it with single nat and not the whole range but it seems not to work for me, here is what i`ve configured now for the adress:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static 172.16.16.10 188.156.65.100&lt;/P&gt;&lt;P&gt;object network 188.156.65.100&lt;BR /&gt; nat (inside,inside) static 172.16.16.10&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 06:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412380#M684646</guid>
      <dc:creator>thorstenn</dc:creator>
      <dc:date>2010-03-30T06:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: nat outside inside</title>
      <link>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412381#M684647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i have tried this. See my post before.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 07:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outside-inside/m-p/1412381#M684647</guid>
      <dc:creator>thorstenn</dc:creator>
      <dc:date>2010-03-30T07:16:48Z</dc:date>
    </item>
  </channel>
</rss>

