<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NATto Remote Desktop Protocol in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567884#M695751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NAT from ASA version 8.3 onwards has completely changed, it has changed to the following 2 NAT concepts:&lt;/P&gt;&lt;P&gt;1) Network object NAT&lt;/P&gt;&lt;P&gt;2) Twice NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are familiar with NAT on ASA on the previous version, you might need to read the following documentation for version 8.3 onwards for NAT order of operation:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118157"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118157&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Network object NAT: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_objects.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_objects.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Twice NAT: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Sep 2010 09:40:38 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-09-20T09:40:38Z</dc:date>
    <item>
      <title>NATto Remote Desktop Protocol</title>
      <link>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567880#M695747</link>
      <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Hi, I am new to ASA, especially to ASDM 8.3.1 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;As the topology show, I would like to setup a rule and NAT for user at public IP remote to the dedicate machine, using port 3389 (RDP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Pubic network (int outside 202,152,80.34 ) &lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="font-family: Wingdings;"&gt;&lt;SPAN&gt;-&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt;STATIC NAT --&amp;gt; 10.10.100.100, port 3389&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;What’s the step I should deal with it? I am confuse with GUI setting, is it compulsory ask to create network object for doing NATTING? (very different from previous GUI setting) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;So for my case, how likely I can use the GUI to do on it. While if it’s success I can console and check on the CLI for the configuration made and learn on it&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567880#M695747</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2019-03-11T18:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: NATto Remote Desktop Protocol</title>
      <link>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567881#M695748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is how you would configure it:&lt;/P&gt;&lt;P&gt;Via ASDM:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;Please see attached word screen shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Via CLI:&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;object network obj-RDP-10.10.100.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;host 10.10.100.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;nat (inside,outside) static interface service tcp 3389 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 06:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567881#M695748</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-20T06:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: NATto Remote Desktop Protocol</title>
      <link>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567882#M695749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to the NAT you will need to make sure that you add an access-list to the outside interface to the REAL IP. (This is new in 8.3 as before you created an access-list to the MAPPED IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With normal outside interface naming conventions, it will usually look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;access-list outside_access_in permit tcp &lt;SOURCE to="" allow=""&gt; host 10.10.100.100 eq 3389&lt;/SOURCE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 09:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567882#M695749</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-09-20T09:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: NATto Remote Desktop Protocol</title>
      <link>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567883#M695750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi halijenn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the reply, i will test it out after hour (cannot conduct any testing on production time...) but anyhow, i never do the attemp same like what you showing on the screenshot do...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i hope you can give more idea on how to do on ASA - NAT. (i'm ok with fundamental routing &amp;amp; switching part, but i am still very fresh with ASA, esp ASDM GUI..)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(1) normal practice doing firewalling, first is it need to define the network object and service object, so that these element can let for re-use on either ACL or NAT section,rite? then only we go for ACL, for lower security-level interface would like go inside interface etc etc...then come to NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(2) assuming this topology, 2 interface (inside, outside). i just wonder why once i create NAT then it will auto treat my source and destination network be part of any new object ? it seems like defeat my (1) step action, making duplicated on the network object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(3) for firewall&amp;nbsp; &amp;gt; NAT rules, how to configure on "Add NAT Rulebefore /after network onect NAT rules.." mean?&amp;nbsp; (attachment)&lt;/P&gt;&lt;P&gt;It just confuse me why original packet with soure and destination address, then action:translate packet also with source and destination address..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(4) once i do in CLI, natting now seem only can do on network object..i am more on old school like static (inside, outside)...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;confuse..hope u can guide&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 09:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567883#M695750</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2010-09-20T09:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: NATto Remote Desktop Protocol</title>
      <link>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567884#M695751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NAT from ASA version 8.3 onwards has completely changed, it has changed to the following 2 NAT concepts:&lt;/P&gt;&lt;P&gt;1) Network object NAT&lt;/P&gt;&lt;P&gt;2) Twice NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are familiar with NAT on ASA on the previous version, you might need to read the following documentation for version 8.3 onwards for NAT order of operation:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118157"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118157&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Network object NAT: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_objects.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_objects.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Twice NAT: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_rules.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 09:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/natto-remote-desktop-protocol/m-p/1567884#M695751</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-20T09:40:38Z</dc:date>
    </item>
  </channel>
</rss>

