<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA NAT question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493362#M712119</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post the output from:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run nat&lt;/P&gt;&lt;P&gt;sh run global&lt;/P&gt;&lt;P&gt;sh run static&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And let us know which are the real IPs that you want to NAT to which mapped IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 May 2010 16:52:29 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-05-05T16:52:29Z</dc:date>
    <item>
      <title>ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493361#M712118</link>
      <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a ip valid range from my isp&lt;/P&gt;&lt;P&gt;I want to nat my inside users to ip vaid range with dynamic NAT&lt;/P&gt;&lt;P&gt;my outside asa interface has one of these ip valids to see outside world&lt;/P&gt;&lt;P&gt;but the other ip in my range do not belong to any devices..&lt;/P&gt;&lt;P&gt;how is it possible that my clients nat to my all ip range&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also i have a web server in my dmz&lt;/P&gt;&lt;P&gt;i want also make a static but i do not know how can i bind an valid ip into non valid ip&lt;/P&gt;&lt;P&gt;i mean i do not know whre this valid ip must be set!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493361#M712118</guid>
      <dc:creator>hanimolani</dc:creator>
      <dc:date>2019-03-11T17:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493362#M712119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post the output from:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run nat&lt;/P&gt;&lt;P&gt;sh run global&lt;/P&gt;&lt;P&gt;sh run static&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And let us know which are the real IPs that you want to NAT to which mapped IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 May 2010 16:52:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493362#M712119</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-05-05T16:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493363#M712120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say that the ISP has provided the following range:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.1.1.1-1.1.1.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, 1.1.1.1 is assigned to the outside interface. Also, 10.10.10.1 is the dmz web server which you want to publish to the outside world.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 1.1.1.2 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 1.1.1.2 eq 80&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ashu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 May 2010 19:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493363#M712120</guid>
      <dc:creator>astripat</dc:creator>
      <dc:date>2010-05-05T19:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493364#M712122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;umm..&lt;/P&gt;&lt;P&gt;I think there is miss understanding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem is that i have a valid range from my ISP&lt;/P&gt;&lt;P&gt;i want make a nat from my inside network to whole range&lt;/P&gt;&lt;P&gt;but the problem is only one ip from that range is assigned to my outside interface and rest od IP are not assign to any machine or any device&lt;/P&gt;&lt;P&gt;how can make a dynamic nat to this range according that no device or machine assigned to these IP addressess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by the way my ASA verssion is 8.3.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2010 10:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493364#M712122</guid>
      <dc:creator>iliafirewall</dc:creator>
      <dc:date>2010-05-06T10:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493365#M712125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If my understanding of the question is correct you want to NAT inside hosts to public IPs in the range assigned to you &lt;BR /&gt;by your ISP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so you can do it like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 1.1.1.1-1.1.1.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have more inside clients than public IPs, probably best to aslo include a fallback to PAT using the outside interface address:&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2010 16:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493365#M712125</guid>
      <dc:creator>peter.kersting</dc:creator>
      <dc:date>2010-05-06T16:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493366#M712127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear pete&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is where the range IP address must be set?&lt;/P&gt;&lt;P&gt;because these ip valid range address do not belong any thing into my network&lt;/P&gt;&lt;P&gt; thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 May 2010 10:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493366#M712127</guid>
      <dc:creator>hanimolani</dc:creator>
      <dc:date>2010-05-07T10:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT question</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493367#M712137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you would like to use that new IP range for dynamic NAT for your internal users, then you would configure it on the "global (outside)" statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just have to make sure that the router in front of your ASA (connected to the outside interface of the ASA), is routing the new IP range towards the ASA outside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 May 2010 10:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-question/m-p/1493367#M712137</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-07T10:32:47Z</dc:date>
    </item>
  </channel>
</rss>

