<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nat in router or firewall? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356077#M728249</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what they say:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Cisco Validated Design and best practices recommended dedicating only security features on the ASA. And they propose removing current NAT on the ASA and putting in on the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Mar 2010 13:38:16 GMT</pubDate>
    <dc:creator>Mon Baul</dc:creator>
    <dc:date>2010-03-19T13:38:16Z</dc:date>
    <item>
      <title>Nat in router or firewall?</title>
      <link>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356075#M728247</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; could anyone confirm if doing the NAT in the router is better that doing it in a firewall?because someone told me this is the best practice from cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; My topology below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; CoreSwitch==&amp;gt;edge switch--&amp;gt;ASA--&amp;gt;Boarder router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Note: i have server in dmz configured in ASA and accessible thru internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;reymon&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356075#M728247</guid>
      <dc:creator>Mon Baul</dc:creator>
      <dc:date>2019-03-11T17:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Nat in router or firewall?</title>
      <link>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356076#M728248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't see the difference configuring it on router or ASA. Most people configured NAT on their ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Mar 2010 12:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356076#M728248</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-19T12:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Nat in router or firewall?</title>
      <link>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356077#M728249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what they say:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Cisco Validated Design and best practices recommended dedicating only security features on the ASA. And they propose removing current NAT on the ASA and putting in on the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Mar 2010 13:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356077#M728249</guid>
      <dc:creator>Mon Baul</dc:creator>
      <dc:date>2010-03-19T13:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Nat in router or firewall?</title>
      <link>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356078#M728250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess it really depends on what you will be using the NAT for, as there is a number of application inspection that ASA is more superior of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;For example&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;You are NATing your FTP server, and ASA is configured to inspect FTP traffic so it will dynamically open a pin hole for the FTP data connection.&lt;/P&gt;&lt;P&gt;If you perform the same on the router, first of all, for tighter security, you would need to create access-list, and then either CBAC or ZBFW to inspect the traffic. Router main functionality is performing routing, with the above example, you have just added security feature on the router which is not very efficient since you already have ASA firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Mar 2010 22:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356078#M728250</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-19T22:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Nat in router or firewall?</title>
      <link>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356079#M728251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;configuring policy nat, dynamic nat, nat exemption, outside nat, destination nat, static 1-1, policy static all of these can be easily done on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say do the nat on the ASA and let the router do what is is betst to do which is routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Mar 2010 22:38:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356079#M728251</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-19T22:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Nat in router or firewall?</title>
      <link>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356080#M728252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree to both of you:) Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Mar 2010 12:57:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-in-router-or-firewall/m-p/1356080#M728252</guid>
      <dc:creator>Mon Baul</dc:creator>
      <dc:date>2010-03-20T12:57:02Z</dc:date>
    </item>
  </channel>
</rss>

