<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-question/m-p/3791693#M7355</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assuming this is 8.3 or later code it is probably to do with the ordering of your NAT statements.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On 8.3 or later NAT is split in 3 sections and it goes through the sections in order so what is probably happening is that the traffic outbound is being caught by the wrong NAT statement and the solution may be as simple as reordering your statements.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a read of this document which explains the above in more detail and gives some recommendations as to how to configure your NAT statements -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050" target="_self"&gt;https://community.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jan 2019 22:17:07 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2019-01-30T22:17:07Z</dc:date>
    <item>
      <title>NAT Question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/3791676#M7352</link>
      <description>&lt;P&gt;Our ISP has issued us two subnets: one is a /30 subnet and the other is a /28. For the sake of this discussion (with false IPs) the /30 is 46.181.101.212/30 with the provider&amp;nbsp;assigned .213 and our WAN on .214. The /28 is &lt;SPAN&gt;46.181.101&lt;/SPAN&gt;&lt;SPAN&gt;.112/28. They are routing the 46.181.101.112/28 to our WAN interface. We have NAT for all users to come from our WAN (48.181.101.214) with a default route pointing to 48.181.101.213. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have a server on our internal network using 10.0.0.25. In the case of this one particular server however, we need the&amp;nbsp;external servers&amp;nbsp;to see our traffic residing from 46.181.101.118 (the /28 subnet). So a NAT for inside address 10.0.0.25 to 46.181.101.118.&amp;nbsp;We cannot seem to get this to work. No matter what we add for the NAT the traffic is still seen as coming from 46.181.101.214. We are able to connect into this server from the outside on 46.181.101.118 so it is only how our traffic is seen externally that we are having an issue with.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can anyone give us some insight? Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/3791676#M7352</guid>
      <dc:creator>Legusol</dc:creator>
      <dc:date>2020-02-21T16:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/3791693#M7355</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assuming this is 8.3 or later code it is probably to do with the ordering of your NAT statements.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On 8.3 or later NAT is split in 3 sections and it goes through the sections in order so what is probably happening is that the traffic outbound is being caught by the wrong NAT statement and the solution may be as simple as reordering your statements.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a read of this document which explains the above in more detail and gives some recommendations as to how to configure your NAT statements -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050" target="_self"&gt;https://community.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 22:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/3791693#M7355</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2019-01-30T22:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/3791709#M7358</link>
      <description>&lt;P&gt;Hi Jon, I thought about that previously and created the NAT as a NAT before Network Object and moved it all the way to the top of the list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot.331.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29019i0C10D7303CEE69B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="screenshot.331.png" alt="screenshot.331.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot.332.png" style="width: 600px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29020iB3C59861D93B564E/image-size/large?v=v2&amp;amp;px=999" role="button" title="screenshot.332.png" alt="screenshot.332.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run a packettracer test as well is shows that it should be picking up this NAT.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot.333.png" style="width: 750px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29021iC2ED550D9BD24C24/image-size/large?v=v2&amp;amp;px=999" role="button" title="screenshot.333.png" alt="screenshot.333.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 22:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/3791709#M7358</guid>
      <dc:creator>Legusol</dc:creator>
      <dc:date>2019-01-30T22:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/3791737#M7360</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have a server on our internal network using 10.0.0.25. In the case of this one particular server however, we need the&amp;nbsp;external servers&amp;nbsp;to see our traffic residing from 46.181.101.118 (the /28 subnet). So a NAT for inside address 10.0.0.25 to 46.181.101.118.&amp;nbsp;We cannot seem to get this to work. No matter what we add for the NAT the traffic is still seen as coming from 46.181.101.214. We are able to connect into this server from the outside on 46.181.101.118 so it is only how our traffic is seen externally that we are having an issue with.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;object network REAL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;host 10.0.0.25&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;object network MAPPED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;host 46.181.101.214&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;nat (inside,outside) source static REAL MAPPED&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list OUT-IN exten permit tcp any object REAL eq 443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-group OUT-IN in interface outside&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 23:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/3791737#M7360</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-30T23:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/3792256#M7362</link>
      <description>&lt;P&gt;This was actually a "stupid" mistake on my part. We are in the process of changing to a new server for this and when I was setting up the NAT I was using the new server inside IP address but I still had the old server relaying the traffic. So in essence, I have the NAT set up correctly, I was just using the wrong IP address for the REAL server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just needed an overnight break to realize that!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you both. I accept both as a resolution since NAT was the issue the the commands provide by Sheraz were correct. Thank you both!&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 15:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/3792256#M7362</guid>
      <dc:creator>Legusol</dc:creator>
      <dc:date>2019-01-31T15:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/3792258#M7365</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/353200"&gt;@Legusol&lt;/a&gt;I did noticed that wrong ip address in your packet tracer and i was curious why you doing this. also i was tired too and this also get over looked from me other wise i have mentioned to you.&lt;/P&gt;&lt;P&gt;anyway good to hear all sorted.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 15:15:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/3792258#M7365</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-31T15:15:17Z</dc:date>
    </item>
  </channel>
</rss>

