<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-help/m-p/1384552#M777051</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would a NAT work, I looked at you link and it looks very similar to a NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I trid to do a Static NAT, but the packet trace should the trafic going out to the internet which I don't want happening:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;info example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interfaces:&lt;/P&gt;&lt;P&gt;inside (192.168.1.1)&lt;/P&gt;&lt;P&gt;outside (100.100.100.1)&lt;/P&gt;&lt;P&gt;VLAN1 (172.25.1.x)&lt;/P&gt;&lt;P&gt;VLAN2 (192.168.15.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently we have a NAT for 100.100.100.2 &amp;gt; 192.168.15.8 from the Outside to VLAN2 web server.&amp;nbsp; We want VLAN2 to ba able to contact 100.100.100.2 and not go out on the global IP.&amp;nbsp; I added '&lt;STRONG&gt;static (VLAN1,VLAN2) 192.168.15.8 100.100.100.2 netmask 255.255.255.255 dns tcp 0 0 udp 0&lt;/STRONG&gt;' but the traffic goes to the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought anything on VLAN1 trying to get to 100.100.100.2 would translate to 192.168.15.8?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Dec 2009 14:44:39 GMT</pubDate>
    <dc:creator>Andy White</dc:creator>
    <dc:date>2009-12-14T14:44:39Z</dc:date>
    <item>
      <title>NAT help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/1384550#M777018</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an internal webserver which is available from the internet via a public IP using a static NAT.&amp;nbsp; This server sits in it's own VLAN off our ASA using a sub-interface (trunk into a switch). Our developers have asked if our internal users could also use this public IP to access the server?&amp;nbsp; It will save them lots of re-programming apparently, is this possibe?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if I wanted to get to this public IP (which is on the ASA anyway), it doesn't go out to the internet, but maybe just NAT's to this internal IP?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/1384550#M777018</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2019-03-11T16:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/1384551#M777036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;Hi,&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;ASA wont allow port redirection, so you may need to use the DNS doctoring feature..&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;If accessing the server via the internal IP address meets your needs, then you may want&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;to try DNS doctoring.&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml"&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 12:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/1384551#M777036</guid>
      <dc:creator>krishnadas.R_2</dc:creator>
      <dc:date>2009-12-14T12:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help</title>
      <link>https://community.cisco.com/t5/network-security/nat-help/m-p/1384552#M777051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would a NAT work, I looked at you link and it looks very similar to a NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I trid to do a Static NAT, but the packet trace should the trafic going out to the internet which I don't want happening:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;info example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interfaces:&lt;/P&gt;&lt;P&gt;inside (192.168.1.1)&lt;/P&gt;&lt;P&gt;outside (100.100.100.1)&lt;/P&gt;&lt;P&gt;VLAN1 (172.25.1.x)&lt;/P&gt;&lt;P&gt;VLAN2 (192.168.15.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently we have a NAT for 100.100.100.2 &amp;gt; 192.168.15.8 from the Outside to VLAN2 web server.&amp;nbsp; We want VLAN2 to ba able to contact 100.100.100.2 and not go out on the global IP.&amp;nbsp; I added '&lt;STRONG&gt;static (VLAN1,VLAN2) 192.168.15.8 100.100.100.2 netmask 255.255.255.255 dns tcp 0 0 udp 0&lt;/STRONG&gt;' but the traffic goes to the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought anything on VLAN1 trying to get to 100.100.100.2 would translate to 192.168.15.8?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 14:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help/m-p/1384552#M777051</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2009-12-14T14:44:39Z</dc:date>
    </item>
  </channel>
</rss>

