<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static nat identity and static map in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285407#M777604</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;i've got a doubt....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;i have to do nat identity for a /25 but 2 addresses of that /25 must be mapped:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ex&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (inside,outside) udp 1.1.1.1 53 2.2.2.1 53 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (inside,outside) udp 1.1.1.2 53 2.2.2.2 53 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (inside,outside) 1.1.1.0 1.1.1.0 netmask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;i think will work even if i've got a WARNING message like&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&lt;A class="active_link" href="https://community.cisco.com/message/893529#893529" target="_blank"&gt;&lt;SPAN style="font-size: 10pt; text-decoration: none; font-weight: normal; "&gt;mapped-address conflict&lt;/SPAN&gt;&lt;/A&gt;&lt;/H2&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i perform a show xlate i can see before first 2 entries and then third one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you think i'll have any issue? may you know better or more elegant way to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tnx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:43:45 GMT</pubDate>
    <dc:creator>danilodicesare</dc:creator>
    <dc:date>2019-03-11T16:43:45Z</dc:date>
    <item>
      <title>static nat identity and static map</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285407#M777604</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;i've got a doubt....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;i have to do nat identity for a /25 but 2 addresses of that /25 must be mapped:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ex&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (inside,outside) udp 1.1.1.1 53 2.2.2.1 53 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (inside,outside) udp 1.1.1.2 53 2.2.2.2 53 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (inside,outside) 1.1.1.0 1.1.1.0 netmask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;i think will work even if i've got a WARNING message like&lt;/SPAN&gt;&lt;/P&gt;&lt;H2&gt;&lt;A class="active_link" href="https://community.cisco.com/message/893529#893529" target="_blank"&gt;&lt;SPAN style="font-size: 10pt; text-decoration: none; font-weight: normal; "&gt;mapped-address conflict&lt;/SPAN&gt;&lt;/A&gt;&lt;/H2&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i perform a show xlate i can see before first 2 entries and then third one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you think i'll have any issue? may you know better or more elegant way to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tnx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285407#M777604</guid>
      <dc:creator>danilodicesare</dc:creator>
      <dc:date>2019-03-11T16:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: static nat identity and static map</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285408#M777633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should be ok, since the first two statics are more specific than the broad network static. If it doesn't work, you could try a policy static nat instead for the two ips.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list hosta permit ip host 2.2.2.1 any&lt;/P&gt;&lt;P&gt;access-list hostb permit ip host 2.2.2.2 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.1 access-list hosta&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.2 access-list hostb&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Nov 2009 20:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285408#M777633</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2009-11-29T20:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: static nat identity and static map</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285409#M777673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tnx Jan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;maybe i was wrong before 'cause i wanna mean:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;static (inside&lt;REAL&gt;,outside&lt;MAPPED&gt;) udp 2.2.2.1&lt;MAPPED&gt; 53 1.1.1.1&lt;REAL&gt; 53 netmask 255.255.255.255&lt;/REAL&gt;&lt;/MAPPED&gt;&lt;/MAPPED&gt;&lt;/REAL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;static (inside,outside) udp 2.2.2.2 53 1.1.1.2 53 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;static (inside,outside) 1.1.1.0 1.1.1.0 netmask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;of course your answer is the same ::)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list hosta permit ip host 1.1.1.1 any&lt;/P&gt;&lt;P&gt;access-list hostb permit ip host 1.1.1.2 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 2.2.2.1 access-list hosta&lt;/P&gt;&lt;P&gt;static (inside,outside) 2.2.2.2 access-list hostb&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but other question is....how can add those entries later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i've already got a command like &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.0 1.1.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and i have to add more specific...do i need to do 'no static (inside,outside) 1.1.1.0 1.1.1.0 netmask 255.255.255.0', add more specific entry and then add again less specific entry?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;maybe there is a tricky NAT entry that i can add without removing temporarly other one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tnx a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Nov 2009 20:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285409#M777673</guid>
      <dc:creator>danilodicesare</dc:creator>
      <dc:date>2009-11-29T20:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: static nat identity and static map</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285410#M777714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dani,&lt;/P&gt;&lt;P&gt;How about nat exemption with an acl and deny these two hosts from that acl and add statics for these two hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the nat order of operations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/cfgnat.html#wp1042696"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/cfgnat.html#wp1042696&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Nov 2009 23:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285410#M777714</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-11-29T23:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: static nat identity and static map</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285411#M777736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;must be the right way....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so if i need inside to outside untranslated and outside to inside untranslated + some static mapping il'll do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX1# show running-config nat&lt;BR /&gt;nat (inside) 0 access-list nat_exemption&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; i wanna inside host to communicate untranslated to external host&lt;BR /&gt;nat (outside) 0 access-list nat_exemption&amp;nbsp;&amp;nbsp; --&amp;gt; i wanna outside world to communicate untranslated to internal host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX1# show running-config static&lt;BR /&gt;static (inside,outside) 7.7.7.7 2.2.2.1 netmask 255.255.255.255 --&amp;gt; i wanna map real ip 2.2.2.1 with 7.7.7.7&lt;BR /&gt;static (inside,outside) 7.7.7.8 2.2.2.4 netmask 255.255.255.255 --&amp;gt; i wanna map real ip 2.2.2.4 with 7.7.7.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX1# show running-config access-list&lt;BR /&gt;access-list all extended permit ip any any&lt;BR /&gt;access-list nat_exemption extended deny ip host 2.2.2.4 any&lt;BR /&gt;access-list nat_exemption extended deny ip host 2.2.2.1 any&lt;BR /&gt;access-list nat_exemption extended permit ip 2.2.2.0 255.255.255.128 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think is the right solution right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tnx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Nov 2009 07:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285411#M777736</guid>
      <dc:creator>danilodicesare</dc:creator>
      <dc:date>2009-11-30T07:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: static nat identity and static map</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285412#M777750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dani,&lt;/P&gt;&lt;P&gt;We don't translate the source from low to high so, there is no need for nat (outside) 0 access-list nat_exemption. Also, nat 0 with an acl applied on the inside will allow traffic to be initiated from the outside. It is bi-directional.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, this is the best way.&amp;nbsp; The acl looks correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Nov 2009 14:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-identity-and-static-map/m-p/1285412#M777750</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-11-30T14:26:08Z</dc:date>
    </item>
  </channel>
</rss>

