<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Questions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274223#M812967</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The natting is a must as both the interfaces are of different security levels with inside and WAN as 100 and 70 respectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But why i am asking is because the nat command is not changing the ip address in my case as the translated ip is the same as the original ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,WAN) 10.0.0.1 10.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i have read the Doc as it talks about translated and original ip in general and there is no general details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Oct 2009 14:30:46 GMT</pubDate>
    <dc:creator>talha_490</dc:creator>
    <dc:date>2009-10-21T14:30:46Z</dc:date>
    <item>
      <title>NAC Questions</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274219#M812955</link>
      <description>&lt;P&gt;We have 2 CAS should be configured with HA are located in the WAN Zone of the FWSM. there is a static NAT means&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,WAN) 10.0.0.1 10.0.0.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where 10.0.0.1 is the ip of CAM and the cas has 20.0.0.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read that if the CAS and CAM sare across the firewall then CAM will not add CAS as HA unit. The above natting is above.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274219#M812955</guid>
      <dc:creator>talha_490</dc:creator>
      <dc:date>2020-02-21T11:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Questions</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274220#M812960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Talha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct. HA with NAT'd CASs isn't supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 13:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274220#M812960</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-10-21T13:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Questions</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274221#M812963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So should i conclude that in my scenario it is not possible for me to configure CAS in HA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 14:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274221#M812963</guid>
      <dc:creator>talha_490</dc:creator>
      <dc:date>2009-10-21T14:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Questions</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274222#M812965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there's NAT in the picture, then yes, this won't work. If you can somehow remove the NAT and route between the CAS and CAM, then it should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Edit] I just looked at the NAT closely and apologize for giving you the wrong information. The only scenario when NAT breaks things is when the IP addresses are different when you're NAT'ing (e.g. 10.x being nat'ed to 192.168.x when reaching the CAM etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this scenario where the NAT and the actual IP are the same it should work. You'll just have to ensure that the required traffic flow is open between the devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 14:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274222#M812965</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-10-21T14:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Questions</title>
      <link>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274223#M812967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The natting is a must as both the interfaces are of different security levels with inside and WAN as 100 and 70 respectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But why i am asking is because the nat command is not changing the ip address in my case as the translated ip is the same as the original ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,WAN) 10.0.0.1 10.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i have read the Doc as it talks about translated and original ip in general and there is no general details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 14:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-questions/m-p/1274223#M812967</guid>
      <dc:creator>talha_490</dc:creator>
      <dc:date>2009-10-21T14:30:46Z</dc:date>
    </item>
  </channel>
</rss>

