<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT help on ASA/Pix - need to change source IP due to overla in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185257#M835208</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Damn, I must be missing something.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for finding the time to help me, once fixed I will definately rate this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added what you mentioned and still no luck, I have attached the 2 updated configs for the firewall and remote router plus a simple diagram. I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the "sh nat" output on the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mypix# sh nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface Inside:&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Outside 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Outside 172.16.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Inside 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Inside 172.16.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 DMZ3 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 DMZ3 172.16.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 3, untranslate_hits = 4&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Outside 10.100.0.32 255.255.255.224&lt;/P&gt;&lt;P&gt;    static translation to 192.168.90.0&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any Outside any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (10.0.0.1 [Interface PAT])&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any Inside any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any DMZ3 any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;    translate_hits = 211, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any Outside any&lt;/P&gt;&lt;P&gt;    no translation group, implicit deny&lt;/P&gt;&lt;P&gt;    policy_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any DMZ3 any&lt;/P&gt;&lt;P&gt;    no translation group, implicit deny&lt;/P&gt;&lt;P&gt;    policy_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface DMZ3:&lt;/P&gt;&lt;P&gt;  match ip DMZ3 192.168.2.0 255.255.255.0 Outside 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 10.100.0.32 255.255.255.224 Outside 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 192.168.2.0 255.255.255.0 DMZ3 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 10.100.0.32 255.255.255.224 DMZ3 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 any Outside any&lt;/P&gt;&lt;P&gt;    no translation group, implicit deny&lt;/P&gt;&lt;P&gt;    policy_hits = 0&lt;/P&gt;&lt;P&gt;mypix#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Jun 2009 19:24:14 GMT</pubDate>
    <dc:creator>jamesgonzo</dc:creator>
    <dc:date>2009-06-01T19:24:14Z</dc:date>
    <item>
      <title>NAT help on ASA/Pix - need to change source IP due to overlapping networks</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185255#M835204</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've not had any luck with this.  I have an ASA with a sub-interface to a switch and from the switch I have a VLAN where a router sits to our remote office.  It is not a VPN just a lease line via serial.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My LAN is on 192.168.3.0/24 and the remote network is 10.100.0.32/27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When 192.168.3.0 connects to 10.100.0.32/27 I want the 192.168.3.0/24 range to change to 192.168.90.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached my basic ASA config, to try and get this NAT to work I added:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Inside_nat0_outbound extended permit ip 192.168.90.0 255.255.255.0 10.100.0.32 255.255.255.224 &lt;/P&gt;&lt;P&gt;access-list policy-nat extended permit ip 192.168.3.0 255.255.255.0 10.100.0.32 255.255.255.224&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.90.0 access-list policy-nat &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shoudl this of worked?  I can ping 10.100.0.61 but it is still seeing me come from 192.168.3.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185255#M835204</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2019-03-11T15:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185256#M835206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Aj,&lt;/P&gt;&lt;P&gt;    Yes that should have worked, but one entry in your exempt NAT statement prevents this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Inside_nat0_outbound extended permit ip 192.168.3.0 255.255.255.0 10.100.0.32 255.255.255.224 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Above line, by the native NAT processin order of ASA, is processed first, thats why trafic never reaches your policy NAT. Remove it by&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list Inside_nat0_outbound extended permit ip 192.168.3.0 255.255.255.0 10.100.0.32 255.255.255.224 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;following is not necessary either&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Inside_nat0_outbound extended permit ip 192.168.90.0 255.255.255.0 10.100.0.32 255.255.255.224 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add only the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list policy-nat extended permit ip 192.168.3.0 255.255.255.0 10.100.0.32 255.255.255.224 &lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.90.0 access-list policy-nat &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure remote site has a route for 192.168.90.0 pointing your end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, do not test this with ping, use tcp instead, for example try to establish Remote desktop, then in remote server, run netstat -an and you will see established connection's source IP and port&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jun 2009 00:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185256#M835206</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-01T00:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185257#M835208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Damn, I must be missing something.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for finding the time to help me, once fixed I will definately rate this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added what you mentioned and still no luck, I have attached the 2 updated configs for the firewall and remote router plus a simple diagram. I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the "sh nat" output on the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mypix# sh nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface Inside:&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Outside 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Outside 172.16.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Inside 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Inside 172.16.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 DMZ3 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 DMZ3 172.16.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 3, untranslate_hits = 4&lt;/P&gt;&lt;P&gt;  match ip Inside 192.168.3.0 255.255.255.0 Outside 10.100.0.32 255.255.255.224&lt;/P&gt;&lt;P&gt;    static translation to 192.168.90.0&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any Outside any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (10.0.0.1 [Interface PAT])&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any Inside any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any DMZ3 any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;    translate_hits = 211, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any Outside any&lt;/P&gt;&lt;P&gt;    no translation group, implicit deny&lt;/P&gt;&lt;P&gt;    policy_hits = 0&lt;/P&gt;&lt;P&gt;  match ip Inside any DMZ3 any&lt;/P&gt;&lt;P&gt;    no translation group, implicit deny&lt;/P&gt;&lt;P&gt;    policy_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface DMZ3:&lt;/P&gt;&lt;P&gt;  match ip DMZ3 192.168.2.0 255.255.255.0 Outside 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 10.100.0.32 255.255.255.224 Outside 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 192.168.2.0 255.255.255.0 DMZ3 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 10.100.0.32 255.255.255.224 DMZ3 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;    NAT exempt&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip DMZ3 any Outside any&lt;/P&gt;&lt;P&gt;    no translation group, implicit deny&lt;/P&gt;&lt;P&gt;    policy_hits = 0&lt;/P&gt;&lt;P&gt;mypix#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jun 2009 19:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185257#M835208</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2009-06-01T19:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185258#M835210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aj,&lt;/P&gt;&lt;P&gt;  According to the diagram you posted, DMZ3 interface is the one which connects to remote subnet, not outside interface. So static should be modified as following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no static (Inside,Outside) 192.168.90.0  access-list policy-nat&lt;/P&gt;&lt;P&gt;static (Inside,DMZ3) 192.168.90.0  access-list policy-nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I remember, ASA may not be advertising 192.168.90.0 network to upstream router since it doesnt have an interface on that subnet. Can you confirm that by checking route table in your 2620?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 10:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185258#M835210</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-03T10:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185259#M835211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA will proxy arp for all the globals that it owns unless proxy arp is turned off with the sysopt command. In this case it will proxy arp for 192.168.90.0 subnet even when we do not have an interface configured on that subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 11:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185259#M835211</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-06-03T11:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185260#M835212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Proxying arp entries ,responding to arp queriers, and advertising routes are two different things. Proxy ARP wont help ASA to advertise the routes that it doesnt have, which is the translated subnet in our case. &lt;/P&gt;&lt;P&gt;Aj,&lt;/P&gt;&lt;P&gt;  Most probably, upstream router doesnt have a route for 192.168.90.0 subnet. If i am right, then assign 192.168.90.254 ip address to an empty interface of ASA (eth3 or another subinterface that doesnt have any connection to anywhere, just enable the interface). Then check if a route entry for 192.168.90.0 appears in upstream routetable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 12:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185260#M835212</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-03T12:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185261#M835213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks finding the time again to help me here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couldn't I just add the 192.168.90.0 subnet to RIP on the ASA like I have the other networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 13:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185261#M835213</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2009-06-03T13:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185262#M835214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a matter of fact, you do have the answer for that question already. What is different between the routes that are advertised correctly and the routes that dont appear at upstream router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)Are subnets entered under router rip correctly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; network 10.0.0.0&lt;/P&gt;&lt;P&gt; network 192.168.2.0&lt;/P&gt;&lt;P&gt; network 192.168.3.0&lt;/P&gt;&lt;P&gt; network 192.168.90.0&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes they are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)Which routes appear correctly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"RIP on the ASA like I have the "!other networks!""&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which are these other networks "just added"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; network 10.0.0.0&lt;/P&gt;&lt;P&gt; network 192.168.2.0&lt;/P&gt;&lt;P&gt; network 192.168.3.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which route doesnt appear?&lt;/P&gt;&lt;P&gt;network 192.168.90.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  What is the difference in the config between those?&lt;/P&gt;&lt;P&gt;Answer: ASA has an interface in correctly advertised networks and doesnt have an interface in subnet that is not advertised&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that was a router, you could create a static route for that network pointing  to null0 interface (self) and redistribute that static route into RIP, but as i remember, ASA doesnt support this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just create another subinterface such as 2.8, just give an ip and enable it. You dont need any nat configs cable connection etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 15:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185262#M835214</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-03T15:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185263#M835215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;husycisco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will attempt creting a new sub-interface for the 192.168.90.c network, is this all I have to do as you say "You dont need any nat configs cable connection etc."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand I just need to add it to rip?  and add your NAT statement?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 17:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185263#M835215</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2009-06-03T17:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185264#M835216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"I will attempt creting a new sub-interface for the 192.168.90.0 network, is this all I have to do "&lt;/P&gt;&lt;P&gt;Exactly, just set IP and enable it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I understand I just need to add it to rip? and add your NAT statement? "&lt;/P&gt;&lt;P&gt;Exactly, remove current entry by no network 192.168.90.0 then set and enable sub-interface, then add it into rip. And add nat statement&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 18:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185264#M835216</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-03T18:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185265#M835217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I have to do a bit more, the subnet is now advertised to te remote router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ping (from 192.168.3.20) 10.100.0.61 and on the router I have debug ip icmp I sees the traffic source as 192.168.3.x not 192.168.90.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I have to add ACL's to the ASA for 192.168.90.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I have to add the 192.168.90.x subnet to the switch so the for the trunk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reason I ask is the remote network on 10.100.0.32/27 can ping 192.168.90.x, or does it have to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2009 19:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185265#M835217</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2009-06-03T19:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185266#M835218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;couple of concerns here,&lt;/P&gt;&lt;P&gt;  1) If Your new subinterface is visible via trunk and upstream router points 192.168.90.x (subinterface IP) as next hop for RIP route, this is bad. Please confirm that the next hop for RIP route 192.168.90.0 is not 192.168.90.x. Lets hope the responder to 90.* destined pings is DMZ3 interface by proxy-arp feature&lt;/P&gt;&lt;P&gt;  2)I assume that translation is not taking place. Remove the static entry, remove the conditional nat ACL, then run "clear xlate" then run "clear local-host all" . Second, add the ACL and the static statement back, then run "clear xlate". Make sure your conditional NAT acl does not contain "any" statement. Submit soure and destination networks specifically.&lt;/P&gt;&lt;P&gt;   3)To make sure our translation works, here is the command that you should run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture PNAT interface DMZ3 real match ip 192.168.90.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;   A live capture screen will open up (ctrl+c to exit). Then try to ping from an inside host (192.168.3.0) a destination client in 10.100.0.32/27 . If some text appears, that means translation is working.  &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;Finally, try testing with tcp rather than PINGs, for example try telnetting or remote desktop to a server and check netstat -an to see source&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jun 2009 10:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185266#M835218</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-06T10:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on ASA/Pix - need to change source IP due to overla</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185267#M835219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any update on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jun 2009 09:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-asa-pix-need-to-change-source-ip-due-to-overlapping/m-p/1185267#M835219</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2009-06-10T09:16:13Z</dc:date>
    </item>
  </channel>
</rss>

