<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static NAT question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-question/m-p/1219766#M861412</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kunal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See this recent thread discussing the same issue - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd28488" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd28488&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Mar 2009 18:59:20 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-03-30T18:59:20Z</dc:date>
    <item>
      <title>Static NAT question</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-question/m-p/1219765#M861411</link>
      <description>&lt;P&gt;Hi folks - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a host in the DMZ that has a one-2-one static NAT on an ASA 5510. The IP address of the host in the DMZ is 192.168.128.20. Now we have added two more hosts in the DMZ that have been clustered with 192.168.128.20. The IP addresses of two additional hosts in the cluster is 192.168.128.26 &amp;amp; .28. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when communication goes out from the server cluster in the DMZ, I've been told the cluster will choose any IP address (.20, .26 or .28) for outbound communication. I added another NAT statement on the 5510 that NAT's .26 &amp;amp; .28 to a public IP address. This public IP address is different from the public IP address that has been assigned to .20. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is, Can I have the below configuration without causing any problems? My goal is to keep the static NAT that is in place for .20, and also NAT .26 and .28 to the same public IP address as .20. Also, when vendors communicate with the server cluster in the DMZ, they use the IP address of 99.99.99.100 (not the real address ofcourse!!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 99.99.99.100 192.168.128.20 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l TEST extended per ip host 192.168.128.20 any&lt;/P&gt;&lt;P&gt;access-l TEST extended per ip host 192.168.128.26 any&lt;/P&gt;&lt;P&gt;access-l TEST extended per ip host 192.168.128.28 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 99.99.99.100 access-l TEST &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-question/m-p/1219765#M861411</guid>
      <dc:creator>ksarin123_2</dc:creator>
      <dc:date>2019-03-11T15:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT question</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-question/m-p/1219766#M861412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kunal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See this recent thread discussing the same issue - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd28488" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd28488&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2009 18:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-question/m-p/1219766#M861412</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-30T18:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT question</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-question/m-p/1219767#M861414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your prompt response. However, my situation is slightly different. I am looking to keep the static NAT in place (for .20) but also NAT .26 and .28 to the same public IP addresses as .20. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am looking to map a single public IP address to multiple hosts inside.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2009 19:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-question/m-p/1219767#M861414</guid>
      <dc:creator>ksarin123_2</dc:creator>
      <dc:date>2009-03-30T19:27:34Z</dc:date>
    </item>
  </channel>
</rss>

