<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 - static from several Public IP's to single inside  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191884#M875174</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you on the complexity of configuring cisco NAT &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say it's doable but i must admit i thought you couldn't do this if the source IP's were always the same ie. any because they are coming from the Internet and the ports were the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have a pix to test with either unfortunately but do you remember the gist of how it is done on a pix. I'd be very interested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Mar 2009 01:03:42 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-03-12T01:03:42Z</dc:date>
    <item>
      <title>ASA 5520 - static from several Public IP's to single inside IP</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191879#M875161</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am about to migrate a customer from a hosted checkpoint firewall to an active/passive ASA 5520 firewall.&lt;/P&gt;&lt;P&gt;I have got some prints from the configuration of the checkpoint firewall, which show that 4 public IP's are forwardet to the same IP on the inside (don't ask me why!!).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as i concern this is not possible on the ASA. I could solve the issue by using PAT, and only forwarding specific services, however my issue is, that I need UDP/53 (DNS) forwardet on 3 of the public IP's to the same server on the inside (again, I know this sounds crazy, but this is how it is set up on the current checkpoint firewall)..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is greatly appreciated !!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191879#M875161</guid>
      <dc:creator>rasmusan1</dc:creator>
      <dc:date>2019-03-11T15:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191880#M875164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be possible with a static NAT with an ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) &lt;OUTSIDE_ADDRESS&gt; access-list &lt;ACL_NAME&gt;&lt;/ACL_NAME&gt;&lt;/OUTSIDE_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;use the source in the ACL as the IP to NAT to and the destination as the IP's that are allowed to be NAT'd.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2009 15:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191880#M875164</guid>
      <dc:creator>adamclarkuk_2</dc:creator>
      <dc:date>2009-03-11T15:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191881#M875168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure I understand. I wan't multiple outside IP's mapped to a single inside IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you please show me an example ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2009 19:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191881#M875168</guid>
      <dc:creator>rasmusan1</dc:creator>
      <dc:date>2009-03-11T19:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191882#M875169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rasmus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"As far as i concern this is not possible on the ASA" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct. Unless you are mapping to different ports as you mention it is not possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2009 19:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191882#M875169</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-11T19:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191883#M875172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is definitely possible.  I do not have a Pix on hand to test but it is doable.  Just open a TAC case with Cisco and have TAC do it for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you have complex NAT like this (even though I don't think it is a big deal with Checkpoint), I personally think it is a big mistake to go from Checkpoint to ASA in this situation.  Furthermore, you also need to take into consideration that with Checkpoint firewalls, secondary IP addresses behaves just like Cisco IOS routers whereas this feature is not available in Cisco ASA platforms (you have to use 802.1q for this).  Remember you have to support this down the road as well which may not be very pleasant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I always laugh when I read posts like yours about converting from Checkpoint to ASA.  With the NAT scenario you described above, a junior person with a couple months of experiences on Checkpoint can do it in less than a minutes without the risk of taking down the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Until Cisco can come up with a User Interface (UI) that can make configuring complex NAT much easier and more user-friendly, I would stay away from Cisco ASA/Pix/FWSM with complex NAT scenarios.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my 2c.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2009 22:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191883#M875172</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-03-11T22:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191884#M875174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you on the complexity of configuring cisco NAT &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say it's doable but i must admit i thought you couldn't do this if the source IP's were always the same ie. any because they are coming from the Internet and the ports were the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have a pix to test with either unfortunately but do you remember the gist of how it is done on a pix. I'd be very interested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Mar 2009 01:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191884#M875174</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-12T01:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191885#M875175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for ytour feedback, however I would still very much like a configuration example - this would be very helpful&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Mar 2009 06:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191885#M875175</guid>
      <dc:creator>rasmusan1</dc:creator>
      <dc:date>2009-03-12T06:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191886#M875176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well, I created a TAC and got the solution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what TAC wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To do the design you want, you have to create 4 identical access-lists but with different names, i.e.:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list ACL_1 permit ip host 10.x.x.2 any&lt;/P&gt;&lt;P&gt;Access-list ACL_2 permit ip host 10.x.x.2 any&lt;/P&gt;&lt;P&gt;Access-list ACL_3 permit ip host 10.x.x.2 any&lt;/P&gt;&lt;P&gt;Access-list ACL_4 permit ip host 10.x.x.2 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you create a static statement for every access-list:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static(dmz,outside) x.x.x.1 access-list ACL_1&lt;/P&gt;&lt;P&gt;Static(dmz,outside) x.x.x.2 access-list ACL_2&lt;/P&gt;&lt;P&gt;Static(dmz,outside) x.x.x.3 access-list ACL_3&lt;/P&gt;&lt;P&gt;Static(dmz,outside) x.x.x.4 access-list ACL_4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, you can refer to the following link &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807d2874.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807d2874.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this is helpful to others...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Mar 2009 10:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191886#M875176</guid>
      <dc:creator>rasmusan1</dc:creator>
      <dc:date>2009-03-12T10:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191887#M875177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rasmus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for letting us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Mar 2009 11:55:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191887#M875177</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-12T11:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191888#M875178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How can this work with Dual ISP's off of 2 Outside interfaces? I have Outside0 and Outside1 and I need to static NAT into a server on the Inside so I can have access from either ISP. I understand the ASA will not handle the routing correctly because it does not have the capability of doing a route-map like a router can do and will always send the traffic out the default route.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Mar 2009 22:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191888#M875178</guid>
      <dc:creator>Gerard Roy</dc:creator>
      <dc:date>2009-03-13T22:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191889#M875179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing same problem. I am trying to replace cyberom firewall with ASA 5520.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In cyberom firewall traffic coming from outside on public ip address on two different public ip address get translated to one private ip address on the same port. But when i am trying to configure the same in ASA i am unable to do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand from solution provided by you that ACL_1, ACL_2, ACL_3, ACL_4 has source ip of 10.x.x.2 and destination any. Nating done from dmz to outside for different public ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in my case traffic will come from internet with source any and destination will be two different public ip address.For these two public ip add i need to nat with single private ip. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could u pl let me know how do i configure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nishith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Apr 2009 13:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191889#M875179</guid>
      <dc:creator>9898nishit</dc:creator>
      <dc:date>2009-04-04T13:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - static from several Public IP's to single inside</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191890#M875180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Nishith&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACL's just specify the private IP on the inside - it does not specify who can access them - that you have to control on your interface ACL's as normal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you just create 2 ACL's, like in my solution post, with your private IP in both ACL's, and then create 2 static's - one for each public IP - using an ACL for each static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this answer your question...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Apr 2009 14:21:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-static-from-several-public-ip-s-to-single-inside-ip/m-p/1191890#M875180</guid>
      <dc:creator>rasmusan1</dc:creator>
      <dc:date>2009-04-04T14:21:47Z</dc:date>
    </item>
  </channel>
</rss>

