<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internal NAT'ing - Security Recommendation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213971#M875595</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hiding the IPs from the two internal segments would depend on your company's security policy. It depends on a number of factors tough. E.g. you have two contractors managing the two different segements, hiding the internal IPs could increase security through the 'security through obscuring' model &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but this is not always the case. However this will increase complications while troubleshooting problems etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Mar 2009 07:34:43 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2009-03-02T07:34:43Z</dc:date>
    <item>
      <title>Internal NAT'ing - Security Recommendation</title>
      <link>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213969#M875591</link>
      <description>&lt;P&gt;Is it recommended to use NAT between servers on different layers divided by the internal firewall. For e.g. a segment of firewall is connected to web servers and another segment to DB servers. Is there any advantage of NAT'ing the destination server IPs (to hide the actual ips from the web server segment while connecting to DB).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please let me know if there any DISadvantages of doing so such as performance, uneasy troubleshooting etc. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213969#M875591</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2019-03-11T14:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Internal NAT'ing - Security Recommendation</title>
      <link>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213970#M875593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This absolutely depend on you. The advantage is protect the servers from normal users sitting on Inside zone. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Mar 2009 21:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213970#M875593</guid>
      <dc:creator>arvind.thevendriya</dc:creator>
      <dc:date>2009-03-01T21:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Internal NAT'ing - Security Recommendation</title>
      <link>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213971#M875595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hiding the IPs from the two internal segments would depend on your company's security policy. It depends on a number of factors tough. E.g. you have two contractors managing the two different segements, hiding the internal IPs could increase security through the 'security through obscuring' model &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but this is not always the case. However this will increase complications while troubleshooting problems etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2009 07:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213971#M875595</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-03-02T07:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Internal NAT'ing - Security Recommendation</title>
      <link>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213972#M875597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You shouldn't rely on NAT for any sort of security. I don't really see much advantage in Natting at all on internal firewalls and therefore all NAT does is add a an extra layer of complication where it isn't needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT is a pain frankly, but we end up having to do it almost everywhere. So if you can avoid it do. I would also add that NAT can break certain apps and without doubt if you are experiencing connectivity problems not having to take into account the NAT rules is one less thing to worry about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2009 10:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-nat-ing-security-recommendation/m-p/1213972#M875597</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-02T10:31:58Z</dc:date>
    </item>
  </channel>
</rss>

