<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185931#M877752</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can try these configs&lt;/P&gt;&lt;P&gt;Assuming that the src traffic is 10.18.1.0 dst is 172.16.1.1:8080&lt;/P&gt;&lt;P&gt;access-list Policy10 x.x.x.x y.y.y.y where x.x.x.x is the src/subnet and y.y.y.y is the dest &lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.1.1 access-list Policy10 &lt;/P&gt;&lt;P&gt;access-list Policy20 x.x.x.x y.y.y.y where x.x.x.x= src of traffic and y.y.y.y dest of trafic &lt;/P&gt;&lt;P&gt;static (insode,outside) 192.168.1.2 access-list Policy20 &lt;/P&gt;&lt;P&gt;This means that xlate when the access-list triggers (src,dst) of traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Jan 2009 19:15:37 GMT</pubDate>
    <dc:creator>sdoremus33</dc:creator>
    <dc:date>2009-01-15T19:15:37Z</dc:date>
    <item>
      <title>Policy NAT</title>
      <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185930#M877751</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;i am trying to prepare for exam and i'm bit stuck with this scenario in my lab. Could someone help me with this? I'm trying to nat one outside global ip address and tcp port to two different inside server based on source ip address.&lt;/P&gt;&lt;P&gt;I have two user pools 10.18.1.0/24 and 10.18.2.0/24 and all users are set to use proxy server 172.16.1.1:8080. That proxy sever was nated on FWSM to 192.168.1.1, but now i want to split the load and want to nat one user subnet (10.18.1.0/24) to 192.168.1.1 and second user subnet to 192.168.1.2. &lt;/P&gt;&lt;P&gt;What i did is i've configured two access-list's &lt;/P&gt;&lt;P&gt;ACL1:&lt;/P&gt;&lt;P&gt;access-list permit tcp host 192.168.1.1 eq 8080 10.18.1.0 255.255.255.0 eq 8080&lt;/P&gt;&lt;P&gt;ACL2:&lt;/P&gt;&lt;P&gt;access-list permit tcp host 192.168.1.2 eq 8080 10.18.2.0 255.255.255.0 eq 8080&lt;/P&gt;&lt;P&gt;i can apply one static:&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 172.16.1.1 8080 access-list ACL1 &lt;/P&gt;&lt;P&gt;fwsm accepts this command but when i try to apply second static:&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 172.16.1.1 8080 access-list ALC2 &lt;/P&gt;&lt;P&gt;i'm getting error that global already used.&lt;/P&gt;&lt;P&gt;What am i doing wrong here?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185930#M877751</guid>
      <dc:creator>darius.liepuonis</dc:creator>
      <dc:date>2019-03-11T14:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Policy NAT</title>
      <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185931#M877752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can try these configs&lt;/P&gt;&lt;P&gt;Assuming that the src traffic is 10.18.1.0 dst is 172.16.1.1:8080&lt;/P&gt;&lt;P&gt;access-list Policy10 x.x.x.x y.y.y.y where x.x.x.x is the src/subnet and y.y.y.y is the dest &lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.1.1 access-list Policy10 &lt;/P&gt;&lt;P&gt;access-list Policy20 x.x.x.x y.y.y.y where x.x.x.x= src of traffic and y.y.y.y dest of trafic &lt;/P&gt;&lt;P&gt;static (insode,outside) 192.168.1.2 access-list Policy20 &lt;/P&gt;&lt;P&gt;This means that xlate when the access-list triggers (src,dst) of traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 19:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185931#M877752</guid>
      <dc:creator>sdoremus33</dc:creator>
      <dc:date>2009-01-15T19:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Policy NAT</title>
      <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185932#M877753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks i will try that&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jan 2009 16:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185932#M877753</guid>
      <dc:creator>darius.liepuonis</dc:creator>
      <dc:date>2009-01-19T16:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Policy NAT</title>
      <link>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185933#M877754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did this work for you, just checking...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2009 05:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/policy-nat/m-p/1185933#M877754</guid>
      <dc:creator>sdoremus33</dc:creator>
      <dc:date>2009-01-20T05:24:14Z</dc:date>
    </item>
  </channel>
</rss>

