<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT exempt question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-exempt-question/m-p/1101650#M892664</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have two sites interconnected by MPLS. Each site has an ASA and is connected to the internet. I'm trying to setup failover for internet connectivity and when on one site the ISP connection is down to route the internet traffic into MPLS and then to the ISP on the other site. The sla monitoring is working but the NAT is converting the traffic since it is not covered by NAT exempt rule and I do not see a way to exempt depending on the outgoing interface. Any suggestions?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 14:22:07 GMT</pubDate>
    <dc:creator>hantonov42</dc:creator>
    <dc:date>2019-03-11T14:22:07Z</dc:date>
    <item>
      <title>NAT exempt question</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-question/m-p/1101650#M892664</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have two sites interconnected by MPLS. Each site has an ASA and is connected to the internet. I'm trying to setup failover for internet connectivity and when on one site the ISP connection is down to route the internet traffic into MPLS and then to the ISP on the other site. The sla monitoring is working but the NAT is converting the traffic since it is not covered by NAT exempt rule and I do not see a way to exempt depending on the outgoing interface. Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-question/m-p/1101650#M892664</guid>
      <dc:creator>hantonov42</dc:creator>
      <dc:date>2019-03-11T14:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAT exempt question</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-question/m-p/1101651#M892666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I build such a scenario for a colleague. Instead of using MPLS I use a WAN-link (doesn't matter).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only backup ASA 2, but it should run in both ways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routing protocol RIPv2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet &lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;ASA 1&lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;inside - 192.168.16.0/21&lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;WAN&lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;inside - 192.168.32.0/21&lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;ASA 2&lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT configuration on ASA 1&lt;/P&gt;&lt;P&gt;--------------------------&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 81.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configuration ASA 2&lt;/P&gt;&lt;P&gt;-------------------&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 82.x.x.x 1 track 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor 1&lt;/P&gt;&lt;P&gt; type echo protocol ipIcmpEcho 81.x.x.x interface outside&lt;/P&gt;&lt;P&gt; num-packets 3&lt;/P&gt;&lt;P&gt; frequency 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sla monitor schedule 1 life forever start-time now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; network 192.168.32.0&lt;/P&gt;&lt;P&gt; redistribute static metric 1&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the Internet on ASA 2 goes down, the default-route to ASA 1 will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Dec 2008 14:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-question/m-p/1101651#M892666</guid>
      <dc:creator>ccarreto</dc:creator>
      <dc:date>2008-12-08T14:53:29Z</dc:date>
    </item>
  </channel>
</rss>

