<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about NAT Exemption in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035885#M893039</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please clarify your scenario so that I can &lt;/P&gt;&lt;P&gt;understand your requirements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In general, NAT on Pix/ASA is not as flexible&lt;/P&gt;&lt;P&gt;as say Juniper or Checkpoint firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Nov 2008 18:04:56 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2008-11-25T18:04:56Z</dc:date>
    <item>
      <title>Question about NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035884#M893038</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have following szenario:&lt;/P&gt;&lt;P&gt;I want to reach a outside host under its original address and its NAT address at it seems to the inside world.&lt;/P&gt;&lt;P&gt;(Host in the DMZ ist translated to the Inside Interface with a Static NAT rule).&lt;/P&gt;&lt;P&gt;It is possible to reach this host from Inside under the NAT and Original IP address?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dirk&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035884#M893038</guid>
      <dc:creator>d.rein</dc:creator>
      <dc:date>2019-03-11T14:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Question about NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035885#M893039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please clarify your scenario so that I can &lt;/P&gt;&lt;P&gt;understand your requirements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In general, NAT on Pix/ASA is not as flexible&lt;/P&gt;&lt;P&gt;as say Juniper or Checkpoint firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2008 18:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035885#M893039</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-11-25T18:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Question about NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035886#M893040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;----Inside--ASA---DMZ---Host&lt;/P&gt;&lt;P&gt;The host is translated to the inside Network an can be reached by the translated address.&lt;/P&gt;&lt;P&gt;I would like that hosts in the Inside Network should reach the Host in the DMZ under their original and also translated address.&lt;/P&gt;&lt;P&gt;At the moment it is working only with the translated address. I have already configured an exemption rule but it is not working. In the syslog file I see that I have no matching translation rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2008 18:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035886#M893040</guid>
      <dc:creator>d.rein</dc:creator>
      <dc:date>2008-11-25T18:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Question about NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035887#M893041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't be done an ASA appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Get a checkpoint firewall and it can do the &lt;/P&gt;&lt;P&gt;trick for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2008 18:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035887#M893041</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-11-25T18:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Question about NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035888#M893042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And do you know why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's one book that shows the NAT order of operation as being first check NAT exemption, then static NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2008 22:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035888#M893042</guid>
      <dc:creator>vladrac-ccna</dc:creator>
      <dc:date>2008-11-25T22:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Question about NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035889#M893043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did some research and yes its possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to define 2 static policy nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;real ip on DMZ 20.20.20.20&lt;/P&gt;&lt;P&gt;nat ip on inside 192.168.100.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you configure the correct order:&lt;/P&gt;&lt;P&gt;static (DMZ,inside) 192.168.100.20  access-list acl_policy1&lt;/P&gt;&lt;P&gt;static (DMZ,inside) 20.20.20.20  access-list acl_policy2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_policy1 extended permit ip host 20.20.20.20 any&lt;/P&gt;&lt;P&gt;access-list acl_policy2 extended permit ip host 20.20.20.20 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telnet from a client on the inside network to the DMZ server using both IPs natted and real.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client#192.168.100.20 80&lt;/P&gt;&lt;P&gt;Trying 192.168.100.20, 80 ... Open&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;get&lt;/P&gt;&lt;P&gt;HTTP/1.1 400 Bad Request&lt;/P&gt;&lt;P&gt;Date: Mon, 01 Mar 1993 03:41:13 GMT&lt;/P&gt;&lt;P&gt;Server: cisco-IOS&lt;/P&gt;&lt;P&gt;Accept-Ranges: none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;400 Bad Request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Connection to 192.168.100.20 closed by foreign host]&lt;/P&gt;&lt;P&gt;client#20.20.20.20 80&lt;/P&gt;&lt;P&gt;Trying 20.20.20.20, 80 ... Open&lt;/P&gt;&lt;P&gt;get&lt;/P&gt;&lt;P&gt;\HTTP/1.1 400 Bad Request&lt;/P&gt;&lt;P&gt;Date: Mon, 01 Mar 1993 03:41:21 GMT&lt;/P&gt;&lt;P&gt;Server: cisco-IOS&lt;/P&gt;&lt;P&gt;Accept-Ranges: none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;400 Bad Request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Connection to 20.20.20.20 closed by foreign host]&lt;/P&gt;&lt;P&gt;client#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2008 22:58:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-exemption/m-p/1035889#M893043</guid>
      <dc:creator>vladrac-ccna</dc:creator>
      <dc:date>2008-11-25T22:58:43Z</dc:date>
    </item>
  </channel>
</rss>

