<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nat problem  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098478#M893370</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the correct remote site before i used examples of ip addresses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Nov 2008 12:56:25 GMT</pubDate>
    <dc:creator>michalis1234</dc:creator>
    <dc:date>2008-11-19T12:56:25Z</dc:date>
    <item>
      <title>Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098470#M893336</link>
      <description>&lt;P&gt;Hi, I have a problem i have a server (10.20.2.20) on the dmz1 interface of a remote site, but i can not access it from the inside interface. I have posted all the nat rules configured on the firewall asa 5510 7.2 ver. Thus remote ite is connected to our hq with site to site vpn. Hence 10.20.1.0 network must be on the nat 0 rule but how will the inside 10.20.1.0 access 10.20.2.0 network and at the same time our hq through the vpn?&lt;/P&gt;&lt;P&gt;Thank you...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list test&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 192.168.1.2 https 10.20.1.240 https netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 192.168.1.2 www 10.20.1.240 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.20.1.20 10.20.1.20 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.20.1.21 10.20.1.21 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.20.1.22 10.20.1.22 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.20.1.23 10.20.1.23 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group OUTSIDE in interface outside&lt;/P&gt;&lt;P&gt;access-group INSIDE in interface inside&lt;/P&gt;&lt;P&gt;access-group DMZ1 in interface dmz1&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:15:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098470#M893336</guid>
      <dc:creator>michalis1234</dc:creator>
      <dc:date>2019-03-11T14:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098471#M893342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the config you posted for the HQ or remote site, as you state "Hi, I have a problem i have a server (10.20.2.20) on the dmz1" but the config states "static (inside,dmz1) 10.20.1.20 10.20.1.20 netmask 255.255.255.255"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Differenet 3rd octets??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 10:44:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098471#M893342</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-11-19T10:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098472#M893347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The config is for the remote site,&lt;/P&gt;&lt;P&gt;I have tried as well the statement&lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.20.2.20 10.20.2.20 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;But it does not work!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 11:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098472#M893347</guid>
      <dc:creator>michalis1234</dc:creator>
      <dc:date>2008-11-19T11:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098473#M893350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firstly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You nat statements look the wrong way around, change to:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1,inside) 10.20.2.20 10.20.2.20 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) What is the IP subnet of the HQ site?&lt;/P&gt;&lt;P&gt;3) You have to make sure the remote DMZ IP subnet is in the VPN encryption domains&lt;/P&gt;&lt;P&gt;4) You have to make sure the remote DMZ IP subnet is in the no-nat VPN statements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;HTH&gt;&lt;/HTH&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 11:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098473#M893350</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-11-19T11:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098474#M893352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) i did it.&lt;/P&gt;&lt;P&gt;2) 192.x.x.x is the ip addressing of the hq site.&lt;/P&gt;&lt;P&gt;3)?&lt;/P&gt;&lt;P&gt;4) i did that as well&lt;/P&gt;&lt;P&gt;it did not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098474#M893352</guid>
      <dc:creator>michalis1234</dc:creator>
      <dc:date>2008-11-19T12:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098475#M893357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the full config for review - remove sensitive information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098475#M893357</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-11-19T12:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098476#M893361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;  'outside' vlan port&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.x.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; 'inside' vlan port&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.8.1.254 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;  vlan port&lt;/P&gt;&lt;P&gt; nameif dmz1&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 10.8.2.253 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 10.8.10.0 255.255.255.128 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 192.168.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 10.0.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.8.1.0 255.255.255.0 10.8.10.0 255.255.255.128 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip object-group Local-Network object-group xxxxxk &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.8.1.0 255.255.255.0 10.8.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 192.168.121.0 255.255.255.0 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object-group SMTP-HTTPS-HTTP host 192.168.1.2 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_20 extended permit ip object-group Local-Network object-group xxxxx &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_20 extended permit ip object-group Local-Network host x.x.x.1 &lt;/P&gt;&lt;P&gt;access-list dmz1_nat0_outbound extended permit ip any 10.0.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_dyn_vpn extended permit ip 10.8.1.0 255.255.255.0 10.8.10.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list DMZ1_INSIDE extended permit ip host 10.8.2.250 host 10.8.1.239 &lt;/P&gt;&lt;P&gt;access-list DMZ1_INSIDE extended permit ip host 10.8.2.250 host 10.8.1.240 &lt;/P&gt;&lt;P&gt;access-list DMZ1_INSIDE extended permit ip host 10.8.2.250 host 10.8.1.236 &lt;/P&gt;&lt;P&gt;access-list DMZ1_INSIDE extended permit ip host 10.8.2.250 host 10.8.1.237 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_IN extended permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_IN extended permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_IN extended permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_IN extended permit tcp any any eq 1801 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_IN extended permit ip host x.x.x.x any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip host 10.8.1.236 any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip host 10.8.1.237 any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip host 10.8.1.240 any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip host 10.8.1.4 any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip host 10.8.1.156 any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended deny tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip host 10.8.1.200 any &lt;/P&gt;&lt;P&gt;access-list INSIDE_ACCESS_IN extended permit ip host 10.8.1.239 host 10.8.2.250 log &lt;/P&gt;&lt;P&gt;access-list xxxxx extended permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging trap informational&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host outside x.x.x.x&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu dmz1 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm512-k8.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list xxxxx&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.8.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 192.168.1.2 https 10.8.1.240 https netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 192.168.1.2 www 10.8.1.240 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.8.1.239 10.8.1.239 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.8.1.240 10.8.1.240 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.8.1.236 10.8.1.236 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,dmz1) 10.8.1.237 10.8.1.237 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group OUTSIDE_IN in interface outside&lt;/P&gt;&lt;P&gt;access-group INSIDE_ACCESS_IN in interface inside&lt;/P&gt;&lt;P&gt;access-group DMZ1_INSIDE in interface dmz1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098476#M893361</guid>
      <dc:creator>michalis1234</dc:creator>
      <dc:date>2008-11-19T12:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098477#M893365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what config is this, the dmz IP range is 10.8.x.x not 10.20.x.x and there is not 192.168 ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which site is this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098477#M893365</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-11-19T12:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098478#M893370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the correct remote site before i used examples of ip addresses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/1098478#M893370</guid>
      <dc:creator>michalis1234</dc:creator>
      <dc:date>2008-11-19T12:56:25Z</dc:date>
    </item>
  </channel>
</rss>

