<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix 506E 6.3(3)need to pass networks without nat translation. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134278#M914129</link>
    <description>&lt;P&gt;We use 10.x.x.x network internally. Pix stands between two networks - 10.34.12.0/24 - outside one with security level 0 and 10.34.3.0/24 - inside one with security level 100. I need all ip's from 10.34.3.0 and 10.34.12.0 networks to pass trough firewall without any nat translation. Also network 10.34.12.0 should get access to another 10.x.x.x subnets within corporate network without any nat translations. What is the best way to achieve this?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:34:29 GMT</pubDate>
    <dc:creator>radutily1</dc:creator>
    <dc:date>2019-03-11T13:34:29Z</dc:date>
    <item>
      <title>Pix 506E 6.3(3)need to pass networks without nat translation.</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134278#M914129</link>
      <description>&lt;P&gt;We use 10.x.x.x network internally. Pix stands between two networks - 10.34.12.0/24 - outside one with security level 0 and 10.34.3.0/24 - inside one with security level 100. I need all ip's from 10.34.3.0 and 10.34.12.0 networks to pass trough firewall without any nat translation. Also network 10.34.12.0 should get access to another 10.x.x.x subnets within corporate network without any nat translations. What is the best way to achieve this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134278#M914129</guid>
      <dc:creator>radutily1</dc:creator>
      <dc:date>2019-03-11T13:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134279#M914131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 10.34.12.0 255.255.255.0  10.34.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 10.34.12.0 255.255.255.0  10.0.0.0 255.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_out permit ip  10.34.3.0  255.255.255.0 10.34.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_access_in&lt;/P&gt;&lt;P&gt;nat (inside) 0   access-list inside_access_out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 07:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134279#M914131</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-08-22T07:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134280#M914132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use a policy based no-nat translation config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;something like:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list no-nat-internal permit ip 10.34.3.0 255.255.255.0 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;access-list no-nat-internal permit ip 10.34.12.0 255.255.255.0 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list no-nat-internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 07:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134280#M914132</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-08-22T07:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134281#M914133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I apply nat (outside) 0 access-list outside_access_in &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I receive the following error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING:  Specified interface is lowest security interface. This statement&lt;/P&gt;&lt;P&gt;WARNING:  is not applicable to any traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I still not able to get access to hosts on 10.34.12.x net. I think as outside is a lower security level interface only static command can help. What do you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 07:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134281#M914133</guid>
      <dc:creator>radutily1</dc:creator>
      <dc:date>2008-08-22T07:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134282#M914134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you post your current config, I think there is some confusing on which side the network's are and the direction of the NAT required?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 07:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134282#M914134</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-08-22T07:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134283#M914136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_access_in   outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;instead of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_access_in &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 07:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134283#M914136</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-08-22T07:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134284#M914137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've implemented such commands on this firewall:&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 10.34.12.0 255.255.255.0 10.34.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit ip 10.34.12.0 255.255.255.0 10.0.0.0 255.0.0.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_out permit ip 10.34.3.0 255.255.255.0 10.34.12.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_out permit ip 10.0.0.0 255.0.0.0 10.34.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_access_in outside&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_access_out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I'm still not able to get access to any hosts from inside to outside. Please find configuration details in attachment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 09:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134284#M914137</guid>
      <dc:creator>radutily1</dc:creator>
      <dc:date>2008-08-22T09:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134285#M914139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your access-list and interface IP address make no sense, and are incorrect.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) What IP subnets are on the inside?&lt;/P&gt;&lt;P&gt;2) What IP subnets are on the outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also have a default route pointing to the inside- why?  Are you sure you have inside &amp;amp; outside the correct way around?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 09:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134285#M914139</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-08-22T09:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134286#M914146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside subnet is 10.34.3.0/24&lt;/P&gt;&lt;P&gt;Outside subnet is 10.34.12.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default route on inside - it's simple a default route to another subnets in our network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 09:54:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134286#M914146</guid>
      <dc:creator>radutily1</dc:creator>
      <dc:date>2008-08-22T09:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134287#M914149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - so what is the issue??  Are there any other subnets on the outside that you want to connect to?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 10:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134287#M914149</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-08-22T10:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134288#M914151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I understand now - after re-reading your initial post.  Cut and past the config below and re-test:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat (outside) 0 access-list outside_access_in outside&lt;/P&gt;&lt;P&gt;no nat (inside) 0 access-list inside_access_out&lt;/P&gt;&lt;P&gt;no access-list outside_access_in permit ip 10.34.12.0 255.255.255.0 10.34.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;no access-list outside_access_in permit ip 10.34.12.0 255.255.255.0 10.0.0.0 255.0.0.0 &lt;/P&gt;&lt;P&gt;no access-list inside_access_out permit ip 10.34.3.0 255.255.255.0 10.34.12.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;no access-list inside_access_out permit ip 10.0.0.0 255.0.0.0 10.34.12.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.34.3.0 10.34.3.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;static (outside,inside) 10.34.12.0 10.34.12.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 10:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134288#M914151</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-08-22T10:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134289#M914154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah right, this could help but in that case firewall will do proxy arp featute that way it can crash these two networks. It may be a good point to use these static with proxy arp disabled on interfaces, but what to do with other 10.x.x.x networks ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 10:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134289#M914154</guid>
      <dc:creator>radutily1</dc:creator>
      <dc:date>2008-08-22T10:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134290#M914158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you just add static statements per network, or just change the previous suggestion to:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.0.0.0 10.0.0.0 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (outside,inside) 10.0.0.0 10.0.0.0 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That way all networks in the 10/8 are the same passing thru the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 10:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134290#M914158</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-08-22T10:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134291#M914164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right this one should work with disabled proxy arp:&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.0.0.0 10.0.0.0 netmask 255.0.0.0 &lt;/P&gt;&lt;P&gt;static (outside,inside) 10.0.0.0 10.0.0.0 netmask 255.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sysopt noproxyarp outside&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guys from that site have already left - will check on Monday ond provide you results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 11:31:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134291#M914164</guid>
      <dc:creator>radutily1</dc:creator>
      <dc:date>2008-08-22T11:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134292#M914166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys. These configuration rows with disabled proxy arp resolved my problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2008 05:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134292#M914166</guid>
      <dc:creator>radutily1</dc:creator>
      <dc:date>2008-08-26T05:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 506E 6.3(3)need to pass networks without nat translation</title>
      <link>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134293#M914168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2008 08:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-506e-6-3-3-need-to-pass-networks-without-nat-translation/m-p/1134293#M914168</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-08-26T08:16:12Z</dc:date>
    </item>
  </channel>
</rss>

