<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allowing Natted IPs through ASA? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865901#M925470</link>
    <description>Oh ok sorry, you mean the firewall itself is not doing the nat translation? If this is inbound traffic, and the ASA is not doing any NAT translation/un-translation, then the ASA would only know the public IP address - therefore the ACL rule should reference the only IP address it recieved traffic from (the public IP address).</description>
    <pubDate>Fri, 31 May 2019 17:48:06 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-05-31T17:48:06Z</dc:date>
    <item>
      <title>Allowing Natted IPs through ASA?</title>
      <link>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865756#M925467</link>
      <description>&lt;P&gt;You must still use the natted IP not the real source IP in the access-rules correct?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:11:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865756#M925467</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2020-02-21T17:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Natted IPs through ASA?</title>
      <link>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865791#M925468</link>
      <description>Hi,&lt;BR /&gt;No, you always use the real IP address in the ACL not the natted ip address.&lt;BR /&gt;&lt;BR /&gt;I believe older version of ASA, v8.2 (from memory) however was different in regard to NAT. I assume you have a relatively new 9.x version of ASA? In which case use the real IP address.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Fri, 31 May 2019 14:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865791#M925468</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-05-31T14:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Natted IPs through ASA?</title>
      <link>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865812#M925469</link>
      <description>Just so I can clarify, so if the IPs are being Natted prior to the FW you need to enter the original IP?</description>
      <pubDate>Fri, 31 May 2019 14:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865812#M925469</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2019-05-31T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Natted IPs through ASA?</title>
      <link>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865901#M925470</link>
      <description>Oh ok sorry, you mean the firewall itself is not doing the nat translation? If this is inbound traffic, and the ASA is not doing any NAT translation/un-translation, then the ASA would only know the public IP address - therefore the ACL rule should reference the only IP address it recieved traffic from (the public IP address).</description>
      <pubDate>Fri, 31 May 2019 17:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3865901#M925470</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-05-31T17:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing Natted IPs through ASA?</title>
      <link>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3867130#M925471</link>
      <description>&lt;P&gt;Yes sorry I should have clarified but awesome thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just created another post, but what if I want to NAT an internal IP address to another IP address that should be allowed to transverse an IPSEC tunnel on an ASA? Example, I have 160.1.1.10 address that I want to be Natted to 170.1.1.10 which is an source IP allowed to reach 200.1.1.10 destination IP of the IPSEC tunnel?&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to my NAT statement which is:&lt;/P&gt;&lt;P&gt;"Object-Nat" natting static 160.1.1.10 to 170.1.1.10 and choosing Inside interface as source interface (160.1.1.10 host is in the Inside interface) and Outside interface (IPSEC tunnel starts/exits Outside interface on both Local and Remote Tunnel/ASA devices,&lt;/P&gt;&lt;P&gt;Do I need to create another ACL rule which would be applied to the Crypto Map ACL or no since the Crypto Map ACL is already defining/allowing source address 170.1.1.10 to reach remote destination IP 200.1.1.10?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 02:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allowing-natted-ips-through-asa/m-p/3867130#M925471</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2019-06-04T02:13:33Z</dc:date>
    </item>
  </channel>
</rss>

