<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: basic Nat rule (newbie) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013700#M937320</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also I think you have the static rule the wrong way round:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 194.250.0.50 190.100.100.102 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least that is how we do it here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 May 2008 11:11:12 GMT</pubDate>
    <dc:creator>jigsaw2026</dc:creator>
    <dc:date>2008-05-23T11:11:12Z</dc:date>
    <item>
      <title>basic Nat rule (newbie)</title>
      <link>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013696#M937302</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I am a newbie for cisco pics and I wanted to add abasic NAT rule to my firewall to allow and redirect FTP requests from internet to one of my public adresses&lt;/P&gt;&lt;P&gt;194.250.0.50 to an internal computer 190.100.100.102.&lt;/P&gt;&lt;P&gt;using the web interface I added one nat rule: &lt;/P&gt;&lt;P&gt;static (outside,inside) 190.100.100.102 194.250.0.50 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;and allow incoming ftp requests:&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp host 190.100.100.102 eq ftp host 194.50.0.0 eq ftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;proxy arp is enabled&lt;/P&gt;&lt;P&gt;but when trying to connect from outside to 194.250.0.50 is denied&lt;/P&gt;&lt;P&gt;here is what I got in the log:&lt;/P&gt;&lt;P&gt;106023:Deny tcp src 195.115.153.23x/xxxx dst inside:ftpexternal/21 by access-group "outside_access_in"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ftpexternal stands for 194.250.0.50&lt;/P&gt;&lt;P&gt;Look's like my rule is not correct .&lt;/P&gt;&lt;P&gt;Can any one help me on the matter ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013696#M937302</guid>
      <dc:creator>paul.lahitte</dc:creator>
      <dc:date>2019-03-11T12:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: basic Nat rule (newbie)</title>
      <link>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013697#M937306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks to me like your ACL is wrong - is should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp host 195.115.153.23x host 194.250.0.50 eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's assuming that you only want access from that one external host - you can have any host or network in there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't need an ACL from 190.100.100.102 to 194.250 (in any case your ACL was referencing 194.50.0.0).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 09:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013697#M937306</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2008-05-23T09:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: basic Nat rule (newbie)</title>
      <link>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013698#M937311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank's&lt;/P&gt;&lt;P&gt;I just want any network being able to connect to 194.250.0.50 using ftp .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 10:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013698#M937311</guid>
      <dc:creator>paul.lahitte</dc:creator>
      <dc:date>2008-05-23T10:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: basic Nat rule (newbie)</title>
      <link>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013699#M937315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So then:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 194.250.0.50 eq ftp &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 11:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013699#M937315</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2008-05-23T11:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: basic Nat rule (newbie)</title>
      <link>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013700#M937320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also I think you have the static rule the wrong way round:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 194.250.0.50 190.100.100.102 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least that is how we do it here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 11:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013700#M937320</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2008-05-23T11:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: basic Nat rule (newbie)</title>
      <link>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013701#M937323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank's it is working&lt;/P&gt;&lt;P&gt;thank's lot again &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 11:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-nat-rule-newbie/m-p/1013701#M937323</guid>
      <dc:creator>paul.lahitte</dc:creator>
      <dc:date>2008-05-23T11:53:22Z</dc:date>
    </item>
  </channel>
</rss>

