<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fixing NAT entries in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fixing-nat-entries/m-p/1019450#M939607</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;with changes i need (or want) to do during biz hours, i usually first type them up in my fav. text editor (textpad) and then copy/paste them into my fav. telnet/ssh client (securecrt).&lt;/P&gt;&lt;P&gt;in your case:&lt;/P&gt;&lt;P&gt;no nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.1.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...to build on sundar's example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Apr 2008 18:26:40 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2008-04-08T18:26:40Z</dc:date>
    <item>
      <title>Fixing NAT entries</title>
      <link>https://community.cisco.com/t5/network-security/fixing-nat-entries/m-p/1019448#M939605</link>
      <description>&lt;P&gt;I have a Cisco 515e running 7.0(1) and one problem with the config of my NATs on my PIX is that the inside interface is not NATed. Rather just the subnet of my internal network. So when I try to add a NAT rule for a single host on that subnet I get: "This static port mapping rule is overlapping with a dynamic address translation rule for X.X.X.X/255.255.252.0 using global pool 1. Do you wish to proceed?" I suppose i could proceed without issue? In the end I would like to replace the subnet NAT using the inside interface, so that I don't receive this message every time i set up a static NAT. But i do not want to compromise breaking my security policies. Is it possible to insert the inside interface NAT and then remove the subnet NAT without breaking my Security Policies and causing too much disruption? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:28:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixing-nat-entries/m-p/1019448#M939605</guid>
      <dc:creator>shorila</dc:creator>
      <dc:date>2019-03-11T12:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Fixing NAT entries</title>
      <link>https://community.cisco.com/t5/network-security/fixing-nat-entries/m-p/1019449#M939606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should experience only a brief disruption when you add nat inside and remove the static NAT configuration. You might want to be precise when you configure nat inside instead of nat anything to setup a more secure configuration. For example a more secure configuration would be nat (inside)1 10.1.1.0 255.255.255.0 instead of nat (inside) 1 0.0.0.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Apr 2008 17:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixing-nat-entries/m-p/1019449#M939606</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-04-08T17:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Fixing NAT entries</title>
      <link>https://community.cisco.com/t5/network-security/fixing-nat-entries/m-p/1019450#M939607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;with changes i need (or want) to do during biz hours, i usually first type them up in my fav. text editor (textpad) and then copy/paste them into my fav. telnet/ssh client (securecrt).&lt;/P&gt;&lt;P&gt;in your case:&lt;/P&gt;&lt;P&gt;no nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.1.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...to build on sundar's example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Apr 2008 18:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixing-nat-entries/m-p/1019450#M939607</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-04-08T18:26:40Z</dc:date>
    </item>
  </channel>
</rss>

