<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT exempt to Internat Interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942431#M941048</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; If you use NAT exemption, and you put from source network to any, your internal network will be able to access internet only through VPN connection.  this will put heavy load on  the ASA.&lt;/P&gt;&lt;P&gt; regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Mar 2008 10:50:00 GMT</pubDate>
    <dc:creator>alanajjar</dc:creator>
    <dc:date>2008-03-13T10:50:00Z</dc:date>
    <item>
      <title>NAT exempt to Internat Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942429#M941044</link>
      <description>&lt;P&gt;I am looking for the most efficient way to configure NAT exempt statements for a multiple interface ASA. I know I will need to write ACL's but do I write based on source and destination networks? Or source network to Any? Any suggestions would be greatly appreicated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942429#M941044</guid>
      <dc:creator>jkeddington_2</dc:creator>
      <dc:date>2019-03-11T12:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT exempt to Internat Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942430#M941046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on your network requirements. If you want to exempt the source network to destination network(any) then you can use (example:- internal to any) if you want only source network could access a particular network then exempt destination network instead of any. As per the cisco, the higher zone network can access the lower security zone by default and if you want to give the access to lower zone network to highher zone network then you need access list. Create rule step by step would be in proper way. Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Mar 2008 05:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942430#M941046</guid>
      <dc:creator>ray_stone</dc:creator>
      <dc:date>2008-03-13T05:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAT exempt to Internat Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942431#M941048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; If you use NAT exemption, and you put from source network to any, your internal network will be able to access internet only through VPN connection.  this will put heavy load on  the ASA.&lt;/P&gt;&lt;P&gt; regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Mar 2008 10:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942431#M941048</guid>
      <dc:creator>alanajjar</dc:creator>
      <dc:date>2008-03-13T10:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT exempt to Internat Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942432#M941049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is really good to know, I was going to see what would happen with nat0 to any but no need too now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2008 04:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-to-internat-interfaces/m-p/942432#M941049</guid>
      <dc:creator>jkeddington_2</dc:creator>
      <dc:date>2008-03-14T04:59:58Z</dc:date>
    </item>
  </channel>
</rss>

