<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static Nat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913742#M941909</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Always u r response very helpfull for me.Thanks again and again.So As per my senario i require 2 public ip's to do Nat in firewall(1 firewall interface and 1 for Static Nat)..But i have one free ip only..So i did Static Nat in router level itself..Let me explain my problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   My firewall is in Data center(DC)..Webserver is in branch as i said in the diagram.If i place in the webserver in DC i can access from outside..but if i place the webserver in branch(R3 router) i m unable to access from outside(getting connections in firewall(saAB))..I think some routing issue..As per current setup we have route in router to connect DC network.I think we have to add route in router like the request from internet need to go to outside(Kindly let me know the route)..Provide me ur valuable information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Feb 2008 06:19:41 GMT</pubDate>
    <dc:creator>sureshkumar</dc:creator>
    <dc:date>2008-02-25T06:19:41Z</dc:date>
    <item>
      <title>Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913740#M941907</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ISP--R1--Firewall--R2--R3--Pc(webserver)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   ISP is terminated in the R1 router.To provide internet for users, Dynamic NATing are given in the rotuer(R1) level itself.R1 F0 ip is primary public ip and Secondary ip is private ip which is terminated in the Firewall interface(Private ip)..Now i need to privide Static Nat for my webserver.Is it possible to do it in Firewall..I think we can't....i have to do only in the router..&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913740#M941907</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2019-03-11T12:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913741#M941908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well the public ip address would be translated on router to firewall interface ip/or any other free ip from that pool and then on firewall we need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface/ip 80 &lt;REAL ip="" of="" server=""&gt; 80&lt;/REAL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-l abc permit tcp any host interface eq 80&lt;/P&gt;&lt;P&gt;access-g abc in interface outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2008 14:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913741#M941908</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-23T14:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913742#M941909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Always u r response very helpfull for me.Thanks again and again.So As per my senario i require 2 public ip's to do Nat in firewall(1 firewall interface and 1 for Static Nat)..But i have one free ip only..So i did Static Nat in router level itself..Let me explain my problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   My firewall is in Data center(DC)..Webserver is in branch as i said in the diagram.If i place in the webserver in DC i can access from outside..but if i place the webserver in branch(R3 router) i m unable to access from outside(getting connections in firewall(saAB))..I think some routing issue..As per current setup we have route in router to connect DC network.I think we have to add route in router like the request from internet need to go to outside(Kindly let me know the route)..Provide me ur valuable information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2008 06:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913742#M941909</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-25T06:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913743#M941910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly provide me solution as soon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2008 13:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913743#M941910</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-25T13:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913744#M941911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you don't need 2 free IPs..you can do static PAT using firewalls outside IP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2008 14:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913744#M941911</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-25T14:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913745#M941912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks..As per now i can't change interface ip of firewall.so i did already in router..but unable to access from outside..some routing issues are there still..Can u plz help me out..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2008 15:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913745#M941912</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-25T15:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913746#M941913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;to what ip address is router translating the request to ?&lt;/P&gt;&lt;P&gt;Give me the sh run static/sh static output, sh run access-group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2008 15:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913746#M941913</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-25T15:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913747#M941914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix Fw(535)--3 interface(inside, outside, branch)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3 Routers(R1,R2 and R3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Webserver--in brach(R3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In beteween R2 and R3---OSPF--Is there anything need to add?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R1--NAT, PAT and routes( Default towards Serial int, Network based towards Firewall Int)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix--(Acl from out to in, Default route towards outside, network routes towards branch and inside, nonat for translation in higher Security interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i access from outside to webserver i m finding conn in firewall( conn status : saAB)..Even i m finding the outsid world ip in my webserver log also..Some return traffic flow is not happening..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 07:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913747#M941914</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-26T07:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913748#M941915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In R1&lt;/P&gt;&lt;P&gt;#sh run | incl static&lt;/P&gt;&lt;P&gt;Ip nat outside static 172.x.x.x 203.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rest of the things unable to do. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 12:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913748#M941915</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-26T12:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913749#M941918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Suresh..as a test allow icmp through the firewall and ping the web server, also can you ping the webserver from the firewall..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me the real ip address of the web server ? if possible post your config here&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 12:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913749#M941918</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-26T12:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913750#M941921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks u very much..Kindly find the attached file..In my client place i m taking care only Pix..rest of the router parts all taking care by other vendor..Static Nat is in router level..let me know the router level routes and verify the PIX config also..If i try to access from outside i m finding conn status(saAB)..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP out 123.176.41.235:4579 in 172.24.248.178:443 idle 0:01:14 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;TCP out 123.176.41.235:4580 in 172.24.248.178:443 idle 0:00:43 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;TCP out 123.176.41.235:4581 in 172.24.248.178:443 idle 0:00:14 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m finding the public ip(123.176.41.235) in websever log also..I think return traffic is not flowing.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 14:31:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913750#M941921</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-26T14:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913751#M941925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kindly ignore the previous post..attachment is not there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks u very much..Kindly find the attached file..In my client place i m taking care only Pix..rest of the router parts all taking care by other vendor..Static Nat is in router level..let me know the router level routes and verify the PIX config also..If i try to access from outside i m finding conn status(saAB)..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP out 123.176.41.235:4579 in 172.24.248.178:443 idle 0:01:14 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;TCP out 123.176.41.235:4580 in 172.24.248.178:443 idle 0:00:43 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;TCP out 123.176.41.235:4581 in 172.24.248.178:443 idle 0:00:14 Bytes 0 flags SaAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m finding the public ip(123.176.41.235) in websever log also..I think return traffic is not flowing.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Attachment Keywords : &lt;/B&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 14:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913751#M941925</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-26T14:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913752#M941927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;config looks good...are we able to ping the webserver from the firewall ?&lt;/P&gt;&lt;P&gt;can you get me sh ip route from both r2 and r3 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 15:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913752#M941927</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-26T15:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913753#M941928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unable to ping the webserver from firewall..&lt;/P&gt;&lt;P&gt;But i can ping R3 router from R1 and from R1 to R3...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly find the atached file R2 ad R3...In R3 no static routes..as i said before OSPF..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2008 05:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913753#M941928</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-27T05:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913754#M941929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from webserver can you ping R1..?&lt;/P&gt;&lt;P&gt;run debug icmp trace on firewall while you initiate a ping from webserver to R1 and 4.2.2.2 simultaneously&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2008 12:16:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913754#M941929</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-27T12:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913755#M941930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes..I can...Is there any issues with the routes in router R1 and R2..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2008 12:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913755#M941930</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-27T12:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913756#M941931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey Suresh..the connection detail TCP out 123.176.41.235:4579 in 172.24.248.178:443 idle 0:01:14 Bytes 0 flags SaAB, clearly indicate that there was no return synack on the firewall back from web server, so either the issue is on WEBSERVER or R2 or R2 &lt;/P&gt;&lt;P&gt;Now from WEBserver are you able to ping 4.2.2.2 through the firewall ? do you see these ICMPs request and replies in debug icmp trace ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see a DG  on R2..??how would R2 know where to send the return packet ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2008 12:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913756#M941931</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-27T12:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat</title>
      <link>https://community.cisco.com/t5/network-security/static-nat/m-p/913757#M941933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After once added route in R2..we got the connectivity...Thanks for ur support..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 10:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat/m-p/913757#M941933</guid>
      <dc:creator>sureshkumar</dc:creator>
      <dc:date>2008-02-29T10:41:14Z</dc:date>
    </item>
  </channel>
</rss>

