<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower NAT confusion in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872775#M942276</link>
    <description>Thanks so much Marvin, this answered my question perfectly!</description>
    <pubDate>Fri, 14 Jun 2019 00:15:40 GMT</pubDate>
    <dc:creator>Warren Sullivan - Corp</dc:creator>
    <dc:date>2019-06-14T00:15:40Z</dc:date>
    <item>
      <title>Firepower NAT confusion</title>
      <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3871315#M942265</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently writing a migration document to move from SOPHOS UTM to Firepower and i'm getting a little confused with Firepower NAT.&lt;/P&gt;&lt;P&gt;Lets say i want to configure what i used to call a "masquerading" rule (NAT Overload or PAT)&lt;/P&gt;&lt;P&gt;I create a Dynamic Auto NAT Rule, select the original source of the traffic to be translated, all good&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i want to set the translated source to the outgoing physical interface, i set "translated source" to "Destination Interface IP"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i want to hardset a different single IP on the outside i can configure a host object and select it there also....but;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What if i want to select a pool of addresses? It seems i can do that two ways?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the "Translated Source" field below, i can set a range of addresses....isn't that essentially what happens on the next Tab? PAT Pool?&lt;/P&gt;&lt;P&gt;Are they essentially the same thing? (with a couple more options under PAT Pool)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance guys and gals &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="12-06-2019 7-47-36 AM.jpg" style="width: 879px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/38418i1AC7593337106318/image-size/large?v=v2&amp;amp;px=999" role="button" title="12-06-2019 7-47-36 AM.jpg" alt="12-06-2019 7-47-36 AM.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:12:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3871315#M942265</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2020-02-21T17:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower NAT confusion</title>
      <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3871542#M942267</link>
      <description>&lt;P&gt;Firepower NAT and ASA NAT is the same. if you understand the ASA NAT you could easily do Firepower NAT too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the link would help you what you want to acheive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050" target="_blank"&gt;https://community.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 08:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3871542#M942267</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-06-12T08:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower NAT confusion</title>
      <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872153#M942270</link>
      <description>Thanks for the link Sheraz,&lt;BR /&gt;&lt;BR /&gt;Unfortunately, it doesn't really help me or answer my questions, as i am not familiar with ASA or Firepower NAT, i have worked with PA, Fortigate and Sophos NAT but not Cisco, i'm a Cisco route/switch guy after a quick explanation if possible, i would have thought it was a fairly easy question for someone who is familiar with the Firepower GUI...&lt;BR /&gt;&lt;BR /&gt;Thanks again</description>
      <pubDate>Thu, 13 Jun 2019 04:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872153#M942270</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2019-06-13T04:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower NAT confusion</title>
      <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872485#M942273</link>
      <description>&lt;P&gt;The configuration in your original post's screenshot is not PAT. It will dynamically assign the source addresses 1-1 NAT entries as long as there are addresses available in the pool or translated addresses. As the FMC Configuration Guide notes, "Many-to-few or many-to-one NAT is not PAT."&lt;/P&gt;
&lt;P&gt;Using the PAT Pool tab will allow you to configure dynamic PAT in a many-many scenario such as you describe. The PAT will use the IPs in the pool sequentially - when the available source ports are exhausted for one address it will move on to the next available one, for all of the tcp connections or udp flows through the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 14:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872485#M942273</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-06-13T14:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower NAT confusion</title>
      <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872775#M942276</link>
      <description>Thanks so much Marvin, this answered my question perfectly!</description>
      <pubDate>Fri, 14 Jun 2019 00:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872775#M942276</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2019-06-14T00:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower NAT confusion</title>
      <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872779#M942277</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just one last question, for this conversation anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I now understand the 1:1 nature of the pool defined under "Translated Packet"but;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the below PAT?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT99.png" style="width: 900px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/38556i898D2EE48A90DD18/image-size/large?v=v2&amp;amp;px=999" role="button" title="NAT99.png" alt="NAT99.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 00:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872779#M942277</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2019-06-14T00:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower NAT confusion</title>
      <link>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872815#M942278</link>
      <description>&lt;P&gt;Yes, I believe that one will be PAT. It's a bit confusing/misleading how they reflect it in the GUI.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 02:34:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-nat-confusion/m-p/3872815#M942278</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-06-14T02:34:27Z</dc:date>
    </item>
  </channel>
</rss>

