<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sub-interface Nat problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3396821#M955200</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;On Asa I have configured 2 internal sub-interfaces GigabitEthernet0/3.50 and&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;GigabitEthernet0/3.70.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config on both interfaces :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GigabitEthernet0/3.50 (vlan50-192.168.50.1/24) security-level is 80. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GigabitEthernet0/3.50 (vlan70-192.168.70.1/24) security-level is 90&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Both subnets which belongs to these interfaces are translated to outside interface.Problem is i want to configure lower security-level interface to have ip connectivity to higher security-level sub interface subnet.When i configure access-list and twice nat for&amp;nbsp;GigabitEthernet0/3.50&amp;nbsp; , i loose connectivity to outside translation. Need yours help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:51:48 GMT</pubDate>
    <dc:creator>Zamilnewbie</dc:creator>
    <dc:date>2020-02-21T15:51:48Z</dc:date>
    <item>
      <title>Sub-interface Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3396821#M955200</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;On Asa I have configured 2 internal sub-interfaces GigabitEthernet0/3.50 and&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;GigabitEthernet0/3.70.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config on both interfaces :&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GigabitEthernet0/3.50 (vlan50-192.168.50.1/24) security-level is 80. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GigabitEthernet0/3.50 (vlan70-192.168.70.1/24) security-level is 90&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Both subnets which belongs to these interfaces are translated to outside interface.Problem is i want to configure lower security-level interface to have ip connectivity to higher security-level sub interface subnet.When i configure access-list and twice nat for&amp;nbsp;GigabitEthernet0/3.50&amp;nbsp; , i loose connectivity to outside translation. Need yours help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3396821#M955200</guid>
      <dc:creator>Zamilnewbie</dc:creator>
      <dc:date>2020-02-21T15:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3396828#M955201</link>
      <description>&lt;P&gt;I`m new to this firewall.Any help appreciated.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jun 2018 13:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3396828#M955201</guid>
      <dc:creator>Zamilnewbie</dc:creator>
      <dc:date>2018-06-09T13:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3396850#M955202</link>
      <description>&lt;P&gt;???????????&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jun 2018 14:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3396850#M955202</guid>
      <dc:creator>Zamilnewbie</dc:creator>
      <dc:date>2018-06-09T14:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3397006#M955203</link>
      <description>&lt;P&gt;First off, be patient. CSC is a free user-supported forum. If you require answers within an hour then use paid TAC support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your:&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs"&gt;&lt;CODE class="txt"&gt;access-list 50-to-70 extended permit ip object network-OBJ-192.168.50.0 object network-OBJ-192.168.70.0
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...will prevent anything not explicitly allowed in that statement. This is because as soon as you apply an ACL to an onterface there is an implicit "deny ip any any" statement at the end.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should add a second line preventing traffic from 192.168.50.0 to inside networks and then a third with a permit for 192.168.50.0 to any to include internet-bound traffic.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jun 2018 14:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3397006#M955203</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-06-10T14:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface Nat problem</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3397020#M955204</link>
      <description>Thanks for your attention and answer.Appreciated.</description>
      <pubDate>Sun, 10 Jun 2018 14:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-nat-problem/m-p/3397020#M955204</guid>
      <dc:creator>Zamilnewbie</dc:creator>
      <dc:date>2018-06-10T14:01:56Z</dc:date>
    </item>
  </channel>
</rss>

