<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question regarding a use of static in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-regarding-a-use-of-static/m-p/860566#M956843</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, that helped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jan 2008 10:40:24 GMT</pubDate>
    <dc:creator>azore2007</dc:creator>
    <dc:date>2008-01-18T10:40:24Z</dc:date>
    <item>
      <title>Question regarding a use of static</title>
      <link>https://community.cisco.com/t5/network-security/question-regarding-a-use-of-static/m-p/860564#M956837</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Situation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a VPN connection to another company where they get connection to the following hosts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.14.2&lt;/P&gt;&lt;P&gt;192.168.14.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I have another company that needs access to these hosts also, but they have the same IP-range in use in their network. So I'm gonna use static and put my two hosts on my DMZ1 which has public IP's instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz1) 111.111.111.111 192.168.14.2&lt;/P&gt;&lt;P&gt;static (inside,dmz1) 111.111.111.112 192.168.14.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will put both my hosts in global "mode" in the firewall..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question is, will this break my old VPN tunnel to the other company? If they try to reach 192.168.14.2, will the firewall stop them or something? Or will it also work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-regarding-a-use-of-static/m-p/860564#M956837</guid>
      <dc:creator>azore2007</dc:creator>
      <dc:date>2019-03-11T11:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding a use of static</title>
      <link>https://community.cisco.com/t5/network-security/question-regarding-a-use-of-static/m-p/860565#M956840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It can work without problems ;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since your  "nat (inside) 0"  have precedence over the static statement, traffic for the first tunnel will be nonated , routed on your outside or dmz1 interface where it will trigger the crypto engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic for the  2nd tunnel will get nated , then routed on your dmz1 interface where it will trigger the crypto engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing to check is that your crypto-acl for the second tunnel must use the translated addresses as the source. Remember that the natting occurs before the crypting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i don't have your complete config , but if the default gateway oy your PIX is on the outside interface , you will need 2 routes on your  dmz1 interface. One for the VPN peer IP , and also one for the peer internal subnet.   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2008 21:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-regarding-a-use-of-static/m-p/860565#M956840</guid>
      <dc:creator>michelcaissie</dc:creator>
      <dc:date>2008-01-17T21:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding a use of static</title>
      <link>https://community.cisco.com/t5/network-security/question-regarding-a-use-of-static/m-p/860566#M956843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, that helped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 10:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-regarding-a-use-of-static/m-p/860566#M956843</guid>
      <dc:creator>azore2007</dc:creator>
      <dc:date>2008-01-18T10:40:24Z</dc:date>
    </item>
  </channel>
</rss>

