<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic nat conversion in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-conversion/m-p/3381183#M958784</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me on how to convert this 8.1 cisco asa configuration into 9.1.&amp;nbsp; Appreciate the help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;global (outsid) 2 150.x.x.x&lt;/P&gt;
&lt;P&gt;nat (inside) 2 10.1.200.0 255.255.255.0 tcp 100 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:45:09 GMT</pubDate>
    <dc:creator>ttnilicense</dc:creator>
    <dc:date>2020-02-21T15:45:09Z</dc:date>
    <item>
      <title>nat conversion</title>
      <link>https://community.cisco.com/t5/network-security/nat-conversion/m-p/3381183#M958784</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me on how to convert this 8.1 cisco asa configuration into 9.1.&amp;nbsp; Appreciate the help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;global (outsid) 2 150.x.x.x&lt;/P&gt;
&lt;P&gt;nat (inside) 2 10.1.200.0 255.255.255.0 tcp 100 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-conversion/m-p/3381183#M958784</guid>
      <dc:creator>ttnilicense</dc:creator>
      <dc:date>2020-02-21T15:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: nat conversion</title>
      <link>https://community.cisco.com/t5/network-security/nat-conversion/m-p/3381270#M958785</link>
      <description>&lt;P&gt;This should do it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network obj-150.x.x.x&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host 150.x.x.x&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;object network obj-10.1.200.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;subnet&amp;nbsp;10.1.200.0 255.255.255.0&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;nat (inside,outside) source dynamic obj-10.1.200.0&amp;nbsp;obj-150.x.x.x&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Documentation used:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/nat_dynamic.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/nat_dynamic.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the last part (most interesting one):&amp;nbsp;&lt;SPAN&gt;tcp 100 100 ; here's the answer:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;EM&gt;The&amp;nbsp;&lt;STRONG class="cBold"&gt;tcp&lt;/STRONG&gt;&amp;nbsp;option specifies the protocol at TCP.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A name="wp1089739" target="_blank"&gt;&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;EM&gt;The&amp;nbsp;tcp_max_cons&amp;nbsp;argument specifies the maximum number of simultaneous TCP connections allowed to the local-host (see the local-host command). The default is 0, which means unlimited connections. (Idle connections are closed after the idle timeout specified by the timeout conn command.)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A name="wp1090058" target="_blank"&gt;&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;EM&gt;The&amp;nbsp;emb_limit&amp;nbsp;option specifies the maximum number of embryonic connections per host. The default is&amp;nbsp;&lt;STRONG class="cBold"&gt;0,&lt;/STRONG&gt;&amp;nbsp;which means unlimited embryonic connections.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;Martin pointed out couple years ago &lt;A href="https://supportforums.cisco.com/t5/firewalling/how-to-configure-limit-tcp-udp-session-using-static-rule-on-asa/td-p/2472559" target="_self"&gt;here&lt;/A&gt;:&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The ability to limit this per NAT rule was deprecated with the overhaul of NAT functions in ASA 8.3.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Currently we can only limit connections globally or in policy maps using the "set connection" options.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 12:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-conversion/m-p/3381270#M958785</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-10T12:06:02Z</dc:date>
    </item>
  </channel>
</rss>

