<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic configure static NAT in FWSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configure-static-nat-in-fwsm/m-p/845169#M960413</link>
    <description>&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;I use FWSM and now I want to configure static NAT in FWSM: &lt;/P&gt;&lt;P&gt;Diagram: &lt;/P&gt;&lt;P&gt;Webserver : 192.0.2.6/32 , interface: inside&lt;/P&gt;&lt;P&gt;NAT IP : 202.78.x.x /32 , interface: outside &lt;/P&gt;&lt;P&gt;I want to configuse static NAT from Webserver to IP Puplic and everyone can connect to Webserver with Service Any.&lt;/P&gt;&lt;P&gt;I only configure : &lt;/P&gt;&lt;P&gt;nameif vlan2 inside security100&lt;/P&gt;&lt;P&gt;access-list INSIDE extended permit ip 192.0.2.0 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-list acl_mdc_inside_access extended permit ip object-group any&lt;/P&gt;&lt;P&gt;ip address inside 192.0.2.x 255.255.255.0 standby 192.0.2.x&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list INSIDE&lt;/P&gt;&lt;P&gt;access-group acl_mdc_inside_access in interface inside&lt;/P&gt;&lt;P&gt;static (inside, outside) 202.78.x.x 192.0.2.6 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;I must configure access-list and routing? &lt;/P&gt;&lt;P&gt;If you need more information, please ask me. &lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;Duy Khang&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2019 00:49:46 GMT</pubDate>
    <dc:creator>mylove142</dc:creator>
    <dc:date>2019-03-13T00:49:46Z</dc:date>
    <item>
      <title>configure static NAT in FWSM</title>
      <link>https://community.cisco.com/t5/network-security/configure-static-nat-in-fwsm/m-p/845169#M960413</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;I use FWSM and now I want to configure static NAT in FWSM: &lt;/P&gt;&lt;P&gt;Diagram: &lt;/P&gt;&lt;P&gt;Webserver : 192.0.2.6/32 , interface: inside&lt;/P&gt;&lt;P&gt;NAT IP : 202.78.x.x /32 , interface: outside &lt;/P&gt;&lt;P&gt;I want to configuse static NAT from Webserver to IP Puplic and everyone can connect to Webserver with Service Any.&lt;/P&gt;&lt;P&gt;I only configure : &lt;/P&gt;&lt;P&gt;nameif vlan2 inside security100&lt;/P&gt;&lt;P&gt;access-list INSIDE extended permit ip 192.0.2.0 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-list acl_mdc_inside_access extended permit ip object-group any&lt;/P&gt;&lt;P&gt;ip address inside 192.0.2.x 255.255.255.0 standby 192.0.2.x&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list INSIDE&lt;/P&gt;&lt;P&gt;access-group acl_mdc_inside_access in interface inside&lt;/P&gt;&lt;P&gt;static (inside, outside) 202.78.x.x 192.0.2.6 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;I must configure access-list and routing? &lt;/P&gt;&lt;P&gt;If you need more information, please ask me. &lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;Duy Khang&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-static-nat-in-fwsm/m-p/845169#M960413</guid>
      <dc:creator>mylove142</dc:creator>
      <dc:date>2019-03-13T00:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: configure static NAT in FWSM</title>
      <link>https://community.cisco.com/t5/network-security/configure-static-nat-in-fwsm/m-p/845170#M960418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Duy, you have to configure static nat which you already have in script, access-list to allow inbound traffic and apply acl to outside interface. Don't have to configure routing unless this is new PIX fwsm setup,  if it is new setup you need to configure global nat and  default route  to access outside internet. Is outside interface the only public IP address you have for NAT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g, if you are using spare public  IP address for webserver NAT config would look as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 202.78.x.x 192.0.2.6 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host  202.78.x.x &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if using outside pix interface IP address as your NAT/PAT address static should be as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) interface 192.0.2.6 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host  202.78.x.x &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to configuire glonal nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (oustide) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to configure default route&lt;/P&gt;&lt;P&gt;route outside 0 0  x.x.x.x  1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where x is ISP router and 1 is next hop. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2007 04:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-static-nat-in-fwsm/m-p/845170#M960418</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-11-19T04:23:49Z</dc:date>
    </item>
  </channel>
</rss>

