<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity NAT on ASA running Version 9.0(1) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3364814#M962980</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I apprecitae the quick reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt; Type: ACCESS-LIST&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Implicit Rule&lt;BR /&gt; Additional Information:&lt;BR /&gt; MAC Access list&lt;BR /&gt; &lt;BR /&gt; Phase: 2&lt;BR /&gt; Type: ROUTE-LOOKUP&lt;BR /&gt; Subtype: input&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;BR /&gt; &lt;BR /&gt; Phase: 3&lt;BR /&gt; Type: ACCESS-LIST&lt;BR /&gt; Subtype: log&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; access-group inside_access_in in interface inside&lt;BR /&gt; access-list inside_access_in extended permit ip any any log disable &lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 4&lt;BR /&gt; Type: NAT&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; object network LAN&lt;BR /&gt; &amp;nbsp;nat (inside,outside) static 10.100.52.0 no-proxy-arp route-lookup&lt;BR /&gt; Additional Information:&lt;BR /&gt; Static translate 10.100.52.23/25685 to 10.100.52.23/25685&lt;BR /&gt; &lt;BR /&gt; Phase: 5&lt;BR /&gt; Type: NAT&lt;BR /&gt; Subtype: per-session&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 6&lt;BR /&gt; Type: IP-OPTIONS&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 7&lt;BR /&gt; Type: INSPECT&lt;BR /&gt; Subtype: inspect-ftp&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; class-map class-default&lt;BR /&gt; &amp;nbsp;match any&lt;BR /&gt; policy-map global_policy&lt;BR /&gt; &amp;nbsp;class class-default&lt;BR /&gt; &amp;nbsp; inspect ftp &lt;BR /&gt; service-policy global_policy global&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 8&lt;BR /&gt; Type: FOVER&lt;BR /&gt; Subtype: standby-update&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 9&lt;BR /&gt; Type: &lt;BR /&gt; Subtype:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 10&lt;BR /&gt; Type: USER-STATISTICS&lt;BR /&gt; Subtype: user-statistics&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 11&lt;BR /&gt; Type: NAT&lt;BR /&gt; Subtype: per-session&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 12&lt;BR /&gt; Type: IP-OPTIONS&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 13&lt;BR /&gt; Type: USER-STATISTICS&lt;BR /&gt; Subtype: user-statistics&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 14&lt;BR /&gt; Type: FLOW-CREATION&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; New flow created with id 960453070, packet dispatched to next module&lt;BR /&gt; &lt;BR /&gt; Result:&lt;BR /&gt; input-interface: inside&lt;BR /&gt; input-status: up&lt;BR /&gt; input-line-status: up&lt;BR /&gt; output-interface: outside&lt;BR /&gt; output-status: up&lt;BR /&gt; output-line-status: up&lt;BR /&gt; Action: allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Apr 2018 10:16:08 GMT</pubDate>
    <dc:creator>Bouki</dc:creator>
    <dc:date>2018-04-12T10:16:08Z</dc:date>
    <item>
      <title>Identity NAT on ASA running Version 9.0(1)</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3363079#M962978</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot have access without Identity NAT configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Object: LAN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network&amp;nbsp;LAN&lt;BR /&gt;&amp;nbsp;subnet 10.100.52.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT:&lt;/P&gt;
&lt;P&gt;object network&amp;nbsp;LAN&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.100.52.0 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to emphasise that there is not PAT configured and this is the only&amp;nbsp;NAT statement configured on the box&amp;nbsp;, without it I cannot access the Internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why do I need the Identity NAT if there is no other statement shadowing it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3363079#M962978</guid>
      <dc:creator>Bouki</dc:creator>
      <dc:date>2020-02-21T15:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT on ASA running Version 9.0(1)</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3363604#M962979</link>
      <description>&lt;P&gt;That shouldn't be the case. Can you run a packet-tracer without the nat rule in place and share the ouput? Something like:&lt;/P&gt;
&lt;P&gt;packet-tracer input inside tcp &amp;lt;client-ip&amp;gt; 12345 4.2.2.2 80 detailed&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2018 17:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3363604#M962979</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-04-10T17:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT on ASA running Version 9.0(1)</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3364814#M962980</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I apprecitae the quick reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt; Type: ACCESS-LIST&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Implicit Rule&lt;BR /&gt; Additional Information:&lt;BR /&gt; MAC Access list&lt;BR /&gt; &lt;BR /&gt; Phase: 2&lt;BR /&gt; Type: ROUTE-LOOKUP&lt;BR /&gt; Subtype: input&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;BR /&gt; &lt;BR /&gt; Phase: 3&lt;BR /&gt; Type: ACCESS-LIST&lt;BR /&gt; Subtype: log&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; access-group inside_access_in in interface inside&lt;BR /&gt; access-list inside_access_in extended permit ip any any log disable &lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 4&lt;BR /&gt; Type: NAT&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; object network LAN&lt;BR /&gt; &amp;nbsp;nat (inside,outside) static 10.100.52.0 no-proxy-arp route-lookup&lt;BR /&gt; Additional Information:&lt;BR /&gt; Static translate 10.100.52.23/25685 to 10.100.52.23/25685&lt;BR /&gt; &lt;BR /&gt; Phase: 5&lt;BR /&gt; Type: NAT&lt;BR /&gt; Subtype: per-session&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 6&lt;BR /&gt; Type: IP-OPTIONS&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 7&lt;BR /&gt; Type: INSPECT&lt;BR /&gt; Subtype: inspect-ftp&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; class-map class-default&lt;BR /&gt; &amp;nbsp;match any&lt;BR /&gt; policy-map global_policy&lt;BR /&gt; &amp;nbsp;class class-default&lt;BR /&gt; &amp;nbsp; inspect ftp &lt;BR /&gt; service-policy global_policy global&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 8&lt;BR /&gt; Type: FOVER&lt;BR /&gt; Subtype: standby-update&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 9&lt;BR /&gt; Type: &lt;BR /&gt; Subtype:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 10&lt;BR /&gt; Type: USER-STATISTICS&lt;BR /&gt; Subtype: user-statistics&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 11&lt;BR /&gt; Type: NAT&lt;BR /&gt; Subtype: per-session&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 12&lt;BR /&gt; Type: IP-OPTIONS&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 13&lt;BR /&gt; Type: USER-STATISTICS&lt;BR /&gt; Subtype: user-statistics&lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; &lt;BR /&gt; Phase: 14&lt;BR /&gt; Type: FLOW-CREATION&lt;BR /&gt; Subtype: &lt;BR /&gt; Result: ALLOW&lt;BR /&gt; Config:&lt;BR /&gt; Additional Information:&lt;BR /&gt; New flow created with id 960453070, packet dispatched to next module&lt;BR /&gt; &lt;BR /&gt; Result:&lt;BR /&gt; input-interface: inside&lt;BR /&gt; input-status: up&lt;BR /&gt; input-line-status: up&lt;BR /&gt; output-interface: outside&lt;BR /&gt; output-status: up&lt;BR /&gt; output-line-status: up&lt;BR /&gt; Action: allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 10:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3364814#M962980</guid>
      <dc:creator>Bouki</dc:creator>
      <dc:date>2018-04-12T10:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity NAT on ASA running Version 9.0(1)</title>
      <link>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3365038#M962981</link>
      <description>&lt;P&gt;Run one without the NAT in place.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, you mentioned that internet does not work without the identity NAT in place, correct? Is there another NAT device sitting ahead of this Firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 15:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-nat-on-asa-running-version-9-0-1/m-p/3365038#M962981</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-04-12T15:38:25Z</dc:date>
    </item>
  </channel>
</rss>

