<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/820257#M969827</link>
    <description>&lt;P&gt;Hi ALL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly assist with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use a PIX 506E with 6.3 and 1 public IP Address. We want all machines (6)on inside network to connect to Internet while Internet user can connect&lt;/P&gt;&lt;P&gt;to 2 services running on 2 machines inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside Machine: a) web server on 192.168.170.190 and ftp server on&lt;/P&gt;&lt;P&gt;192.168.170.186&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX inside interface IP = 192.168.170.185&lt;/P&gt;&lt;P&gt;PIX outside interface IP = 80.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list goutbound permit ip 192.168.170.184 255.255.255.248 any access-list ginside permit tcp any host 80.1.1.1 eq www&lt;/P&gt;&lt;P&gt;access-list ginside permit tcp any host 80.1.1.1 eq ftp&lt;/P&gt;&lt;P&gt;access-group goutbound in interface inside access-group ginside in interface outside&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www 192.168.170.190 www netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface ftp 192.168.170.186 www netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While we can connect to the Internet from any machine on our inside network, the static does not seem to work as we can not connect to our ftp or www&lt;/P&gt;&lt;P&gt;machines from the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my access-list and acces-group ok?&lt;/P&gt;&lt;P&gt;Can I use static(outside,inside) instead of static (inside,outside) above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ismail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:08:29 GMT</pubDate>
    <dc:creator>itadebayo</dc:creator>
    <dc:date>2019-03-11T11:08:29Z</dc:date>
    <item>
      <title>NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/820257#M969827</link>
      <description>&lt;P&gt;Hi ALL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly assist with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use a PIX 506E with 6.3 and 1 public IP Address. We want all machines (6)on inside network to connect to Internet while Internet user can connect&lt;/P&gt;&lt;P&gt;to 2 services running on 2 machines inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside Machine: a) web server on 192.168.170.190 and ftp server on&lt;/P&gt;&lt;P&gt;192.168.170.186&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX inside interface IP = 192.168.170.185&lt;/P&gt;&lt;P&gt;PIX outside interface IP = 80.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list goutbound permit ip 192.168.170.184 255.255.255.248 any access-list ginside permit tcp any host 80.1.1.1 eq www&lt;/P&gt;&lt;P&gt;access-list ginside permit tcp any host 80.1.1.1 eq ftp&lt;/P&gt;&lt;P&gt;access-group goutbound in interface inside access-group ginside in interface outside&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www 192.168.170.190 www netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface ftp 192.168.170.186 www netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While we can connect to the Internet from any machine on our inside network, the static does not seem to work as we can not connect to our ftp or www&lt;/P&gt;&lt;P&gt;machines from the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my access-list and acces-group ok?&lt;/P&gt;&lt;P&gt;Can I use static(outside,inside) instead of static (inside,outside) above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ismail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/820257#M969827</guid>
      <dc:creator>itadebayo</dc:creator>
      <dc:date>2019-03-11T11:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/820258#M969828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need only this&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any any eq ftp&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any any eq www&lt;/P&gt;&lt;P&gt;access-group OUTSIDE-IN in interface outside &lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www 192.168.170.190 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface ftp 192.168.170.186 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Sep 2007 12:18:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/820258#M969828</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2007-09-09T12:18:37Z</dc:date>
    </item>
  </channel>
</rss>

