<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Exemption in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764432#M980284</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for both replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another situation but do not know how to do the translations for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have remote access VPN users getting public ip addresses in the range x.x.26.0/23 on the outside. They need to access their desktops on the inside using RDP and the desktops are on the private 10.x.x.x range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to allow remote access users on the outside to access the desktops on the inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been looking into policy NAT but need some help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 May 2007 13:43:11 GMT</pubDate>
    <dc:creator>mchockalingam</dc:creator>
    <dc:date>2007-05-23T13:43:11Z</dc:date>
    <item>
      <title>NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764429#M980277</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I jsut need some help in making sure that the following statements are correct. Here is the scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our inside private addresss 10.x.x.x always gets NATed to a public IP on the outside. Now I have a situatuion where we do not want to NAT the private IP if the destination address is x.x.226.31 on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come up with the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list no_nat_ipvc_out permit ip 10.0.0.0 255.0.0.0 host x.x.226.31&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list  no_nat_ipvc_out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will this work?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764429#M980277</guid>
      <dc:creator>mchockalingam</dc:creator>
      <dc:date>2019-03-26T00:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764430#M980279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2007 11:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764430#M980279</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-22T11:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764431#M980281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah that should do it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Hoogen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2007 12:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764431#M980281</guid>
      <dc:creator>hoogen_82</dc:creator>
      <dc:date>2007-05-22T12:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764432#M980284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for both replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another situation but do not know how to do the translations for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have remote access VPN users getting public ip addresses in the range x.x.26.0/23 on the outside. They need to access their desktops on the inside using RDP and the desktops are on the private 10.x.x.x range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to allow remote access users on the outside to access the desktops on the inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been looking into policy NAT but need some help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 13:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764432#M980284</guid>
      <dc:creator>mchockalingam</dc:creator>
      <dc:date>2007-05-23T13:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764433#M980287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is what you're asking. Just add the traffic to you existing nat exemption acl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list no_nat_ipvc_out permit ip 10.0.0.0 255.0.0.0 host x.x.226.31 &lt;/P&gt;&lt;P&gt;access-list no_nat_ipvc_out permit ip 10.0.0.0 255.0.0.0 x.x.226.0 255.255.254.0&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list no_nat_ipvc_out &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 14:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764433#M980287</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-23T14:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764434#M980289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this will only allow 10.x.x.x access the 26.0/23 with no NAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I would like to no NAT the 10.x.x.x on the inside if the traffic is coming from the outside source x.x.26.0/23. I do not have any interface in the 10.x.x.x range on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are doing the NATing on the FWSM but the perimeter firewall has the DMZ which has our VPN device. When remote users connect they get an IP on the DMZ of the perimeter firewall and the users need access to inside which is 10.x.x.x. But all our 10.x.x.x gets NATed to a public IP by the FWSM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 15:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764434#M980289</guid>
      <dc:creator>mchockalingam</dc:creator>
      <dc:date>2007-05-23T15:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764435#M980290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nat exemption acl's are bi-directional.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 15:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764435#M980290</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-23T15:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764436#M980291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a learning for me. I just want to make sure that it will work if the traffic originates from outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 17:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764436#M980291</guid>
      <dc:creator>mchockalingam</dc:creator>
      <dc:date>2007-05-23T17:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exemption</title>
      <link>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764437#M980292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How are doing Meena im &lt;A href="mailto:dillonoct@aol.com"&gt;dillonoct@aol.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 18:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exemption/m-p/764437#M980292</guid>
      <dc:creator>joe2065</dc:creator>
      <dc:date>2007-05-23T18:38:51Z</dc:date>
    </item>
  </channel>
</rss>

