<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about NAT redirection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-about-nat-redirection/m-p/716182#M984155</link>
    <description>&lt;P&gt;I will be deploying an ASA5520 very soon and I wanted to find out if the following is possible...and if so, any advice or pointers on the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I plan to have three security zones:&lt;/P&gt;&lt;P&gt;SERVER_NETWORK 10.0.0.0/24&lt;/P&gt;&lt;P&gt;CLIENT_NETWORK 192.168.100.0/24&lt;/P&gt;&lt;P&gt;PUBLIC_NETWORK 200.200.200.0/24 (obfuscated intentionally)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will have a server exposed (or NAT'd) from the SERVER_NETWORK to the PUBLIC_NETWORK. Lets say for simplicity, its a web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SERVER01 (ip: 10.0.0.10) (External NAT: 200.200.200.10)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Externally, if you resolve "&lt;A href="http://www.mycompanywebsite.com" target="_blank"&gt;www.mycompanywebsite.com&lt;/A&gt;",  DNS will return 200.200.200.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to configure the ASA5520 such that, if a user on the CLIENT_NETWORK resolved that address (200.200.200.10) or browsed to that resouce, they would be able to reach SERVER01 too?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, can I have NAT translations occur on both interfaces, public and client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried this in the past with a PIX and was told that it couldn't be done.  Something about not being able to send traffic out, or looping back in, through an interface that is NAT'ing an address. (that was a long time ago, though)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've resolved it in the past by running a secondary DNS server for the clients in the CLIENT_NETWORK, that responds with internal addresses instead of the external ones.  That is obviously a less than desireable solution because you have to maintain duplicate zone files with different host records. But that isn't an option with this install. I can't do that here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice?  Is this easily overcome now?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:46:20 GMT</pubDate>
    <dc:creator>mattg</dc:creator>
    <dc:date>2019-03-11T10:46:20Z</dc:date>
    <item>
      <title>Question about NAT redirection</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-redirection/m-p/716182#M984155</link>
      <description>&lt;P&gt;I will be deploying an ASA5520 very soon and I wanted to find out if the following is possible...and if so, any advice or pointers on the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I plan to have three security zones:&lt;/P&gt;&lt;P&gt;SERVER_NETWORK 10.0.0.0/24&lt;/P&gt;&lt;P&gt;CLIENT_NETWORK 192.168.100.0/24&lt;/P&gt;&lt;P&gt;PUBLIC_NETWORK 200.200.200.0/24 (obfuscated intentionally)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will have a server exposed (or NAT'd) from the SERVER_NETWORK to the PUBLIC_NETWORK. Lets say for simplicity, its a web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SERVER01 (ip: 10.0.0.10) (External NAT: 200.200.200.10)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Externally, if you resolve "&lt;A href="http://www.mycompanywebsite.com" target="_blank"&gt;www.mycompanywebsite.com&lt;/A&gt;",  DNS will return 200.200.200.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to configure the ASA5520 such that, if a user on the CLIENT_NETWORK resolved that address (200.200.200.10) or browsed to that resouce, they would be able to reach SERVER01 too?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, can I have NAT translations occur on both interfaces, public and client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried this in the past with a PIX and was told that it couldn't be done.  Something about not being able to send traffic out, or looping back in, through an interface that is NAT'ing an address. (that was a long time ago, though)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've resolved it in the past by running a secondary DNS server for the clients in the CLIENT_NETWORK, that responds with internal addresses instead of the external ones.  That is obviously a less than desireable solution because you have to maintain duplicate zone files with different host records. But that isn't an option with this install. I can't do that here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice?  Is this easily overcome now?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:46:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-redirection/m-p/716182#M984155</guid>
      <dc:creator>mattg</dc:creator>
      <dc:date>2019-03-11T10:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Question about NAT redirection</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-redirection/m-p/716183#M984156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can do this, it is called DNS doctoring. Attached is a link to a configuration example of DND doctoring on the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 07:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-redirection/m-p/716183#M984156</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-19T07:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Question about NAT redirection</title>
      <link>https://community.cisco.com/t5/network-security/question-about-nat-redirection/m-p/716184#M984157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats perfect Jon.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 07:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-nat-redirection/m-p/716184#M984157</guid>
      <dc:creator>mattg</dc:creator>
      <dc:date>2007-07-19T07:46:28Z</dc:date>
    </item>
  </channel>
</rss>

