<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Operations question urgent in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-operations-question-urgent/m-p/3327200#M988394</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to be sure, I want to confirm something.&lt;/P&gt;
&lt;P&gt;You have 2 interfaces inside and inside_2.&lt;/P&gt;
&lt;P&gt;Behind inside you have a host natted on asa for inbound connection, let's say ip 10.100.100.1.&lt;/P&gt;
&lt;P&gt;What you're achieving is moving that server behind interface inside_2 keeping same IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How you're advertising your network? I mean, on ASA, BGP will learn the full subnet from inside and during your migration, this subnet is gonna be learned behind inside_2?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, you can convert all your nat (inside,outside) into nat (any,outside). When your migration is finished, then put all nat back with the right interface nat (inside_2,outside). In that way, nat will be enable for all interfaces and the decision will be made with route-lookup step.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've done that multiple times for customer migration and didn't get any issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2018 02:15:26 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2018-02-08T02:15:26Z</dc:date>
    <item>
      <title>NAT Operations question urgent</title>
      <link>https://community.cisco.com/t5/network-security/nat-operations-question-urgent/m-p/3327054#M988393</link>
      <description>&lt;P&gt;we are doing an migration so added another inside_2 interface, BGP is running between ASA and routers on both sides.&lt;/P&gt;
&lt;P&gt;now there are around 50 Static NAT Twice entry in place with #nat (inside,ouside)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now in migration activity we need to point same nat entry to inside_2 like #nat (inside_2,outside).&lt;/P&gt;
&lt;P&gt;I understand that when I will create same NAT rules again with inside_2 interface then they will be placed down in order and will not match because with inside-outside they will match first.&lt;/P&gt;
&lt;P&gt;now what we want is that during that activity when BGP points the exit&amp;nbsp;path to inside_2 then NAT should use inside_2 and when BGP points inside as exit then it should use inside. but both interfaces will be up at same time with same security level.&lt;/P&gt;
&lt;P&gt;how can I achieve this ? only have CLI access and IP's will remain same.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-operations-question-urgent/m-p/3327054#M988393</guid>
      <dc:creator>amanverma</dc:creator>
      <dc:date>2020-02-21T15:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Operations question urgent</title>
      <link>https://community.cisco.com/t5/network-security/nat-operations-question-urgent/m-p/3327200#M988394</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to be sure, I want to confirm something.&lt;/P&gt;
&lt;P&gt;You have 2 interfaces inside and inside_2.&lt;/P&gt;
&lt;P&gt;Behind inside you have a host natted on asa for inbound connection, let's say ip 10.100.100.1.&lt;/P&gt;
&lt;P&gt;What you're achieving is moving that server behind interface inside_2 keeping same IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How you're advertising your network? I mean, on ASA, BGP will learn the full subnet from inside and during your migration, this subnet is gonna be learned behind inside_2?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, you can convert all your nat (inside,outside) into nat (any,outside). When your migration is finished, then put all nat back with the right interface nat (inside_2,outside). In that way, nat will be enable for all interfaces and the decision will be made with route-lookup step.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've done that multiple times for customer migration and didn't get any issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 02:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-operations-question-urgent/m-p/3327200#M988394</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-02-08T02:15:26Z</dc:date>
    </item>
  </channel>
</rss>

