NAT subnet in the network object group

Can someone help me please? I'm rusty with VPN and Natting.

Scenario: I need to share my internal-tunnel network. Traffic to 192.168.88.0/24 192.168.0.0/24 NAT when establishing a VPN connection for the objects that I defined in one group of objects specific network (Group1Servers). Internet traffic does not get this NAT 88, even by default.

ASA5506-X, 7.5 ASDM, ASA 9.5

Hello

You can configure a static strategy of nat to translate 192.168.0.0/24 to 192.168.88.0/24 when the destination is Group1Servers, the CLI command:

Create objects for 192.168.0.0/24 and 192.168.88.0/24

network object obj - 192.168.0.0
192.168.0.0 subnet 255.255.255.0

network object obj - 192.168.88.0
192.168.88.0 subnet 255.255.255.0

Statement by NAT:

NAT obj destination - source (indoor, outdoor) 192.168.88.0 obj - 192.168.0.0 static static Group1Servers Group1Servers

You can view this documentation to setup NAT:

https://supportforums.Cisco.com/document/33921/ASA-pre-83-83-NAT-CONFIGU...

Given that this traffic goes through a tunnel of site to site do not forget interesting traffic must be configured with the translated '192.168.88.0/24' not the real network, which is a common error just keep in mind

Best regards, please rate.

Tags: Cisco Security

Similar Questions

  • Trying to file share two computers that are running Windows XP, but every time I go into the network working group, that it says access denied.

    original title: HELP!

    Trying to file share two computers runing xp but whenever I go to enter the network working group, that it says access denied

    http://helpdeskgeek.com/Networking/connect-two-computers/

  • Sharing folder on the network working group

    I have 3 computers (both windows vista and windows 7). I created a group on a private network and all computers have access to the public folder, but I want to share a specific folder on both windows vista computers. How do I do that?  I can't find a way of only limited access to two computer users.

    The public sharing, file sharing, network printer discovery and sharing is enabled.
    The password and the sharing of multimedia files is DISABLED.

    Hello

    I suggest you to visit these links and check if it helps:

    http://Windows.Microsoft.com/en-us/Windows-Vista/file-sharing-essentials

    http://Windows.Microsoft.com/en-us/Windows-Vista/share-files-and-folders-over-the-network-from-Windows-Vista-inside-out

    It will be useful.

  • Level of access for a user on the network device group

    Hello

    1 al ' ACS is possible to give Readwrite access to a user when it connects to a network and readonly device group when it connects to another group of network devices.

    Thanks in advance

    Hello

    You need to set up the command authorization set on a per network device group basis

    Assign permission to control Shell Set on a per network basis-Associates ammunition special device group command authorization sets to be effective on particular NDG.

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/GrpMgt.html#wp480029

    Kind regards

    ~ JG

  • Access to a virtual computer within a NAT configuration on the network

    Is it supported or not supported methods to access a virtual machine which is within an instance of fusion on the network?

    For example, say that my VM is 192.168.168.34

    I can understand which port is used for NAT translation somehow (i.e.i 4598) and then launch access to this virtual machine across the network using 192.168.168.34:4598?

    Otherwise, any other ideas on how to make this work?

    Hello

    You can redirect the single ports between the host and the VM.

    So if you want access to the X application on your virtual machine, you need to know on which port that the application is listening and forward this port from your host to your virtual machine.

    There was formerly a nat.conf file, located in Library/Preferences/VMware Fusion/vmnet8/in older versions of Fusion, where you can set up port forwarding. Don't know if it's always the right path, as I have no mac here.

    Tim

  • Change the subnet on the network profile

    Hello

    Like a fool I created 3 network profiles and paths using 16 subnets when they should have been 24. I wonder now to open firewall rules to route to other VLANs in 24 of the subnets. As its 16 and the two first parts are identical i.e. 10.2.X.X they don't route through the firewall

    The current VMS I can just go to manually change the subnet assigned to the NIC and they work.

    When I look at a network profile to change the subnet - it is greyed out

    Is there a way I can change this manually? so that the new virtual machines created with / 24 subnet and exisiting VMs I can manually change

    Or is the only way to delete the network profile and start over. How this affect the VMs running other than bulk can try and assign an IP address already in use?

    Thank you!

    You can try to update the database

    Find the name of the profile

    SELECT * from StaticIPv4NetworkProfile

    the name of the profile update

    Update dbo. StaticIPv4NetworkProfile

    Set SubnetMaskIPv4 = "255.255.255.0" where StaticIPv4NetworkProfileName = 'YOUR NETWORK PROFILE'

    Open the database in SSMS (SQL Server Management Studio) and run the SQL query when it is connected to your database of vRA. He has not supported but will most likely solve your problem.

    Or if you are not happy to do this directly through the database, you might try using the vRO vRA plugin and call the vCACEntityManager and update the StaticIPv4NetworkProfiles entity. My guess is the update of the database direct would be easier, but please take a backup and only update the field and nothing else.

  • Automate the network port group selection in vsphere replication

    Hi, when you use the vsphere replication tool to recover servers in the data center of DR, the tool does not gives option to select network settings. I have to manually add the port groups and turn on the system remotely vcenter. Is it possible to automate this process, when the replication of a major part of the vms ~ 100-150. I would like to know if there is another way to fix the process and avoid the manual load.

    I use replication of vsphere device version 5.8

    Thank you

    The only way to automate this process is through the Site Recovery Manager.  Automate and orchestrate BC/DR is a big part of the value offered by SRM. The other advantage is the ability to test your recovery plans without disruption of service.

    Does that answer your question?

  • Configure NAT for object-group 8.3

    I'm working on a project to simplify our routing by NAT'ing the IP address of our clients VPN S2S.  Currently, the we have a bunch of roads pointing to different destinations that are created by the VPN S2S.  I wish that NAT all these destinations in a single subnet IP address, but a question about the configuration.

    As you can see, we are not currently NAT'ing anything:

    ***************************************************************************************************************************************************************

    NAT (inside, outside) static source OUR_HOSTS OUR_HOSTS THEIR_HOSTS THEIR_HOSTS non-proxy-arp-search of route static destination

    the OUR_HOSTS object-group network

    network-object VIP1

    network-object VIP2

    the VIP1 object network

    Home 10.200.125.32

    the VIP2 object network

    Home 10.200.120.32

    the THEIR_HOSTS object-group network

    host of the object-Network 192.168.15.100

    host of the object-Network 192.168.15.130

    host of the object-Network 192.168.15.15

    ********************************************************************************************************************************************************************

    What I would do is NAT THEIR_HOSTS to a 10.200.192.x/24 address.  I have NAT can do those at one address and Surchargez the NAT or must it be an address for each of these 3 hosts?  I'm very well be it.  According to which would be easier to do, please point me in the right direction.

    Thank you!

    Hello

    Else seems fine, but the ' object-group ' after the 'static destination' are the wrong way.

    First of all must be the ' object-group ' that contains the NAT IP address and the second the ' object-group ' holding real / IP address of the destination host.

    -Jouni

  • Cisco ASA 8.4 (3) remote access VPN - client connects but cannot access inside the network

    I have problems to access the resources within the network when connecting with the Cisco VPN client for a version of 8.4 (3) operation of the IOS Cisco ASA 5510. I tried all new NAT 8.4 orders but cannot access the network interior. I can see traffic in newspapers when ping. I can only assume I have NAT evil or it's because the inside interface of the ASA is on the 24th of the same subnet as the network interior? Please see config below, any suggestion would be appreciated. I configured a VPN site to another in this same 5510 and it works well

    Thank you

    interface Ethernet0/0

    Speed 100

    full duplex

    nameif outside

    security-level 0

    IP x.x.x.x 255.255.255.240

    !

    interface Ethernet0/1

    Speed 100

    full duplex

    nameif inside

    security-level 100

    IP 10.88.10.254 255.255.255.0

    !

    interface Management0/0

    Shutdown

    nameif management

    security-level 0

    no ip address

    !

    permit same-security-traffic inter-interface

    permit same-security-traffic intra-interface

    network of the PAT_to_Outside_ClassA object

    10.88.0.0 subnet 255.255.0.0

    network of the PAT_to_Outside_ClassB object

    subnet 172.16.0.0 255.240.0.0

    network of the PAT_to_Outside_ClassC object

    Subnet 192.168.0.0 255.255.240.0

    network of the LocalNetwork object

    10.88.0.0 subnet 255.255.0.0

    network of the RemoteNetwork1 object

    Subnet 192.168.0.0 255.255.0.0

    network of the RemoteNetwork2 object

    172.16.10.0 subnet 255.255.255.0

    network of the RemoteNetwork3 object

    10.86.0.0 subnet 255.255.0.0

    network of the RemoteNetwork4 object

    10.250.1.0 subnet 255.255.255.0

    network of the NatExempt object

    10.88.10.0 subnet 255.255.255.0

    the Site_to_SiteVPN1 object-group network

    object-network 192.168.4.0 255.255.254.0

    object-network 172.16.10.0 255.255.255.0

    object-network 10.0.0.0 255.0.0.0

    outside_access_in deny ip extended access list a whole

    inside_access_in of access allowed any ip an extended list

    11 extended access-list allow ip 10.250.1.0 255.255.255.0 any

    outside_1_cryptomap to access extended list ip 10.88.0.0 255.255.0.0 allow object-group Site_to_SiteVPN1

    mask 10.250.1.1 - 10.250.1.254 255.255.255.0 IP local pool Admin_Pool

    NAT static NatExempt NatExempt of the source (indoor, outdoor)

    NAT (inside, outside) static source any any static destination RemoteNetwork4 RemoteNetwork4-route search

    NAT static LocalNetwork LocalNetwork destination (indoor, outdoor) static source RemoteNetwork1 RemoteNetwork1

    NAT static LocalNetwork LocalNetwork destination (indoor, outdoor) static source RemoteNetwork2 RemoteNetwork2

    NAT static LocalNetwork LocalNetwork destination (indoor, outdoor) static source RemoteNetwork3 RemoteNetwork3

    NAT (inside, outside) static source LocalNetwork LocalNetwork static destination RemoteNetwork4 RemoteNetwork4-route search

    !

    network of the PAT_to_Outside_ClassA object

    NAT dynamic interface (indoor, outdoor)

    network of the PAT_to_Outside_ClassB object

    NAT dynamic interface (indoor, outdoor)

    network of the PAT_to_Outside_ClassC object

    NAT dynamic interface (indoor, outdoor)

    Access-group outside_access_in in interface outside

    inside_access_in access to the interface inside group

    Route outside 0.0.0.0 0.0.0.0 x.x.x.x 1

    dynamic-access-policy-registration DfltAccessPolicy

    Sysopt connection timewait

    Service resetoutside

    Crypto ipsec transform-set ikev1 ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-192-SHA esp-aes-192 esp-sha-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-128-MD5-esp - aes esp-md5-hmac

    Crypto ipsec transform-set esp-ikev1 esp-md5-hmac bh-series

    Crypto ipsec transform-set ikev1 esp ESP-DES-MD5-esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-3DES-MD5-esp-3des esp-md5-hmac

    Crypto ipsec transform-set ikev1 ESP-DES-SHA esp - esp-sha-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-128-SHA aes - esp esp-sha-hmac

    Crypto ipsec transform-set ikev1 ESP-AES-256-SHA esp-aes-256 esp-sha-hmac

    Crypto ipsec transform-set ikev1 SHA-ESP-3DES esp-3des esp-sha-hmac

    Crypto-map dynamic dynmap 10 set pfs

    Crypto-map dynamic dynmap 10 set transform-set bh - set ikev1

    life together - the association of security crypto dynamic-map dynmap 10 28800 seconds

    Crypto-map dynamic dynmap 10 kilobytes of life together - the association of safety 4608000

    Crypto-map dynamic dynmap 10 the value reverse-road

    card crypto mymap 1 match address outside_1_cryptomap

    card crypto mymap 1 set counterpart x.x.x.x

    card crypto mymap 1 set transform-set ESP-AES-256-SHA ikev1

    card crypto mymap 86400 seconds, 1 lifetime of security association set

    map mymap 1 set security-association life crypto kilobytes 4608000

    map mymap 100-isakmp ipsec crypto dynamic dynmap

    mymap outside crypto map interface

    crypto isakmp identity address

    Crypto isakmp nat-traversal 30

    Crypto ikev1 allow outside

    IKEv1 crypto ipsec-over-tcp port 10000

    IKEv1 crypto policy 5

    preshared authentication

    3des encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 10

    preshared authentication

    3des encryption

    sha hash

    Group 1

    life 86400

    IKEv1 crypto policy 50

    preshared authentication

    the Encryption

    md5 hash

    Group 2

    life 86400

    IKEv1 crypto policy 60

    preshared authentication

    aes-256 encryption

    sha hash

    Group 2

    life 86400

    IKEv1 crypto policy 70

    preshared authentication

    aes-256 encryption

    sha hash

    Group 1

    life 86400

    IKEv1 crypto policy 90

    preshared authentication

    aes encryption

    sha hash

    Group 2

    life 86400

    Telnet timeout 5

    Console timeout 0

    management-access inside

    a basic threat threat detection

    Statistics-list of access threat detection

    no statistical threat detection tcp-interception

    WebVPN

    internal BACKDOORVPN group policy

    BACKDOORVPN group policy attributes

    value of VPN-filter 11

    Ikev1 VPN-tunnel-Protocol

    Split-tunnel-policy tunnelall

    BH.UK value by default-field

    type tunnel-group BACKDOORVPN remote access

    attributes global-tunnel-group BACKDOORVPN

    address pool Admin_Pool

    Group Policy - by default-BACKDOORVPN

    IPSec-attributes tunnel-group BACKDOORVPN

    IKEv1 pre-shared-key *.

    tunnel-group x.x.x.x type ipsec-l2l

    tunnel-group ipsec-attributes x.x.x.x

    IKEv1 pre-shared-key *.

    !

    class-map inspection_default

    match default-inspection-traffic

    !

    !

    type of policy-card inspect dns preset_dns_map

    parameters

    maximum message length automatic of customer

    message-length maximum 512

    Policy-map global_policy

    class inspection_default

    inspect the preset_dns_map dns

    inspect the ftp

    inspect h323 h225

    inspect the h323 ras

    inspect the rsh

    inspect the rtsp

    inspect esmtp

    inspect sqlnet

    inspect the skinny

    inspect sunrpc

    inspect xdmcp

    inspect the sip

    inspect the netbios

    inspect the tftp

    Review the ip options

    !

    global service-policy global_policy

    Excellent.

    Evaluate the useful ticket.

    Thank you

    Rizwan James

  • No visible computers in the network

    I use a desktop computer on (in English) windows XP Edition family and two laptop computers on Windows Vista. All are connected in a home network (with the same name of working group). Now I can 'see' my office in the network from my laptop, but I can't 'see' laptops in my office (or in the network as in the windows Explorer environment)

    Make sure that the name of the network working group is the same for all computers/workstations. Activate the network at least _off_ passwords while you get it all set up and works. Then configure passwords or create an account with the same user/pass on all computers/workstations in the network.

    I found these. http://support.Microsoft.com/kb/903267

    http://Windows.Microsoft.com/en-us/Windows-Vista/troubleshoot-file-and-printer-sharing

  • Please advice on the Configuration of the network and possibilities.

    Hello

    I have a small office at home (me, my wife and 2 employees) and I need to improve my network. It's simply not up to the task.

    Which must be supported:

    • 5 PC desktop
    • 2 notebooks private
    • 2 network printers
    • XBOX
    • NAS
    • Many mobile devices
    • ADSL internet connection
    • Connection internet optical fiber (glass)
    • System network audio (Sonos)

    Right now I use a combination of routers/switches of different brands, and I want to spend it again all devices, all from a brand. That's what I want to do:

    • A wired router to handle the traffic internet ADSL and fiber
    • Several access points wireless (1 device with multiple SSID) or multiple devices: a client, a desk, one for home, one for...
    • Home network of offices on a separate subnet from the network
    • Router must be able to act as an OpenVPN client and tunnel specific IP addresses / ports LAN from the intranet to the VPN service provider (it of to hide my IP address, mainly for private use, not for torrenting, right to privacy)
    • Currently, there is no need to be able to Dáil from outside the office, this could change in the future

    I was thinking to buy the following:

    • LRT224
    • 2 * LAPAC1750 (since the home + office is large enough)

    I reuse a switch 8 ports business grade, no need to replace it.

    My setup is as follows:

    ADSL Modem (bridge mode)-\ /-LAPAC1750 for office and clients (2 SSID)

    > - LRT224 -

    Fiber connection-/ |       \--LAPAC1750 for House- + - OpenVPN connection

    |                                |

    Switch 8 ports (company) + - direct connection

    After reading the manual for both devices, I think that the wireless access points are more then adequate for the task. However, I have my doubts about the LRT224. Yes, it has dual WAN, so perfect for the routing of traffic ADSL or fiber. But the OpenVPN part is not what I need. I need something that is offered by the tomato/DD-WRT flashes for all-in-one routers: OpenVPN client build-in and able to route specific traffic through the VPN tunnel.

    My question is: is this, I want to install, possible with devices metntioned, including a tunnel (via AirVPN) OpenVPN implementation to route the traffic/specific devices through, and multiple wireless access points.

    I hope some of you can help me here. I won't buy an all-in-one wireless router, since a problem with these devices lies between offten, and I like the look and feel of Linksys devices.

    Thanks in advance.

    With sincere friendships.

    Sjoerd

    Edit: fixed formatting and some typo

    LRT routers don't tunnel VPN vendors like the Open Source router firmwares.

  • My Windows 7 PC cannot see themselves on the network.

    My Windows 7 PC cannot see themselves on the network. Under the heading network in Windows Explorer when I try to extend the C drive, I get an error message saying that Windows cannot access it. Also, I can't access this PC from a PC in 10 Windows on the same network - this error message indicates that Windows cannot communicate with the device or resource. It is available, but it is unresponsive to attempts to connect.

    I have tried turning the firewall off temporarily, but this makes no difference.

    Can access my PC Windows 7 Windows 10 PC and a laptop Windows 7 without any problem.

    Integrated network diagnostics do not come to the top with something useful.

    OT:

    Windows 7 networking

    Hello

    Thanks for posting your query in Microsoft Community.

    • Your computer is connected to the domain?

    There could be several reasons for this cause and to diagnose the problem, we can try the following steps and check.

    Step 1: Check if the network discovery is turned on.

    Please refer to: enable or disable network discovery

    Step 2: Check Event Viewer for detailed information on the problem. Consult the following links.

    Open event viewer

    What are the information in event logs? (Event Viewer)

    Step 3: Search the computer browser service, if it is running.

    1. click on Start, type services.msc in the start search.

    2. search for the computer browser service.

    3. right click on the computer browser service and select Properties. Check if it is started.

    4. If it is stopped, select Start or restart. Make sure that the service is started and set as Automatic.

    5. click apply and OK, if you make any changes.

    Step 4: Temporarily try to disable the antivirus on the computer program and check if the problem persists. If you are able to connect, you may need to check for updates and firewall settings in the security software.

    Note: Check that you activate your anti-virus protection on the computer back after you complete these steps. It is not recommended to disable these settings on the computer. It's just to solve the problem.

    Disable the anti-virus software

    Step 5: Make sure that the name of the network working group is the same for all computers. Also try disabling some protected sharing and check for the issue.

    1. Open advanced sharing settings by clicking theStart button, thenControl Panel. In the search box, type network, click network and sharing Center, and then in the left pane, click change advanced sharing settings.

    2 click to expand the current network profile.

    3. by password protected sharing, click turn off password protected sharing, and then click save changes.  If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.

    Also, try to perform a SFC scan to see if it solves the problem. Read the following article.

    Use the System File Checker tool to repair missing or corrupted system files

    Also refer to:

    Networking of computers running different versions of Windows

    Why can't I connect to other computers?

    Hope this information is useful. Please feel free to answer in the case where you are facing in the future other problems with Windows.

  • NAT 0 using the object in OS 8.6 NAT network

    Hello

    I am trying to create a remote access IPSEC vpn and work for the first time with network NAT object on an architecture of 5512 X with OS 8.6. I would like to know how to create a SHEEP script with users on the other side, using an entry of 0 nat NAT so that traffic destined for subnets to the other end of the VPN are not NATTED?

    Thank you

    Vick.

    Here you go:

    For example:

    LAN: 192.168.5.0/24

    Remote LAN: 192.168.88.0/24

    object of local-LAN

    192.168.5.0 subnet 255.255.255.0

    object distance-LAN network

    192.168.88.0 subnet 255.255.255.0

    NAT (inside, outside) static source local-LAN LAN local static destination remote control remote-LAN-LAN

    Hope that helps.

  • object-group network

    Hi all

    recentry I had some problems with my router 892 and maybe I can find the answer here.

    I have two groups of network object:

    object-group network net1

    192.168.1.0 255.255.255.0

    the object-group net2 network

    192.168.2.0 255.255.255.0

    Two ACLs:

    acl-net12 extended IP access list

    permit ip object-group net1 net2 object-group

    acl-net12-new extended IP access list

    ip permit 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255

    A single card encryption:

    card crypto ipsec vpn 1 isakmp

    Network2 description

    defined peer xx.xx.xx.xx

    Set security-association second life 28800

    the value of the transform-set 3des-sha

    match address acl-net12

    When the address for correspondence is set to acl-net12, I can't ping my router on the external interface and tunnel works very badly (15-20% packet loss).

    If I change my address for correspondence of the acl-net12 to acl-net12 - new then I can ping my router on external if interface and vpn works well.

    I also have an acl (located on the external interface) allowing the ping, but it seems that this does not work when the acl-net12 is used on a card encryption

    outside_acl extended IP access list

    Note leave ping

    permit any any icmp echo

    permit any any icmp echo response

    What I am doing wrong?

    Maybe someone can help me.

    Thank you.

    On my final tests with groups of crypto-acl objects, is that the content has been changed to "permit ip any any" which is usually not a desired configuration. I guess it's a bug or a feature that is not yet implemented.

    Until that which is fixed, you must configure VPN without groups of objects. BTW: IOS-version are you running? I don't a not test it with the new versions-15, 2.

    --
    Don't stop once you have upgraded your network! Improve the world by lending money to low-income workers:
    http://www.Kiva.org/invitedBy/karsteni

  • Script to get the VLan ID, vSwitch, networking and group of vCenter vmkernel ports.

    Hello

    Need help to get the script of ' Script for the VLan ID, vSwitch, networking and group ports vmkernel of vCenter. "to CSV

    Any help will be much appreciated.

    Get-VMHost | {foreach}

    $vmhost = $_

    $PortGroups = $vmhost | Get-VirtualPortGroup

    $vSwitchs = $vmhost | Get-VirtualSwitch

    $pNic = $vmhost | Get-VMHostNetworkAdapter

    $Managementinfo = $pNic | Where-Object {$_.} ManagementTrafficEnabled - eq $true}

    $vMotioninfo = $pNic | Where-Object {$_.} VMotionEnabled - eq $true}

    $FTinfo = $pNic | Where-Object {$_.} FaultToleranceLoggingEnabled - eq $true}

    $vlanID = $PortGroup | Where-Object {$_.name - eq $Managementinfo.ExtensionData.spec.Portgroup} | Select-object - ExpandProperty VLanId

    {foreach ($PG in $PortGroups)

    #Management Info network

    If ($Managementinfo.PortGroupName - eq $PG.) {Name)

    $MGMTStatus = "enabled".

    $ManagementIP = $Managementinfo | Where-Object {$_.} PortGroupName - eq $PG. Name} | Select-Object - ExpandProperty IP

    }

    else {}

    $MGMTStatus = "Disabled".

    $ManagementIP = $null

    }

    #vMotion Info network

    If ($vMotioninfo.PortGroupName - eq $PG.) {Name)

    $vmotionStatus = "enabled".

    $vMotionIP = $vMotioninfo | Where-Object {$_.} PortGroupName - eq $PG. Name} | Select-Object - ExpandProperty IP

    }

    else {}

    $vmotionStatus = "Disabled".

    $vMotionIP = $null

    }

    #FT Info network

    If ($FaultToleranceLoggingEnabled.PortGroupName - eq $PG.) {Name)

    $FTStatus = "enabled".

    $ftIP = $FTinfo | Where-Object {$_.} PortGroupName - eq $PG. Name} | Select-Object - ExpandProperty IP

    }

    else {}

    $FTStatus = "Disabled".

    $ftIP = $null

    }

    #vmKernel name

    $VMKernel = $pNic | Where-Object {$_.} PortGroupName - eq $PG. Name} | Select-Object - ExpandProperty DeviceName

    $result = "" | Select-Object HostName, vSwitchName, PortGroupName, VLanID, ManagementTraffic, ManagementIP, vMotionTraffic, vMotionIP, FTTraffic, FTIP, VMKernel

    $result. Host name = $vmhost.name

    $result.vSwitchName = $PG. VirtualSwitchName

    $result. PortGroupName = $PG. Name

    $result. VLanID = $PG. VLanID

    $result. VLanID = $PG. VLanID

    $result. ManagementTraffic = $MGMTStatus

    $result. ManagementIP = $ManagementIP

    $result.vMotionTraffic = $vmotionStatus

    $result.vMotionIP = $vMotionIP

    $result. FTTraffic = $FTStatus

    $result. FTIP = $ftIP

    $result. VMKernel = $VMKernel

    $result

    }

    } | Export-Csv c:\temp\data.csv

Maybe you are looking for