Need help to understand political static with Nat No.

Hi all

I have a Pix 515e with 6 interfaces. 5 interfaces are considered as internal that we don't want any translation NAT occur between them. We want only NAT between the 5 and the external interface.

I created a No_Nat ACL successfully to not manage any portion of nat.

What I have trouble understanding is the static command to allow traffic between higher levels to lower levels and vice versa.

I understand the

public static inside_address outside_address (indoor, outdoor)

for the part of NAT translation.

What I do not understand, this is when the inside address and address outside are the same, what order are going. For example, my inner interface (192.168.1.0/24) (sec100) is where the live servers, and I have another interface named accounting (192.168.2.0/24) (sec75).

If I don't want no nat occurs between these two, I have the following

No_Nat of the 192.168.1.0/24 192.168.2.0/24 ip access list permit

No_Nat of the 192.168.1.0/24 192.168.2.0/24 ip access list permit

NAT (inside) 0-list of access No_Nat

NAT (accounting) 0-list of access No_Nat

Now how can I enter the static command?

Maybe

static (inside, accounting) 192.168.1.0 192.168.1.0 netmask 255.255.255.0

or

static (inside, accounting) 192.168.2.0 192.168.2.0 netmask 255.255.255.0

or

static (accounting, inside) 192.168.1.0 192.168.1.0 netmask 255.255.255.0

or

static (accounting, inside) 192.168.2.0 192.168.2.0 netmask 255.255.255.0

I do not understand the prescription for it and why it would be used one verses the other way. Is the security level determines the order? Do I need two static command, one for each direction?

Thank you

Denny

Hello denny

static can be defined in any way... its only traffic that determines what it... for example, if accounting dmz is access to any server on your inside interface, you normally want the accounting servers see the original on its public IP server inside... so, you will end up as static

static (inside, accounting) 192.168.1.0 192.168.1.0 netmask 255.255.255.0

only the above static command is sufficient to establish connectivity between inside and dmz accounting. u don't need 2 static on any sense...

Similarly, if you want to inside users to access a server on the dmz accounting, you can write a static type

static (accounting, inside) 192.168.2.0 192.168.2.0 netmask 255.255.255.0

hope you understand. Let us know if you need help... but normally a statement nat 0 is more than enough for the inside / dmz communication

Kind regards

REDA

Tags: Cisco Security

Similar Questions

  • need help to understand the compatibility with video cards

    I recently bought a HP Pavilion a6742p Desktop PC I have no idea what graphics cards, it supports (trying to upgrade). Check the manufacturers page, but I couldn't understand anything either here is the link

    http://h10025.www1.HP.com/ewfrf/wc/product?LC=en&DLC=en&CC=HK&lang=en&product=3875703

    insaneaim wrote:

    THX but which manufacturers video card companies take in charge of hp?

    HERE, none of them.  I recommend the following manufacturers, XFX, BFG, EVGA, Sapphire & PNY, in that order.  These recommendations are based on personal knowledge, as well as several years of hanging around in the forums of enthusiasts.

  • Need help to understand why my downloaded PDF doc displays "Please wait...". If this message is not finally replaced with the appropriate content... "after that I have already downloaded the version update for windows 10

    Need help to understand why my downloaded PDF doc displays "Please wait...". If this message is not finally replaced with the appropriate content... "after that I have already downloaded the version update for windows 10

    This is because the PDF file is not be open in Acrobat or Reader, but by the browser which is unable to handle the specific PDF content.

    If you use Firefox or Chrome, follow these steps: https://helpx.adobe.com/livecycle/kb/xfa-forms-firefox-chrome.html

  • Need help to reactivate Lightroom 5 with my old serial number and the number TAN.  I got a license for Lightroom 5 when I bought my Leica delux 4 in 2012.

    I got a license for Lightroom 5 when I bought my Leica delux 4 in 2012. It worked great, but after that I put an old hard drive on my PC (for 30 minutes - then I removed again) to get some information of this former, Lightroom now license application or try it for 30 days.

    I have not installed Lightroom on a new hard drive. He is always on the same hard disk. How can I now have my Lightroom to run again using my serial number and TAN? Need help to reactivate my old serial number and the number TAN.

    I use win 7.

    Duplicate thread: need help to reactivate Lightroom 5 with my old serial number and the number TAN.  I got a license for Lightroom 5 when I bought my Leica delux 4 in 2012.

  • Need help to solve the problem with the margin at the bottom of the converted pdf file.

    Need help to solve the problem with the margin of the converted CEO down. What caused the change in format?

    Hi jerrio1949,

    There is no way to change the margin, you settle back into your original file & then convert to PDF format.

    Kind regards
    Nicos

  • Need help to open two images with the same file with different exposures on the screen at the same time in the Photoshop creative cloud (in previous versions we could open two images of the same nef (raw) file and then combine them on the screen with the

    Need help to open two images with the same file with different exposures on the screen at the same time in the Photoshop creative cloud (in previous versions we could open two images of the same nef (raw) file and then combine them on the screen with the move tool. They have become a composite of two layers which could be developed further with the mask tool.

    Hello

    Please go to the preferences > workspace and uncheck the option 'open the document in the tabs '.

    Now you can click on file and choose file > open and open the two images in two different windows which can be arranged side by side.

    Thank you

  • Need help to understand CodeModuleListener.

    Hi all

    I need your help to understand CodeModuleListener.

    I need to implement CodeModuleListener in my application, but I am confused between docs provided with the 5.0 SDK and documentation online.

    Please look at the below link and image

    http://www.BlackBerry.com/developers/docs/5.0.0api/NET/rim/device/API/system/CodeModuleListener.html...

    If you can not see image below please find docs on link: -.

    Search in Motion\BlackBerry JDE 5.0.0\docs\api\index.html (or attempt to open attachments)

    Please answer as soon as POSSIBLE.

    Found the root of the problem.

    When I was using jde 5.0 with eclipse (by creating an ee file) problem appears, but as I install it new eclipse with the plugin 5.0, problem solved.

  • Need help as soon as POSSIBLE with RAM Preview

    Hey guys I need help with my RAM Preview and how to get it back on the default setting. I don't know what happened, but now my RAM Preview is divided on two screens. I tried literally everything to solve this problem and came to nothing. Nothing on google as well. Help, please! I need to get there soon! Here's what happens: 2016-09 - 03.png - Google Drive

    This is your equal to 2 times and not the RAM Preview Composition Panel (in fact it is seen now and not the RAM Preview... you can call him Mr. Preview if you want to get fancy). knowing how to describe your problem lies at halfway to a solution

    DON'T PANIC!

    Set it to 1 view and you'll be fine!

    These views are used for 3D to show the different perspectives and views spelling of a 3D scene. When they have no use in 2D. If you clicked on the option to display 2 views or more they will appear unless you change it back manually. even when you reset your workspace, they will appear - so I understand why this can be confusing.

    more about it here: https://helpx.adobe.com/after-effects/using/modifying-using-views.html...

  • Need help to understand the network of vSphere environment

    Hello

    I need your help in understanding the network environment in vSphere. Please see the diagram and the text below:

    vm.png

    NIC #1 - Management Port (access from client vsphere, vCenter server)

    NIC #2 - Port of VMkernal (for iSCSI, vMotion, etc.)

    NIC #3 -?

    #4 – CARTE NETWORK INTERFACE?

    Q1 how allow external users to access services over the ESX host? (for example, IIS, FTP, Exchange, NFS)

    Q2, what will be the role of the other two network cards? Is it connected to the physical switch?

    * Ask you all to please help me by sharing your knowledge / experience on the network portion, you have made in your environment as NIC how, what to do with that. *

    I really need to understand the networking of concepts in vSphere, hope that your help!


    Best regards: Yash

    With an additional NIC with 2 port a general configuration might look like this:

    vSwitch0 - vmnic0, vmnic1 (connected to different physical switches)

    Network VMkernel management

    VMotion VMkernel network (own IP network, own VLAN)

    Better if they is configured as active / standby.

    vSwitch1 - vmnic2, vmnic3 (connected to different physical switches)

    Trade VM

    vSwitch2 - vmnic4, vmnic5 (connected to different physical switches)

    VMkernel iSCSI (own IP network, own VLAN)

    Ideal if it is added to the component Multipath iSCSI, which is quite easy to vSphere 5.

  • Need help to organize Excel files with several data

    Hello everyone!

    I'm working on a project consisting of a full acquisition system. I have great finisheda part of my program and now my guardian's ask me something else.

    In you project I have several datas: Move, force, speed, time,...

    And he would like that this data in the same Excel file with a predefined order. In the example: column 1: time, column 2: speed, etc.

    I already tried to work with the block 'write on a file of measure' and associate a different signal through a simulation, and it works. The first signal is the left column. The second signal is the second column. So it's ok about this. But when I try to link a VI unlike a simulation, that the file does not work. Even if I use the data of 3 or 4, I only had a column with some strange results.

    That's why I ask your help. I would like to know if you have a good way to solve this problem I want to clarify that I am a beginner in LabVIEW.

    I join my project in order to help you understand. I hope I was clear enough

    Kind regards.

    ML

    PS: Sorry for my English, I know that I'm not very good like that!

    Thank you for your project, including - it shows me that you are using LabVIEW 2015, which means that you have the Report Generation Toolkit, with the ability to easily generate Excel "Reports", available.

    If you really want to generate Excel (.xls, .xlsx) files, the GTA is, by far, the best way to do.  If you go to the search bar in the Forums of LabVIEW and type "Example revised" - the first 'hit' should be a post of two years of mine where I show how to use the GTA to more or less do what you described.  Give it a try with some of your data, and come back if you have any other questions.

    Bob Schor

  • Need help to understand the query result

    Hi gurus

    I was reading one of the question here in this forum and its link is below:

    Query required for scenario

    I had some confusion related to this code and don't understand the logic of the out put, see query below:

    Query

    with sub_services as

    (

    Select su_seq 12323, 'HLR1' so_id, 1 seq Union double all the

    Select su_seq 12323, "HLR2' so_id, seq 2 Union double all the

    Select su_seq 12323, "A09" so_id, seq 3 of all the double union

    Select su_seq 12333, "MO1" so_id, seq 4 Union double all the

    Select su_seq 12333, "MO2' so_id, seq 5 Union double all the

    Select su_seq 12333, "A09" so_id, 6 seq in union double all the

    Select su_seq 12333, 'M0CR' so_id, seq 7 Union double all the

    Select su_seq 12999, "LOL1' so_id, seq 8 Union double all the

    Select su_seq 12999, "LOL2' so_id, seq 9 double

    )

    Select *.

    of sub_services b

    where exists (select 1 from sub_services

    where su_seq = b.su_seq

    and so_id = 'A09.

    )

    order by 2;

    The query result

    12323 A09 3

    12333 6 A09

    12323 HLR1 1

    12323 HLR2 2

    12333 M0CR 7

    12333 4 MO1

    12333 5 MO2

    According to my understanding, the above query should return records in red only because of her is below command

    It exists (select 1 from sub_services

    where su_seq = b.su_seq

    and so_id = 'A09.

    but don't know why he's back 7 files, can someone help me understand the result...

    It is query is functionally identical to the PL/SQL block, but much more effective.

    declare

    number of l_res;

    Start

    for line (select *)

    sub_services) loop

    Start

    Select 1 from l_res

    of sub_services

    where su_seq = row.su_seq and

    so_id = "A09" and

    rownum = 1;

    exception when

    NO_DATA_FOUND then

    null;

    end;

    end loop;

    end;

    Essentially every row in the outer query are tested against him exists query.  Given the correlation between two requests is based only on su_seq each line with a su_seq value returned by him is returned in the output.

    Another way to think he uses instead a join condition.  This query is equivalent to the query to exist

    Select the main

    of main sub_services

    Join select (separate su_seq

    of sub_services

    where so_id = "A09") cond

    We main.su_seq = cond.su_seq;

    John

  • I need help creating a vector mask with an adjustable edge or fade, can anyone help?

    I need help creating a vector with an adjustable edge mask or disappear so that I can surround a hand drawn - isolate the background so that I can black out around the hand, the hand a hair above, so I can not just pen tool, can anyone help?

    hand4.jpg

    hand.jpg

    I recommend starting with a layer mask based on the green channel, edition that with the curves to get a decent contrast and then paint in the areas needed.

  • Noob... haha. Need help to understand...

    OK, I downloaded and have the virtual machine of VMa 4.0 linux on my cluster...

    Now what...

    Our goal is to get daily reports in our email information about our environment from virtual machines, we run a 3 cluster nodes.

    I work a lot with linux, so I may need help to figure it all out.

    Thank you

    Try this:

    http://a2alpha.webnode.com/Healthcheck-script/

    He started by Ivo Beerens and with contributions from other institutions. I use on our sites and put in place to send every day as a scheduled task. You don't need the vMA to run it, it will work from the vCenter server. There are details of the requirements on the page. Its a powershell script.

    Dan

  • need help to understand REGEXP_REPLACE

    Hi all
    I'm new to this site so please forgive me for making mistakes. I have a field 'DESCRIPTION of the STUDENT' and they have the following values
    2830 ORO - (2011) Rob Miller [6]
    2830 ORO - Cathy Ingrid (2011) [7]
    2830 ORO - (2011) Sam Sullivan [8]
    2650 Robert Lawson
    2660 Pat Ortt (2009)
    2690 - mark lively
    2710 Tim Lacreta
    What I want in my desired output is
    (2011) Rob Miller [6]
    Cathy Ingrid (2011) [7]
    (2011) Sam Sullivan [8]
    Robert Lawson
    Pat Ortt (2009)
    Mark lively
    Tim Lacreta

    Need help please, I know I have to use REGEXP_REPLACE, but I do not understand how I went through the documentation, but has not been of any help.

    Thank you

    Hello

    Welcome to the forum!

    Whenever you have a problem, please post CREATE TABLE and INSERT statements for your sample data. Since this is your first post, I'll do it for you:

    CREATE TABLE     table_x
    (       student_description     VARCHAR2 (80)
    );
    
    INSERT INTO table_x (student_description) VALUES ('2830-BGC - (2011) Rob Miller [6]');
    INSERT INTO table_x (student_description) VALUES ('2830-BGC - (2011) Cathy Ingid [7]');
    INSERT INTO table_x (student_description) VALUES ('2830-BGC - (2011) Sam Sullivan [8]');
    INSERT INTO table_x (student_description) VALUES ('2650 - Robert Lawson');
    INSERT INTO table_x (student_description) VALUES ('2660 - Pat Ortt(2009)');
    INSERT INTO table_x (student_description) VALUES ('2690 - Mark Lively');
    INSERT INTO table_x (student_description) VALUES ('2710 - Tim Lacreta');
    

    Explain how you get the results you want from these data. For example: "I want the student_description part that comes after the substring of characters 3 space-dash-space. Spaces are important, because the first part of student_description, the part I want to delete, can contain a hyphen (for example ' 2830 - ORO - (2011) Rob Miller [6] "). »

    I think you want something like this:

    SELECT     student_description
    ,     REGEXP_REPLACE ( student_description
                     , '.* - (.*$)'
                     , '\1'
                     )          AS after_dash
    FROM    table_x
    ;
    

    «. "*" means "0 or more characters (all).
    "-" means exactly what it says: a space, followed by a hyphen, followed by a space. Hyphen has no special meaning outside the brackets.
    ' $' means the end of the string.

    It would be more effective to do this particular job without using regular expressions:

    SELECT     student_description
    ,     SUBSTR ( student_description
                , 3 + INSTR ( student_description
                                  , ' - '
                      )
                )          AS after_dash
    FROM    table_x
    ;
    

    Depending on your needs, you may need to adjust this query if student_description does not always contain ' - '.

    Published by: Frank Kulash, December 29, 2011 14:08

  • Need help to restore Iphone recycled with no password

    Hello, I received a recycled locked Iphone no password need help. Downloaded Itunes followed instructions nothing and I have no company of cells still need help. J.

    You must use a SIM card to activate the phone

    IF the phone is locked - so it must be a carrier card

    IF the carrier unlocked - any SIM card will do

    There is no need for a new SIM card

Maybe you are looking for