Need help to understand political static with Nat No.
Hi all
I have a Pix 515e with 6 interfaces. 5 interfaces are considered as internal that we don't want any translation NAT occur between them. We want only NAT between the 5 and the external interface.
I created a No_Nat ACL successfully to not manage any portion of nat.
What I have trouble understanding is the static command to allow traffic between higher levels to lower levels and vice versa.
I understand the
public static inside_address outside_address (indoor, outdoor)
for the part of NAT translation.
What I do not understand, this is when the inside address and address outside are the same, what order are going. For example, my inner interface (192.168.1.0/24) (sec100) is where the live servers, and I have another interface named accounting (192.168.2.0/24) (sec75).
If I don't want no nat occurs between these two, I have the following
No_Nat of the 192.168.1.0/24 192.168.2.0/24 ip access list permit
No_Nat of the 192.168.1.0/24 192.168.2.0/24 ip access list permit
NAT (inside) 0-list of access No_Nat
NAT (accounting) 0-list of access No_Nat
Now how can I enter the static command?
Maybe
static (inside, accounting) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
or
static (inside, accounting) 192.168.2.0 192.168.2.0 netmask 255.255.255.0
or
static (accounting, inside) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
or
static (accounting, inside) 192.168.2.0 192.168.2.0 netmask 255.255.255.0
I do not understand the prescription for it and why it would be used one verses the other way. Is the security level determines the order? Do I need two static command, one for each direction?
Thank you
Denny
Hello denny
static can be defined in any way... its only traffic that determines what it... for example, if accounting dmz is access to any server on your inside interface, you normally want the accounting servers see the original on its public IP server inside... so, you will end up as static
static (inside, accounting) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
only the above static command is sufficient to establish connectivity between inside and dmz accounting. u don't need 2 static on any sense...
Similarly, if you want to inside users to access a server on the dmz accounting, you can write a static type
static (accounting, inside) 192.168.2.0 192.168.2.0 netmask 255.255.255.0
hope you understand. Let us know if you need help... but normally a statement nat 0 is more than enough for the inside / dmz communication
Kind regards
REDA
Tags: Cisco Security
Similar Questions
-
need help to understand the compatibility with video cards
I recently bought a HP Pavilion a6742p Desktop PC I have no idea what graphics cards, it supports (trying to upgrade). Check the manufacturers page, but I couldn't understand anything either here is the link
http://h10025.www1.HP.com/ewfrf/wc/product?LC=en&DLC=en&CC=HK&lang=en&product=3875703
insaneaim wrote:
THX but which manufacturers video card companies take in charge of hp?
HERE, none of them. I recommend the following manufacturers, XFX, BFG, EVGA, Sapphire & PNY, in that order. These recommendations are based on personal knowledge, as well as several years of hanging around in the forums of enthusiasts.
-
Need help to understand why my downloaded PDF doc displays "Please wait...". If this message is not finally replaced with the appropriate content... "after that I have already downloaded the version update for windows 10
This is because the PDF file is not be open in Acrobat or Reader, but by the browser which is unable to handle the specific PDF content.
If you use Firefox or Chrome, follow these steps: https://helpx.adobe.com/livecycle/kb/xfa-forms-firefox-chrome.html
-
I got a license for Lightroom 5 when I bought my Leica delux 4 in 2012. It worked great, but after that I put an old hard drive on my PC (for 30 minutes - then I removed again) to get some information of this former, Lightroom now license application or try it for 30 days.
I have not installed Lightroom on a new hard drive. He is always on the same hard disk. How can I now have my Lightroom to run again using my serial number and TAN? Need help to reactivate my old serial number and the number TAN.
I use win 7.
Duplicate thread: need help to reactivate Lightroom 5 with my old serial number and the number TAN. I got a license for Lightroom 5 when I bought my Leica delux 4 in 2012.
-
Need help to solve the problem with the margin at the bottom of the converted pdf file.
Need help to solve the problem with the margin of the converted CEO down. What caused the change in format?
Hi jerrio1949,
There is no way to change the margin, you settle back into your original file & then convert to PDF format.
Kind regards
Nicos -
Need help to open two images with the same file with different exposures on the screen at the same time in the Photoshop creative cloud (in previous versions we could open two images of the same nef (raw) file and then combine them on the screen with the move tool. They have become a composite of two layers which could be developed further with the mask tool.
Hello
Please go to the preferences > workspace and uncheck the option 'open the document in the tabs '.
Now you can click on file and choose file > open and open the two images in two different windows which can be arranged side by side.
Thank you
-
Need help to understand CodeModuleListener.
Hi all
I need your help to understand CodeModuleListener.
I need to implement CodeModuleListener in my application, but I am confused between docs provided with the 5.0 SDK and documentation online.
Please look at the below link and image
If you can not see image below please find docs on link: -.
Search in Motion\BlackBerry JDE 5.0.0\docs\api\index.html (or attempt to open attachments) Please answer as soon as POSSIBLE.
Found the root of the problem.
When I was using jde 5.0 with eclipse (by creating an ee file) problem appears, but as I install it new eclipse with the plugin 5.0, problem solved.
-
Need help as soon as POSSIBLE with RAM Preview
Hey guys I need help with my RAM Preview and how to get it back on the default setting. I don't know what happened, but now my RAM Preview is divided on two screens. I tried literally everything to solve this problem and came to nothing. Nothing on google as well. Help, please! I need to get there soon! Here's what happens: 2016-09 - 03.png - Google Drive
This is your equal to 2 times and not the RAM Preview Composition Panel (in fact it is seen now and not the RAM Preview... you can call him Mr. Preview if you want to get fancy). knowing how to describe your problem lies at halfway to a solution
DON'T PANIC!
Set it to 1 view and you'll be fine!
These views are used for 3D to show the different perspectives and views spelling of a 3D scene. When they have no use in 2D. If you clicked on the option to display 2 views or more they will appear unless you change it back manually. even when you reset your workspace, they will appear - so I understand why this can be confusing.
more about it here: https://helpx.adobe.com/after-effects/using/modifying-using-views.html...
-
Need help to understand the network of vSphere environment
Hello
I need your help in understanding the network environment in vSphere. Please see the diagram and the text below:
NIC #1 - Management Port (access from client vsphere, vCenter server)
NIC #2 - Port of VMkernal (for iSCSI, vMotion, etc.)
NIC #3 -?
#4 – CARTE NETWORK INTERFACE?
Q1 how allow external users to access services over the ESX host? (for example, IIS, FTP, Exchange, NFS)
Q2, what will be the role of the other two network cards? Is it connected to the physical switch?
* Ask you all to please help me by sharing your knowledge / experience on the network portion, you have made in your environment as NIC how, what to do with that. *
I really need to understand the networking of concepts in vSphere, hope that your help!
Best regards: Yash
With an additional NIC with 2 port a general configuration might look like this:
vSwitch0 - vmnic0, vmnic1 (connected to different physical switches)
Network VMkernel management
VMotion VMkernel network (own IP network, own VLAN)
Better if they is configured as active / standby.
vSwitch1 - vmnic2, vmnic3 (connected to different physical switches)
Trade VM
vSwitch2 - vmnic4, vmnic5 (connected to different physical switches)
VMkernel iSCSI (own IP network, own VLAN)
Ideal if it is added to the component Multipath iSCSI, which is quite easy to vSphere 5.
-
Need help to organize Excel files with several data
Hello everyone!
I'm working on a project consisting of a full acquisition system. I have great finisheda part of my program and now my guardian's ask me something else.
In you project I have several datas: Move, force, speed, time,...
And he would like that this data in the same Excel file with a predefined order. In the example: column 1: time, column 2: speed, etc.
I already tried to work with the block 'write on a file of measure' and associate a different signal through a simulation, and it works. The first signal is the left column. The second signal is the second column. So it's ok about this. But when I try to link a VI unlike a simulation, that the file does not work. Even if I use the data of 3 or 4, I only had a column with some strange results.
That's why I ask your help. I would like to know if you have a good way to solve this problem I want to clarify that I am a beginner in LabVIEW.
I join my project in order to help you understand. I hope I was clear enough
Kind regards.
ML
PS: Sorry for my English, I know that I'm not very good like that!
Thank you for your project, including - it shows me that you are using LabVIEW 2015, which means that you have the Report Generation Toolkit, with the ability to easily generate Excel "Reports", available.
If you really want to generate Excel (.xls, .xlsx) files, the GTA is, by far, the best way to do. If you go to the search bar in the Forums of LabVIEW and type "Example revised" - the first 'hit' should be a post of two years of mine where I show how to use the GTA to more or less do what you described. Give it a try with some of your data, and come back if you have any other questions.
Bob Schor
-
Need help to understand the query result
Hi gurus
I was reading one of the question here in this forum and its link is below:
I had some confusion related to this code and don't understand the logic of the out put, see query below:
Query
with sub_services as
(
Select su_seq 12323, 'HLR1' so_id, 1 seq Union double all the
Select su_seq 12323, "HLR2' so_id, seq 2 Union double all the
Select su_seq 12323, "A09" so_id, seq 3 of all the double union
Select su_seq 12333, "MO1" so_id, seq 4 Union double all the
Select su_seq 12333, "MO2' so_id, seq 5 Union double all the
Select su_seq 12333, "A09" so_id, 6 seq in union double all the
Select su_seq 12333, 'M0CR' so_id, seq 7 Union double all the
Select su_seq 12999, "LOL1' so_id, seq 8 Union double all the
Select su_seq 12999, "LOL2' so_id, seq 9 double
)
Select *.
of sub_services b
where exists (select 1 from sub_services
where su_seq = b.su_seq
and so_id = 'A09.
)
order by 2;
The query result
12323 A09 3
12333 6 A09
12323 HLR1 1
12323 HLR2 2
12333 M0CR 7
12333 4 MO1
12333 5 MO2
According to my understanding, the above query should return records in red only because of her is below command
It exists (select 1 from sub_services
where su_seq = b.su_seq
and so_id = 'A09.
but don't know why he's back 7 files, can someone help me understand the result...
It is query is functionally identical to the PL/SQL block, but much more effective.
declare
number of l_res;
Start
for line (select *)
sub_services) loop
Start
Select 1 from l_res
of sub_services
where su_seq = row.su_seq and
so_id = "A09" and
rownum = 1;
Essentially every row in the outer query are tested against him exists query. Given the correlation between two requests is based only on su_seq each line with a su_seq value returned by him is returned in the output.
Another way to think he uses instead a join condition. This query is equivalent to the query to exist
Select the main
of main sub_services
Join select (separate su_seq
of sub_services
where so_id = "A09") cond
We main.su_seq = cond.su_seq;
John
-
I need help creating a vector mask with an adjustable edge or fade, can anyone help?
I need help creating a vector with an adjustable edge mask or disappear so that I can surround a hand drawn - isolate the background so that I can black out around the hand, the hand a hair above, so I can not just pen tool, can anyone help?
I recommend starting with a layer mask based on the green channel, edition that with the curves to get a decent contrast and then paint in the areas needed.
-
Noob... haha. Need help to understand...
OK, I downloaded and have the virtual machine of VMa 4.0 linux on my cluster...
Now what...
Our goal is to get daily reports in our email information about our environment from virtual machines, we run a 3 cluster nodes.
I work a lot with linux, so I may need help to figure it all out.
Thank you
Try this:
http://a2alpha.webnode.com/Healthcheck-script/
He started by Ivo Beerens and with contributions from other institutions. I use on our sites and put in place to send every day as a scheduled task. You don't need the vMA to run it, it will work from the vCenter server. There are details of the requirements on the page. Its a powershell script.
Dan
-
need help to understand REGEXP_REPLACE
Hi all
I'm new to this site so please forgive me for making mistakes. I have a field 'DESCRIPTION of the STUDENT' and they have the following values
2830 ORO - (2011) Rob Miller [6]
2830 ORO - Cathy Ingrid (2011) [7]
2830 ORO - (2011) Sam Sullivan [8]
2650 Robert Lawson
2660 Pat Ortt (2009)
2690 - mark lively
2710 Tim Lacreta
What I want in my desired output is
(2011) Rob Miller [6]
Cathy Ingrid (2011) [7]
(2011) Sam Sullivan [8]
Robert Lawson
Pat Ortt (2009)
Mark lively
Tim Lacreta
Need help please, I know I have to use REGEXP_REPLACE, but I do not understand how I went through the documentation, but has not been of any help.
Thank youHello
Welcome to the forum!
Whenever you have a problem, please post CREATE TABLE and INSERT statements for your sample data. Since this is your first post, I'll do it for you:
CREATE TABLE table_x ( student_description VARCHAR2 (80) ); INSERT INTO table_x (student_description) VALUES ('2830-BGC - (2011) Rob Miller [6]'); INSERT INTO table_x (student_description) VALUES ('2830-BGC - (2011) Cathy Ingid [7]'); INSERT INTO table_x (student_description) VALUES ('2830-BGC - (2011) Sam Sullivan [8]'); INSERT INTO table_x (student_description) VALUES ('2650 - Robert Lawson'); INSERT INTO table_x (student_description) VALUES ('2660 - Pat Ortt(2009)'); INSERT INTO table_x (student_description) VALUES ('2690 - Mark Lively'); INSERT INTO table_x (student_description) VALUES ('2710 - Tim Lacreta');
Explain how you get the results you want from these data. For example: "I want the student_description part that comes after the substring of characters 3 space-dash-space. Spaces are important, because the first part of student_description, the part I want to delete, can contain a hyphen (for example ' 2830 - ORO - (2011) Rob Miller [6] "). »
I think you want something like this:
SELECT student_description , REGEXP_REPLACE ( student_description , '.* - (.*$)' , '\1' ) AS after_dash FROM table_x ;
«. "*" means "0 or more characters (all).
"-" means exactly what it says: a space, followed by a hyphen, followed by a space. Hyphen has no special meaning outside the brackets.
' $' means the end of the string.It would be more effective to do this particular job without using regular expressions:
SELECT student_description , SUBSTR ( student_description , 3 + INSTR ( student_description , ' - ' ) ) AS after_dash FROM table_x ;
Depending on your needs, you may need to adjust this query if student_description does not always contain ' - '.
Published by: Frank Kulash, December 29, 2011 14:08
-
Need help to restore Iphone recycled with no password
Hello, I received a recycled locked Iphone no password need help. Downloaded Itunes followed instructions nothing and I have no company of cells still need help. J.
You must use a SIM card to activate the phone
IF the phone is locked - so it must be a carrier card
IF the carrier unlocked - any SIM card will do
There is no need for a new SIM card
Maybe you are looking for
-
Activity app illustrating not road
Just saw this on iLounge this morning. Apparently the iPhone App activity is supposed to now show the routes of your workouts as well as the temperature at the time of the workout. I guess that they have managed to do this pairing of the iphone with
-
iCloud wants me to change my password. I don't
iClod wants me to change my apple ID password before I use it now. I don't. Its my business what password I use, and its use in on itunes etc and other apple devices associated. Apple is arrogant. If someone at Apple is listening to everyone complain
-
Hello: Did someone knows if it is possible to use a HP Photosmart 8750 printer with a tablet of Microsoft Surface RT? If you try to install the printer, its driver is not lsted in option. If it is installed via a usb port, a message appears indicatin
-
It's my pc problem, what do I do to fix it? It says that I have to choose the right fix or otherwise it will be haarm my system, I just need a step by step help and how to choose the right fix for my problem, thank you!... Wait ill the resp0nse, than
-
I have Windows XP Home in my computer, but I want to buy a DVD - RW to burn music. Before buy you, I need to know if it is compatible with my motherboard, but I have no idea how to collect information on the motherboard on my computer. Any help?