IP which only allowed for PAT

Hello,
I am looking for example which allow some of the IP's belongs to INSIDE which can allow to using PAT method to access Internet.
With reference to URL
http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/nat_objects.html#pgfId-1455942
It is talking about the whole 192.168.2.0/24 subnet.
The following example configures dynamic PAT that hides the 192.168.2.0 network behind the outside interface address:
hostname(config)# object network my-inside-net
hostname(config-network-object)# subnet 192.168.2.0 255.255.255.0
hostname(config-network-object)# nat (inside,outside) dynamic interface
I would like to check how should config if only allow parts of IP belongs to 192.168.2.0/24 can be PAT to internet and others will deny.  Should be need create additional ACL?
Thanks!

Hi,
You might be better of limitin the mentioned hosts from connecting to the Internet in the interface ACL rather than making a special NAT configuration that determines if a host can connect to the Internet.
If you want to control which host gets NATed then you could use the Manual NAT / Twice NAT configuration instead of the above Auto NAT / Network Object NAT
Example could look something like this
object-group network PAT-SOURCE-HOSTS
 network-object host <host1 ip>
 network-object host <host2 ip>
 network-object host <host3 ip>
nat (inside,outside) after-auto source dynamic PAT-SOURCE-HOSTS interface
You can then add the addresses directly under the "object-group" or remove them when needed.
You could naturally use small subnets instead of the host addresses in the above example if all the users are from a certain range of the subnet you mentioned. You will also have to make sure that there is no other NAT configuration on your ASA that would apply to the users.
The above Manual NAT / Twice NAT is at the lowest Section 3 (priority of NAT configuration) because it has "after-auto" as a part of the "nat" command.
Hope this helps :)
- Jouni

Similar Messages

  • Automatic carryforward only allowed for amount 0

    On 4.7, we are attempting to process a payment for on a FY2007 Purchase order using MIRO. We are now in our FY2009 year but we are receiving the error message FMCF101 - Automatic carryforward is only allowed for amount 0. What could be the cause of this?
    The PO was created on 03/21/2007. A goods receipt for the total quantity of the PO was entered on 06/27/2007. Two invoices were successfully processed on 02/28/2008 but when we attempt the final 3rd invoice for 06/30/08, we receive the error message.

    If you have Periodic Based Encumbrance Tracking PBET active and you use the GR/IR updating in OFUP as well as you use the invoices to determine the CF level, then you MUST carry forward the GR - which in FM are considered invoices (same value type 54).
    Trying to reduce the GR without having carried forward the GR is not valid and you will get the error "Automatic carryforward is only allowed for amount 0".
    The only possibilities to avoid this error are:
    1. Carry forward the GR from the previous fiscal year to the one being modified.
    2. In OFUP do not use the invoice to determine the carry forward level.
    3. Do not update both the GR and IR but only the IR
    4. Do not use PBET. To update the GR in the previous FY or update it in the current FY without carry forward, contradicts PBET.

  • I would like to transfer all data from my iPod classic to my new computer with windows 8.1. My old computer's cpu died. Utilizing iTunes which only allows iTunes albums purchased at iTunes store. The cd's were loaded via iTunes originally.

    I would like to transfer all data from my iPod classic to my new computer with windows 8.1. My old computer's cpu died. Utilizing iTunes which only allows iTunes albums purchased at iTunes store. The cd's were loaded via iTunes originally.

    Install disk drive from old computer in an external enclosure.
    Then copy the complete iTunes library from the disk drive to the disk drive in the new computer.

  • I am a Canadian staying in England for a few weeks.  How can I get an iPhoto Book printed win England and sent as a gift to an English relative? With my account, it seems that Apple only allows for my book to be printed in Canada.

    I am a Canadian staying in England for a few weeks.  How can I get an iPhoto Book printed win England and sent as a gift to an English relative? With my account, it seems that Apple only allows for my book to be printed in Canada and then sent to my Canadian address..

    in the iPhoto preferences  change the print products country to the UK and give it a try - there may be some restirctions on billing but it has worked for some people
    LN

  • I'm tying to make a payment for photoshop but the fields on the payment form won't allow me to enter the correct card information.  Im based in Japan but my card is registered to a UK address.  the fields only allow for a Japanese style address and postco

    I'm tying to make a payment for photoshop but the fields on the payment form won't allow me to enter the correct card information.  Im based in Japan but my card is registered to a UK address.  the fields only allow for a Japanese style address and postcode.  What can i do to complete the payment and get photoshop!

    As far as I know, your registered location and your credit card information must match... but,
    This is an open forum, not Adobe support... you need Adobe staff to help
    Adobe contact information - http://helpx.adobe.com/contact.html
    -Select your product and what you need help with
    -Click on the blue box "Still need help? Contact us"
    -or by telephone http://helpx.adobe.com/x-productkb/global/phone-support-orders.html

  • Capacities of type 1 or 2 are only allowed for resources

    HI,
    I am getting the below error during selecting the capacity catogory 001 in the Capacities tab in CR01 transaction.
    Capacities of type 1 or 2 are only allowed for resources.
    Thanks and regards
    Murugesan

    WHat is the work center category you are creating...

  • WM - This screen is only allowed for manual transfer orders

    hi
    I am getting below when i am going to carry out the transaction LT06
    "This screen is only allowed for manual transfer orders"
    please help
    Regards

    then check at the very same place if you have entered an indicator for automatic TO.
    If there is none then check in OMLR what indicators you have set in field immediate TO creation

  • So I just purchased Lightroom 5 and put it on my desktop last week and my computer crashed. If I end up having to purchase a new PC, does this mean I also have to purchase Lightroom again because it is only allowed for 1 PC use?

    This may seem like a silly question. But, I see on the insert that it says license is only good for 1 PC use. I am SO upset that my computer crashed, and thinking about wasting $128 makes that even more upsetting.

    I'm not sure what "insert" you are talking about, but as said above a perpetual license is good for installation on two computers. If the old computer is still functional, you can either uninstall LR5 from it or consider a new computer as the second installation. If the old computer is not functional and will never be used again, then LR is not functional and this is equivalent to its having been uninstalled.

  • Double charge full month of Family Plan which only used for 7 days  and full month of individual plan

    I changed from Family Plan to Individual Plan and I got only refund back $9.99 for one line that stay with Verizon but I got charged double both Family Plan and Individual Plan for full month without any credits for 23 days of unused Family Plan. ($120-discount Family Plan + $39.99-discount Individual Plan) per 1 month (from 06/07 to 07/06).
    I am asking the credit of unused 23 days of Family Plan back into my account when I changed from Family plan to Individual plan then I got the answer like this which I do not agree at all.
    "As the previous rep stated since the numbers were ported out the bill continued to bill until the end of the current bill cycle. This is the reason why there was no credit issued for the first month in advance. Had the numbers not been ported, and instead disconnected, there would have been a refund issued for any unused portion of the service"
    I never saw any clause saying that porting numbers would not get credit issued for any unused portion of the month billed in advance.
    I expected refund 23 days credit of the Family plan from 06/06 to 07/06 back to my account since the family plan supposed to be disconnected on 06/07 but because of porting time schedule from other carrier so that all 4 lines completely disconnected the service 1 week later which is on 06/13/2012 and only 1 line(my current number) left as individual plan as it planned originally 06/07.
    Family Plan with corporate discount: $120-$16 cisco discount/month------> each day is: $104/30 days= $3.46/day
                       23 days unused of Family Plan is : $3.46 x 23= $79.58
    I still expect missing credits into my account: $79.58-$9.99= $69.59.
    At the least if you want to take away the $16 discount for the last month of Family plan, then you still owe me the refund of ($69.59-$16)= $53.59

    verizonloyal wrote:
    You left out the next important sentence ..... If it is your intention to fool all other members, please correct it.
    This is the path for the whole thing:"Customer Agreement"
    http://www.verizonwireless.com/b2c/support/customer-agreement
    I am not a Prepaid customer and I will be entitled to a refund of unused charge from an advanced month charge. Any cancellation should honor that..I called the customer representative to ask in advance what happened when I plan to keep only one line and change to individual plan ,she assured me that I will get credits for any unused of Family Plan of the advanced month, the new Individual Plan charge will take over and I would not get double charge at all.
    I am the customer with Verizon very long time, more than 5 years and I can not believe that you charged me double like that.
    Please return me back my money.
    I am NOT trying to fool anyone. As with the sentence you highlighted, if what I highlighted ONLY pertained to prepaid customers, it would have indicated it in the sentence. Since it did not, it DOES NOT. Postpaid customers are NOT mentioned at all within the section about porting numbers. Are you saying since they are not mentioned that postpaid customers CANNOT port their numbers? Didn't think so. The entire paragraph is about ALL Verizon customers EXCEPT the sentence which specifically singles out prepaid customers. You are responsible for all charges until the end of the billing cycle from the point of porting, not from when you asked to be ported. Therefore you are responsible for the charges for the "Family Plan" until the end of the billing cycle.
    Unfortunately, you only left ONE phone on the account when you ported out your numbers. Therefore the single line could NOT have been left on a Family Plan, and was therefore migrated to an Individual Plan. AT MOST, you would be entitled to a prorated refund of the $9.99 access fee FOR THAT ONE LINE, since that line was not canceled due to the porting. However, you should ONLY be responsible for Individual Plan charges from the point your single line was migrated until the end of the billing cycle, NOT for an entire month of service. Of course, your bill would show that the following month was being charged, too, since Verizon charges a month in advance.
    While Verizon may refund you more money just to placate you, according to the CUSTOMER AGREEMENT, you are not entitled to it.
    Good luck.

  • IPhone only allows for a very limited amount of iTunes tracks

    Hi there, since receiving a replacement iPhone 5, I've only been able to put 40-ish songs on it at a time. I have plenty of room for more, and have the most recent operating system, Is there a fix for this?

    OK Steve..I bet I know, because it happened to me.,,try this: It has to do with the AAC Encoder and bit rate at which you are importing songs into your ITunes.
    Connect your IPod, and look at the Bit Rate. If it is 800 to over a thousand, your songs are taking up too much space; the bit rate should only be 128 to 160. A song imported at a bit rate of 1022 will take up around 33 MB, while that same song imported at a bit rate of 160 will only take up about 5 MB. If that is the case, you will have to import all your songs again using a lower bit rate, and then replace those high bit rate songs on your IPod, which is a pain, but I do not know any other way to do it.
    This is how your change your bit rate that you import songs into your ITunes program from CD's:
    1. Connect your IPod & click EDIT, then PREFERENCES.
    2. Click the ADVANCED tab, then the IMPORTING tab.
    3. I use the AAC Encoder, and, in the SETTING block, select CUSTOM.
    4. Select 160 kbps, auto for the 2 boxes below, & say OK. You could, if you want use 'HIGH QUALITY 128 kbps' and that works fine, but I like 160...not much difference in how much room it takes up on your IPod..WHICH is where your problem lies, I suspect.
    Spend some time replacing your songs, and you can put a ton of songs on your IPod. Hope this all makes sense,,Bobby in Jax

  • NEF files only allow for exposure changes in CS2

    Hi
    When I open a NEF file (this happened with both D50 and D200 cameras) they only open a small raw box that allows me to change just exposure.
    When I had a Canon 20D the raw files would open a big box where I could change EVERYTHING and included a preview screen, but I just dont have this for my Nikon files.
    Any ideas?
    Thanks
    And

    To expand on Jeff's message, the Nikon PS plug-in is installed automatically when you install Nikon software. To get ACR, you need to remove or disable (rename, changing the extension) the Nikon plug-in and properly install Adobe Camera Raw, per the installations on the ACR download page.
    Art

  • Contract release orders only allowed for sche.agreements with dep.condition

    hi frnds,
    i got this error msg while i try to create a scheduling agreement with ref. to contracts
    help me out...
    thanks in advance....

    Hi
    Check whether you have used contract or Contract release order.
    Also check the allowed document types for the scheduling agreement.
    Thanks/Karthik

  • Is SAP Certication only allowed for ppl taken training from selected center

    Hi Experts
    Just wanted to know that : If someone who has taken SAP training from any local institute is elligible for SAP certification?
    Is there any prerequisite for Certification , which states that u should be trained from some specific institues. If yes, which are those institutes in India.
    Regards
    Dhanya Nair

    Dear Dhanya Nair,
    for the certification of your software product there is no prerequisite for a specifiy SAP training.
    This forum is about software product certification. I think your interest is more into consultant certification. Please have a look at the following link for further information:
    http://www.sap.com/services/education/certification/index.epx
    Best regards,
      Juergen

  • RFC Communication Channel only allows for one Logon User

    We're currently building a SOAP over HTTPS application in XI where
    an RFC communication channel connects to R3 with a logon user id
    and logon password (RFC Client Parameter). When updates are made
    on the R3 side using BAPI_NETWORK_MAINTAIN (for example), they're all
    done with the one logon user id. So fields "Last Changed by" or "Created by" have the
    one id, and any approvals can only be done by the one manager over the one id XI uses.
    If the external application passed an id (and password if necessary) to
    XI, is there any way connect to R3 using the passed id, and not have to
    use the one generic id .  If we're limited to the one id, is it
    possible on the R3 side to be able to change the id to a passed id that
    can then run the BAPI's/RFC's ?

    Hi Kye
    These should help you
    https://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/8798be90-0201-0010-d093-85f728778d37
    https://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/2a9dbe90-0201-0010-b283-a56f64534f18
    To capture parameter from URL you need to use ASMA for SOAP.
    Thanks
    Gaurav

  • Wifi has suddenly stopped working. There is an exclamation mark which takes me to network diagnostics. This asks me for network name and password. This is different from the startup wizard which only asked for a WEP key and modem name. What to do?

    My wifi has suddenly stopped working on my iMac, after working fine for almost a year. There is an exclamation mark on the wifi bars and when I click it, it takes me to a network diagnostics page. This page asks me for my username and password for the wifi, which I don't have. It is different from the WEP key and modem name, which I originally used to set up my connection. I have not experienced any problems on all my other wifi-enabled devices. Ipod touch, iPad, MacBook all work fine. What should I do?

    The name is the name of the network you created on the router. The password is the WEP password. You shouldn't be using WEP at all, as it's insecure and also seems to cause connection failures. Use WPA 2 Personal. If your router doesn't support it, get a new one.

Maybe you are looking for

  • Multiple devices/apple ID's one laptop

    Hi can someone help me, i have an iphone 5 my wife has a iphone 4 and my son has a ipod 5th generation im purchasing a laptop and am wondering the following : can we all use the one itunes but each be able to backup or own information? i.e if i attac

  • Logic preference are not loading completely so my audio has stopped workin

    when i boot up logic it says "Error reading /writing file "com.apple.logic.pro.cs" logical end of file reached during read operation." So my logic is totally dead no audio or instruments work - how do i sort this out???

  • Sharing folders in 10.8.3 to windows and macs PROBLEMS

    I'm tryng to share folders from an 10.8.3 imac to users in my LAN (using bot mac and windows) I'm having this problem: 1) Mac users can access the share using afp:// but when they create new folders the permission are: drwxr-xr-x so no other can writ

  • Current Date in BEx

    Hi guys, I want to calculate a duration between current date and another fixed date in queries of Business Explorer. I'm on BI 7.0 and use Infosets. I can't use a virtual caracteristic because of infosets. So do you know how put current date in queri

  • How can i turn off faces in iPhoto 11´?. I can´t not ignore this!

    Hello People. How can i turn off faces in Iphoto? This features annoys me slowly! Please Help ! Thank you Rompehuesos