No NAT convertion to 9.x from 8.0 question

I had something like this on the 8.0
nat (inside) 0 access-list 100
access-list 100 extended permit ip 10.239.1.0 255.255.255.0 10.239.125.0 255.255.255.0
access-list 100 extended permit ip 10.239.1.0 255.255.255.0 10.239.126.0 255.255.255.0
access-list 100 extended permit ip 10.239.17.0 255.255.255.0 10.239.125.0 255.255.255.0
access-list 100 extended permit ip 10.239.17.0 255.255.255.0 10.239.126.0 255.255.255.0
I know I create objects and this is what it would look like in the 9.x config
object network OBJ-10.239.1.0_24
 subnet 10.239.1.0 255.255.255.0
object network OBJ-10.239.17.0_24
 subnet 10.239.17.0 255.255.255.0
object network OBJ-10.239.125.0_VPN
 subnet 10.239.125.0 255.255.255.0
object network OBJ-10.239.126.0_VPN
 subnet 10.239.126.0 255.255.255.0
nat (inside,outside) source static OBJ-10.239.1.0_24 OBJ-10.239.1.0_24 destination static OBJ-10.239.125.0_VPN OBJ-10.239.125.0_VPN
nat (inside,outside) source static OBJ-10.239.1.0_24 OBJ-10.239.1.0_24 destination static OBJ-10.239.126.0_VPN OBJ-10.239.126.0_VPN
nat (inside,outside) source static OBJ-10.239.17.0_24 OBJ-10.239.17.0_24 destination static OBJ-10.239.125.0_VPN OBJ-10.239.125.0_VPN
nat (inside,outside) source static OBJ-10.239.17.0_24 OBJ-10.239.17.0_24 destination static OBJ-10.239.126.0_VPN OBJ-10.239.126.0_VPN
Now I have a bunch of subnets in the 10.239.X.0 space so rather than creating a bunch of NAT lines for each one could I do this.
object network OBJ-10.239.0.0_16
 subnet 10.239.0.0 255.255.0.0
object network OBJ-10.239.125.0_VPN
 subnet 10.239.125.0 255.255.255.0
object network OBJ-10.239.126.0_VPN
 subnet 10.239.126.0 255.255.255.0
nat (inside,outside) source static OBJ-10.239.0.0_16 OBJ-10.239.0.0_16 destination static OBJ-10.239.125.0_VPN OBJ-10.239.125.0_VPN
nat (inside,outside) source static OBJ-10.239.0.0_16 OBJ-10.239.0.0_16 destination static OBJ-10.239.126.0_VPN OBJ-10.239.126.0_VPN
or would this cause a problem because the 10.239.125.0 and the 10.239.126.0 would overlap with the source 10.23.0.0 /16
Mike

Hi,
The overlap in this case should not cause any problems as this NAT configuration only applies to traffic between "inside" and "outside" interface. So I don't see a situation where it would for example forward traffic in a wrong way.
It would possibly become a problem if for example you had some subnets fitting the 10.239.0.0/16 behind some other interface than "inside". In that situation you might face a problem if a remote VPN user should be able to connect to that subnet. It might then match this NAT configuration and get forwarded to "inside" interface rather than that other interface.
You should however be able to avoid the above problem by either adding NAT configuration for those subnets behind another interface on the ASA on a higher priority in the NAT configuration or perhaps you could have the above NAT configurations you mention with the parameter "route-lookup" at the end. The "route-lookup" should force the ASA to check the routing table and not apply the NAT configuration if the route lookups destination interface did not match the one the NAT configuration had. It should therefore prevent traffic from getting forwarded to the wrong interface by the NAT. The ASA would then to my understanding go through the other NAT configurations to see if there is any other matching configuration that it could apply.
I guess you have many options how to do the above NAT configurations.
I typically use "object-group" configurations to group the subnet related to the NAT0 configurations. If you wanted you could for example group all your internal subnets under one "object-group" and the VPN subnets under their own "object-group".
object-group network VPN-NAT0-LOCAL
 network-object 10.239.x.0 255.255.255.0
 network-object 10.239.y.0 255.255.255.0
object-group network VPN-NAT0-REMOTE
 network-object 10.239.125.0 255.255.255.0
 network-object 10.239.126.0 255.255.255.0
nat (inside,outside) source static VPN-NAT0-LOCAL VPN-NAT0-LOCAL destination static VPN-NAT0-REMOTE VPN-NAT0-REMOTE
Naturally this approach might narrow down your ability to name the objects in a meaningful way but I personally prefer to keep the amount of objects to a minimum.
Hope this helps :)
- Jouni

Similar Messages

  • How do I convert my Voice Memo from iPhone 5s to a text file?

    How do I convert my Voice Memo from iPhone 5s to a text file?

    If you have Evernote, you could try quicktate.   http://www.quicktate.com
    I convert voice memos on my Mac using the Dictation feature:
    Open TextEdit on a new document
    Enable  Dictation & Speech enabled the System Preferences.
    Press the fn-key twice
    Play the voice memo on the iPhone and let the  Mac listen to it using the internal microphone with TextEdit open on a new document.
    Press the fn-key twice, to finish Dictation.  You will only see the transcribed text, when Dictation has finished.

  • Itunes is copying/converting 500gb of music from .wma to .m4a files that are on an external drive onto my laptop which doesnt have enough room. how do i reroute these newly converted files somewhere with enough space for them?

    itunes is copying/converting 500gb of music from .wma to .m4a files that are on an external drive onto my laptop which doesnt have enough room. how do i reroute these newly converted files somewhere with enough space for them?
    new to itunes, used windows media player before that and always ripped music directly to an external hardrive and accessed it through the player. now that i downloaded itunes it is taking from the external hardrive and copying a second file for each song onto my lap top hard drive which does not have the capacity for all my music. as itunes converts music files i want them saved back onto my external drive or another location i have space for rather than the lap top. how do i change the setting to move the itunes media folder to another location. assuming that hitting copy and past and dropping it in a random location will cause a few errors.

    When I have done this, all I did was network the two machines and copy the contents of the iTunes folder to the other machine, and that's it.
    My understanding (which may not be 100% correct) is that the one file that is absolutely necessary is iTunes Library, and that the XML file is actually a copy auto-generated from the iTunes Library, appearing in a different format only for non-iTunes apps that take advantage of the iTunes Library data.
    As far as I know, if you simply have the Library (database) file and all your original music files, iTunes on that computer should operate as it did on your old computer. I believe that the Album Artwork, Genius Data, and XML files can be regenerated from the Library file. Not sure about the Extras file.

  • What type of adapter/ converter would I purchase from Apple if traveling to France? Does Apple even offer one?

    What type of adapter/ converter would I purchase from Apple if traveling to France? Does Apple even offer one?

    The power supplies used by Apple can be used with any line voltage between 100 and 240 volts so you done need any changes there.
    What you will need is pin adapters because the European socket require different shaped pins. You can get the pins adapters at any hardware store quite inexpensively.
    Read http://www.francetravelplanner.com/details/electric.html

  • How to convert the date time from MM-DD-YYYThh:mm:ss to YYYY-MM-DDThh:mm:ss format

    Hi All,
    I have a requirement in my project like to convert the date time from one format to another.my situation is like to convert the date time from MM-DD-YYYThh:mm:ss to YYYY-MM-DDThh:mm:ss format. I am using the soa suite 11.1.1.6.
    Can any one suggest me how to convert in the BPEL transformation.
    Thanks,
    Sanju.

    Hi Sanju,
    Store the date to be converted into a variable viz. dateVar. Now, process an expression in assign as: xp20:format-dateTime($dateVar,'[Y0001]-[M01]-[D01] [h]:[m01]:[s01]').
    Regards

  • How do I convert or send data from a MacBook Pro to an s-video device???

    How do I convert or send data from a MacBook Pro to an s-video device??

    Use a Mini-Displayport-to-VGA adapter and a conversion box like this:
    http://www.amazon.com/PC-To-TV-Video-Converter/dp/B001CJOLBW/ref=pd_cp_e_2
    MBP

  • Not able to convert my application file from mxml to Action Script

    Hi,
        In my mobile project I want to convert my application file from mxml to ActionScript.When I do this I get error and when I digged into the code I found that the error comes in preloader class initialize method as preloader property in System Manager class is null(line 2026 in SystemManager class).it actually represents the splashScreen class.When I tried to set the splash Screen the document says we cannot set this property from action script.
       I know we have an option of action script mobile project but it doesnt recognise TabbedViewNavigatorApplication.
    So how can I overcome the problem.

    I get the following error:
    TypeError: Error #1007: Instantiation attempted on a non-constructor.
    at mx.preloaders::Preloader/initialize()[E:\dev\4.5.1\frameworks\projects\framework\src\mx\p reloaders\Preloader.as:261]
    at mx.managers::SystemManager/http://www.adobe.com/2006/flex/mx/internal::initialize()[E:\dev\4.5.1\frameworks\projects\ framework\src\mx\managers\SystemManager.as:2103]
    at mx.managers::SystemManager/initHandler()[E:\dev\4.5.1\frameworks\projects\framework\src\m x\managers\SystemManager.as:2588]

  • Converting data volume type from LINK to FILE on a Linux OS

    Dear experts,
    I am currently running MaxDB 7.7.04.29 on Red Hat Linux 5.1.  The file types for the data volumes were
    initially configured as type LINK and correspondingly made links at the OS level via "ln -s" command. 
    Now (at the OS level) we have replaced the link with the actual file and brought up MaxDB.  The system
    comes up fine without problems but I have a two part question:
    1) What are the ramifications if MaxDB thinks the data volumes are links when in reality they are files.
        (might we encounter a performance problem).
    2) In MaxDB, what is the best way to convert a data volume from type LINK to type FILE?
    Your feedback is greatly appreciated.
    --Erick

    > 1) What are the ramifications if MaxDB thinks the data volumes are links when in reality they are files.
    >     (might we encounter a performance problem).
    Never saw any problems, but since I don't have a linux system at hand I cannot tell you for sure.
    Maybe it's about how to open a file with special options like DirectIO if it's a link...
    > 2) In MaxDB, what is the best way to convert a data volume from type LINK to type FILE?
    There's no 'converting'.
    Shutdown the database to offline.
    Now logon to dbmcli and list all parameters there are.
    You'll get three to four parameters per data volume, one of them called
    DATA_VOLUME_TYPE_0001
    where 0001 is the number of the volume.
    open a parameter session and change the value for the parameters from 'L' to 'F':
    param_startsession
    param_put DATA_VOLUME_TYPE_0001 F
    param_put DATA_VOLUME_TYPE_0002 F
    param_put DATA_VOLUME_TYPE_0003 F
    param_checkall
    param_commitsession
    After that the volumes are recognizes as files.
    regards,
    Lars
    Edited by: Lars Breddemann on Apr 28, 2009 2:53 AM

  • I am trying to convert a pdf file from the Government Website.

    I am trying to convert a pdf file from the government site, it is a divorce petition item d008-eng.docx. Whenever I do the transcript is all over the place. Any suggestions?
    I have only bought the software to do this one thing and it failed.

    If you use Reader XI you should be able to save it. You should also be able to save the form with Acrobat. However, the form name you gave is a docx file, not a PDF. So it is not clear what you are asking. If it were a PDF form as I would have expected, your questions would have made more sense.
    Did you buy Acrobat? If so, are you trying to convert to docx or what. I really do not understand your question. I did find an 8 page PDF of the form (assume it is the same). If you have Acrobat, just start filling it out and save at any stage. I do not see any need to convert it to docx. There are no restrictions on the form for saving or such, so I do not see why you say you can not save your input. If you bought Reader, you got ripped off. If you bought Acrobat there should be no issues with saving. If you use Reader XI there should also be no issues with saving the PDF. So, I do not see the point of your question, sorry.

  • Convert list item attachment from docx to pdf using Word Automation Services

    I have been trying to convert List Item attachments from docx to pdf using word automation services, it works in a normal document library but when I use the list attachment it throws a null reference error.
    var settings = new ConversionJobSettings();
    settings.OutputFormat = Microsoft.Office.Word.Server.Conversions.SaveFormat.PDF;
    var conversion = new ConversionJob("Word Automation Services", settings);
    conversion.UserToken = SPContext.Current.Site.UserToken;
    var wordFile = SPContext.Current.Site.RootWeb.Url + "/" + wordForm.Url;
    var pdfFile = wordFile.Replace(".docx", ".pdf");
    conversion.AddFile(wordFile, pdfFile);
    conversion.Start();
    Using reflector I was able to see my problem lies in Microsoft.Office.Word.Server.FolderIterator.cs where it uses SPFile.Item which returns NULL
    internal void CheckSingleItem(SPFile inputFile, SPFile outputFile)
    Microsoft.Office.Word.Server.Log.TraceTag(0x67337931, Microsoft.Office.Word.Server.Log.Category.ObjectModel, Microsoft.Office.Word.Server.Log.Level.Verbose, "OM: FolderIterator start a single item: source='{0}'; dest='{1}'", new object[] { inputFile.Url, outputFile.Url });
    Stopwatch stopwatch = Microsoft.Office.Word.Server.Log.StartPerfStopwatch();
    try
    this.CheckInputFile(inputFile.Item);
    this.CheckOutputFile(outputFile.Url);
    Is there any way to get around this?

    Hi Qfroth,
    According to your description, my understanding is that when you use word automation service to convert Word to PDF for list item attachment, it throws the null reference error.
    I suggest you can create an event receiver and convert the word to memory stream like below:
    private byte[] ConvertWordToPDF(SPFile spFile, SPUserToken usrToken)
    byte[] result = null;
    try
    using (Stream read = spFile.OpenBinaryStream())
    using (MemoryStream write = new MemoryStream())
    // Initialise Word Automation Service
    SyncConverter sc = new SyncConverter(WORD_AUTOMATION_SERVICE);
    sc.UserToken = usrToken;
    sc.Settings.UpdateFields = true;
    sc.Settings.OutputFormat = SaveFormat.PDF;
    // Convert to PDF
    ConversionItemInfo info = sc.Convert(read, write);
    if (info.Succeeded)
    result = write.ToArray();
    catch (Exception ex)
    // Do your error management here.
    return result;
    Here is a detailed code demo for your reference:
    Word to PDF Conversion using Word Automation Service
    Best Regards
    Zhengyu Guo
    TechNet Community Support

  • Convert smartform as PDF from ABAP Webdynpro

    Hi,
    I want to convert smartform as pdf from ABAP webdynpro.
    Flow: SmartForm-->Generating Function Module -->Getting Output Data --> Converting OTF to PDF --> Open/Save PDF file in ABAP webdynpro.
    What are the sequence of function modules to be used for this?
    OR
    Is there any other way to convert smartform as pdf from ABAP webdynpro?
    plz give me the flow and FM'details clearly in detail.

    Look here https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/f0de1eb8-0b98-2910-7996-8a3c2fcf6785
    Cheers
    Graham Robbo

  • How do I convert emails to PDF from Outlook to make a file on the PC?

    how do I convert emails to PDF from Outlook to make a file on the PC

    It is always tough for anyone when we need to save our emails into one file for future reference. You could either do it manually or can use a simple tool to Convert all your messages into one pdf file . This Single pdf file can be used if we need to read any past email. you can easily convert oulook to pdf in no time. If you are converting several email messages, you can either save them as separate files with initial layout fully intact or combine them into one big PDF document.

  • Approach to converting database character set from Western European to Unicode

    Hi All,
    EBS:12.2.4 upgraded
    O/S: Red Hat Linux
    I am looking for the below information. If anyone could help provide would be great!
    INFORMATION NEEDED: Approach to converting database character set from Western European to Unicode for source systems with large data exceptions
    DETAIL: We are looking to convert Oracle EBS database character set from Western European to Unicode to support Kanji characters. Our scan results show
    both “lossy (110K approx.)” and “truncation (26K approx.)” exceptions in the database which needs to be fixed before the database is converted to Unicode.
    Oracle Support has suggested to fix all open and closed transactions in the source Production instance using forms and scripts.
    We’re looking for information/creative approaches  who have performed similar exercises without having to manipulate data in the source instance.
    Any help in this regard would be greatly appreciated!
    Thanks for yourn time!
    Regards,

    There are two aspects here:
    1. Why do you have such large number of lossy characters? Is this data coming from some very old eBS release, i.e. from before the times of the Java applet interface to Oracle Forms?  Have you analyzed the nature of this lossy data?
    2. There is no easy way around truncation issues as you cannot modify eBS metadata (make columns wider). You must shorten or remove the data manually through the documented eBS interfaces. eBS does not support direct manipulation of data in the database due to complex consistency rules enforced by the application itself (e.g. forms).
    Thanks,
    Sergiusz

  • Function Module to convert date to week from Sunday to Saturday

    Hi,
    In BW the convertion date to week always give week from Monday(1) to Sunday(7)
    I'm looking for a function module to convert date to week from Sunday(1) to Saturday(7)
    Thanks
    Sebastien

    Hi,
    I think this SAP standardized. Maybe you need to create custom FM.
    You can copy SAP FM DATE_GET_WEEK. in the FORM FIRSTWEEK, I see below case,
    CASE start_weekday.
        WHEN if_calendar_definition=>c_monday.
          start_weekday_number = 1.
        WHEN if_calendar_definition=>c_tuesday.
          start_weekday_number = 2.
        WHEN if_calendar_definition=>c_wednesday.
          start_weekday_number = 3.
        WHEN if_calendar_definition=>c_thursday.
          start_weekday_number = 4.
        WHEN if_calendar_definition=>c_friday.
          start_weekday_number = 5.
        WHEN if_calendar_definition=>c_saturday.
          start_weekday_number = 6.
        WHEN if_calendar_definition=>c_sunday.
          start_weekday_number = 7.
      ENDCASE.
    Maybe you can play something here.

  • I'm having troubles converting my raw files from Nikon D5200 (NEF) to DNG. I tried using Lightroom 4, but it didn't identify the folder containing the files. So i downloaded the latest DNG converter but that too didn't identify the files kept in the folde

    I'm having troubles converting my raw files from Nikon D5200 (NEF) to DNG. I tried using Lightroom 4, but it didn't identify the folder containing the files. So i downloaded the latest DNG converter but that too didn't identify the files kept in the folder location. So I downloaded DNG converter v7.3 for D5200. It identifies the folder and files; but it is giving me parsing error on trying to convert files. I'm running Windows Vista Home Edition SP1. Kindly advise. Thank you.

    I probably missed this detail in what you’ve posted, but do you see the thumbnails of the three cameras’ raw files in Finder if you don’t convert to DNG?
    What has happened in the past is that the Apple raw interpreter doesn’t read thumbnails of DNGs it doesn’t like, where at least one thing it didn’t used to like was embedded lens corrections for mirrorless cameras.  Are the Olympus and Panasonic mirrorless—meaning there is no optical viewfinder and everything is seen on an LCD screen or perhaps an electronic view finder?  If so the reason these are different is that the camera is doing the lens distortion corrections automatically and this information is stored in the raw files and in the DNGs but Apple doesn’t know how to use these embedded lens corrections or doesn’t know how to read the newer DNG spec that does allow for this information to be embedded in the DNG, at least.
    Apple could just extract the embedded jpg preview and ignore the other parts of the file it doesn’t understand, but it apparently doesn’t do this.
    What I’m not sure about is if the Apple raw interpreter still has this problem or if you’re on an older system without the latest updates for camera raw decoding by Apple.

Maybe you are looking for

  • How to place an image in database and how to retrieve and display it in the front end

    how to place an image in database and how to retrieve and display it in the front end and to place an image in database and retrieve the image from database using xml please,help me out.

  • IN BOM the Weight and Volume Update from the Parent item when Change Itemca

    Hi  Guru we are facing problem when we create SO for Configuration material, By Default all the weight and Volume Flow Proparlly form Material Master for all Parent and Child item  but when we change the item Categries for Child item the weight is co

  • Not all of my bookmarks are coming thru

    Not all of my bookmarks are coming into my iPhone from my PC via the Firefox server. Only one folder of my bookmarks is coming in. Never had this problem before. Other sync instructions in Preferences can be changed and are properly executed (tabs vs

  • Maximum attachment size in utl_mail.send_attach_raw

    Hi All, Oracle 10.2.0 Linux 2.6.9 EL We are using utl_mail package to send mails from oracle server. Now i tried to send a mail with the attachment of size 105 K. But i got an error like ERROR at line 1: ORA-03113: end-of-file on communication channe

  • N8 Unable to play media clip from micro SD

    Hi All, I've seen this about a couple of places but there don't seem to be any solutions out there. I've got a 32gb micro SD card in the N8. Everything seemed fine to start with, but after the first 3 videos I watched now if I try to play videos off