<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA policy-nat is working but acl is not hit in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-policy-nat-is-working-but-acl-is-not-hit/m-p/2105534#M161681</link>
    <description>&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Hope you guys can help explain why is it working this strange. Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;access-list NET1 permit ip host 10.1.2.27 10.76.5.0 255.255.255.224&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;static (inside,outside) 192.168.100.100 access-list NET1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show access-list &lt;/P&gt;&lt;P&gt;access-list NET1 line 1 extended permit ip host 10.1.2.27 10.76.5.0 255.255.255.224 (hitcnt=0) 0x19580e75 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show xlate&lt;/P&gt;&lt;P&gt;3 in use, 4 most used&lt;/P&gt;&lt;P&gt;Global 192.168.100.100 Local 10.1.2.27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show nat&lt;/P&gt;&lt;P&gt;NAT policies on Interface inside:&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 10.1.2.27 255.255.255.255 outside 10.76.5.0 255.255.255.224&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 192.168.100.100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 9, untranslate_hits = 28&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:57:00 GMT</pubDate>
    <dc:creator>sok_senmonorom</dc:creator>
    <dc:date>2019-03-11T02:57:00Z</dc:date>
    <item>
      <title>ASA policy-nat is working but acl is not hit</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-policy-nat-is-working-but-acl-is-not-hit/m-p/2105534#M161681</link>
      <description>&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Hope you guys can help explain why is it working this strange. Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;access-list NET1 permit ip host 10.1.2.27 10.76.5.0 255.255.255.224&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;static (inside,outside) 192.168.100.100 access-list NET1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show access-list &lt;/P&gt;&lt;P&gt;access-list NET1 line 1 extended permit ip host 10.1.2.27 10.76.5.0 255.255.255.224 (hitcnt=0) 0x19580e75 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show xlate&lt;/P&gt;&lt;P&gt;3 in use, 4 most used&lt;/P&gt;&lt;P&gt;Global 192.168.100.100 Local 10.1.2.27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show nat&lt;/P&gt;&lt;P&gt;NAT policies on Interface inside:&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 10.1.2.27 255.255.255.255 outside 10.76.5.0 255.255.255.224&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 192.168.100.100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 9, untranslate_hits = 28&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-policy-nat-is-working-but-acl-is-not-hit/m-p/2105534#M161681</guid>
      <dc:creator>sok_senmonorom</dc:creator>
      <dc:date>2019-03-11T02:57:00Z</dc:date>
    </item>
    <item>
      <title>ASA policy-nat is working but acl is not hit</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-policy-nat-is-working-but-acl-is-not-hit/m-p/2105535#M161702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems as if this is the behavior with access lists that are associated with NAT. I did a few checks around the support forums and found that this could be the issue and there isnt anything to worry about. However if you can move this thread to the firewalling community I am sure they will be able to confirm this for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 16:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-policy-nat-is-working-but-acl-is-not-hit/m-p/2105535#M161702</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-08T16:15:26Z</dc:date>
    </item>
  </channel>
</rss>

