<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808774#M1007942</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please add your config to the conversation so I can check it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Franco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Apr 2007 13:54:45 GMT</pubDate>
    <dc:creator>fzamora</dc:creator>
    <dc:date>2007-04-10T13:54:45Z</dc:date>
    <item>
      <title>NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808771#M1007936</link>
      <description>&lt;P&gt;i have next config for pix515e-&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 branches security50&lt;/P&gt;&lt;P&gt;global (outside) 2 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list vpn_outside_1&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (branches) 2 10.20.18.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tryed to ping public address from network 10.20.18.0 and i see not NATed packets at the outside interface-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- PACKET ---------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- IP --&lt;/P&gt;&lt;P&gt;10.20.18.3      ==&amp;gt;     1.1.119.28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x64&lt;/P&gt;&lt;P&gt;        id = 0x239      flags = 0x0     frag off=0x0&lt;/P&gt;&lt;P&gt;        ttl = 0xfb      proto=0x1       chksum = 0x547b&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        -- ICMP --&lt;/P&gt;&lt;P&gt;                type = 0x8      code = 0x0      checksum=0x2f9e&lt;/P&gt;&lt;P&gt;                identifier = 0x22       seq = 0x1&lt;/P&gt;&lt;P&gt;        -- DATA --&lt;/P&gt;&lt;P&gt;                00000010:                                     00 00 00 00  |              ....&lt;/P&gt;&lt;P&gt;                00000020: 5c 33 f2 55 ab cd ab cd ab cd ab cd ab cd ab cd  |  \3.U............&lt;/P&gt;&lt;P&gt;                00000030: ab cd ab cd ab cd ab cd ab cd ab cd ab cd ab cd  |  ................&lt;/P&gt;&lt;P&gt;                00000040: ab cd ab cd ab cd ab cd ab cd ab cd ab cd ab cd  |  ................&lt;/P&gt;&lt;P&gt;                00000050: ab cd ab cd ab cd ab cd ab cd ab cd ab cd ab cd  |  ................&lt;/P&gt;&lt;P&gt;                00000060: ab cd ab cd 03                                   |  .....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- END OF PACKET ---------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i do the same from PIX - it's ok-&lt;/P&gt;&lt;P&gt;--------- PACKET ---------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- IP --&lt;/P&gt;&lt;P&gt;Public_address_VPNgate   ==&amp;gt;     1.1.119.28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x3c&lt;/P&gt;&lt;P&gt;        id = 0xa407     flags = 0x0     frag off=0x0&lt;/P&gt;&lt;P&gt;        ttl = 0xff      proto=0x1       chksum = 0x8629&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        -- ICMP --&lt;/P&gt;&lt;P&gt;                type = 0x8      code = 0x0      checksum=0xf5d8&lt;/P&gt;&lt;P&gt;                identifier = 0x1124     seq = 0x2&lt;/P&gt;&lt;P&gt;        -- DATA --&lt;/P&gt;&lt;P&gt;                00000018:             00 01 02 03 04 05 06 07 08 09 0a 0b  |      ............&lt;/P&gt;&lt;P&gt;                00000028: 0c 0d 0e 0f 10 11 12 13 14 15 16 17 18 19 1a 1b  |  ................&lt;/P&gt;&lt;P&gt;                00000038: 1c 1d 1e 1f 18                                   |  .....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- END OF PACKET ---------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where is a problem?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808771#M1007936</guid>
      <dc:creator>rmv72</dc:creator>
      <dc:date>2019-03-11T09:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808772#M1007939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you add the access list in order to permit the incoming ICMP traffic on the outside interface? If you can ping from the PIX that means it has connectivity so one of the first things one needs to check is the ACL. Please add the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inbound permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inbound in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you already added it, please let me know so we can continue with the troubleshooting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Franco Zamora&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2007 03:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808772#M1007939</guid>
      <dc:creator>fzamora</dc:creator>
      <dc:date>2007-04-10T03:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808773#M1007941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;yes,i've ACL.&lt;/P&gt;&lt;P&gt;i think the problem is that packets goes from outside interface with private source (which is certainly is not routed in public internet &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ).&lt;/P&gt;&lt;P&gt;Seems they don't NATed - maybe here problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2007 05:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808773#M1007941</guid>
      <dc:creator>rmv72</dc:creator>
      <dc:date>2007-04-10T05:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808774#M1007942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please add your config to the conversation so I can check it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Franco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2007 13:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808774#M1007942</guid>
      <dc:creator>fzamora</dc:creator>
      <dc:date>2007-04-10T13:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808775#M1007943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2007 08:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808775#M1007943</guid>
      <dc:creator>rmv72</dc:creator>
      <dc:date>2007-04-11T08:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808776#M1007944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take out...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Save with: write mem and also issue: clear xlate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2007 11:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808776#M1007944</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2007-04-11T11:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808777#M1007945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i've it already&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2007 11:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808777#M1007945</guid>
      <dc:creator>rmv72</dc:creator>
      <dc:date>2007-04-11T11:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808778#M1007946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2007 16:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808778#M1007946</guid>
      <dc:creator>jbeltrame</dc:creator>
      <dc:date>2007-04-11T16:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT question</title>
      <link>https://community.cisco.com/t5/network-security/nat-question/m-p/808779#M1007947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i've done it.&lt;/P&gt;&lt;P&gt;same problem.&lt;/P&gt;&lt;P&gt;from network 10.20.18.0/24-&lt;/P&gt;&lt;P&gt;debug packet outside dst A.177.119.28 netmask 255.255.255.255  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping from network 10.20.18.0/24&lt;/P&gt;&lt;P&gt;-- IP --&lt;/P&gt;&lt;P&gt;10.20.18.3      ==&amp;gt;     A.177.119.28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x64&lt;/P&gt;&lt;P&gt;        id = 0x2aa      flags = 0x0     frag off=0x0&lt;/P&gt;&lt;P&gt;        ttl = 0xfb      proto=0x1       chksum = 0x540a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        -- ICMP --&lt;/P&gt;&lt;P&gt;                type = 0x8      code = 0x0      checksum=0x41e9&lt;/P&gt;&lt;P&gt;                identifier = 0x25       seq = 0x8&lt;/P&gt;&lt;P&gt;        -- DATA --&lt;/P&gt;&lt;P&gt;                00000010:                                     00 00 00 00  |              ....&lt;/P&gt;&lt;P&gt;                00000020: 6a 3d d1 f6 ab cd ab cd ab cd ab cd ab cd ab cd  |  j=..............&lt;/P&gt;&lt;P&gt;                00000030: ab cd ab cd ab cd ab cd ab cd ab cd ab cd ab cd  |  ................&lt;/P&gt;&lt;P&gt;                00000040: ab cd ab cd ab cd ab cd ab cd ab cd ab cd ab cd  |  ................&lt;/P&gt;&lt;P&gt;                00000050: ab cd ab cd ab cd ab cd ab cd ab cd ab cd ab cd  |  ................&lt;/P&gt;&lt;P&gt;                00000060: ab cd ab cd 6e                                   |  ....n&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- END OF PACKET ---------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping from PIX-&lt;/P&gt;&lt;P&gt;PIX2# ping A.177.119.28&lt;/P&gt;&lt;P&gt;--------- PACKET ---------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- IP --&lt;/P&gt;&lt;P&gt;VPNgate (ip address of outside interface)   ==&amp;gt;     A.177.119.28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x3c&lt;/P&gt;&lt;P&gt;        id = 0x642d     flags = 0x0     frag off=0x0&lt;/P&gt;&lt;P&gt;        ttl = 0xff      proto=0x1       chksum = 0xc603&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;        -- ICMP --&lt;/P&gt;&lt;P&gt;                type = 0x8      code = 0x0      checksum=0xf5da&lt;/P&gt;&lt;P&gt;                identifier = 0x1124     seq = 0x0&lt;/P&gt;&lt;P&gt;        -- DATA --&lt;/P&gt;&lt;P&gt;                00000018:             00 01 02 03 04 05 06 07 08 09 0a 0b  |      ............&lt;/P&gt;&lt;P&gt;                00000028: 0c 0d 0e 0f 10 11 12 13 14 15 16 17 18 19 1a 1b  |  ................&lt;/P&gt;&lt;P&gt;                00000038: 1c 1d 1e 1f 59                                   |  ....Y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------- END OF PACKET ---------&lt;/P&gt;&lt;P&gt;but i want to say that packets from network 10.20.18.0/24 comes to interface branches, not inside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2007 04:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-question/m-p/808779#M1007947</guid>
      <dc:creator>rmv72</dc:creator>
      <dc:date>2007-04-12T04:40:15Z</dc:date>
    </item>
  </channel>
</rss>

