<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Translation issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707362#M1022833</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the logs. Please try using these commands-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list nonat deny tcp any host 10.1.96.2 eq 80&lt;/P&gt;&lt;P&gt;no access-list nonat permit ip any any&lt;/P&gt;&lt;P&gt;no nat (outside) 0 access-list nonat outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat (outside) 1 access-list policy-nat outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonat deny ip any host 10.1.96.2&lt;/P&gt;&lt;P&gt;access-list nonat permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 access-list policy-nat outside &lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list nonat outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Mar 2007 04:41:29 GMT</pubDate>
    <dc:creator>vitripat</dc:creator>
    <dc:date>2007-03-27T04:41:29Z</dc:date>
    <item>
      <title>Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707357#M1022828</link>
      <description>&lt;P&gt;I seem to have stumbled on an issue in our test environment. Please see explanation below and relevant lines of the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a PIX that is using 2 interfaces, inside and outside, no DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network outside of the PIX is 10.1.0.0/16. The network inside the PIX is 172.16.15.0/27.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Behind the PIX is a web server. NAT is configured so that HTTP traffic to the web server which is directed at its external ip address (10.1.96.2), is port redirected to its real ip address on the inside (172.16.15.30). This is achieved using static NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web server needs to initiate outbound traffic. In this example I have configured it to be able to do DNS lookups on external servers (10.1.15.98 + 99). The "inside" access-list and nat/global pair achieve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK so far. For arguments sake the web server needs to receive HTTP traffic from the same source IP address. I have achieved this using outside NAT with another nat/global pair. All inbound HTTP requests appear to the web server as 192.168.0.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is when the problem occurs. The inbound HTTP requests still succeed. The destination IP address is changed to the web servers real IP address and the source IP address is changed to the address configured with the inside global. This has been verified by entries in the web server logs.&lt;/P&gt;&lt;P&gt;What now fails to work is any outbound requests. The error I see on the PIX is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"No translation group found for udp src inside:172.16.15.30/1340 dst outside:10.1.15.99/53"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am puzzled as this message normally appears when NAT has not been configured yet it has been and has worked up until this point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 10.1.96.2 eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside deny ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list policy-nat permit tcp any host 10.1.96.2 eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.15.30 host 10.1.15.98 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.15.30 host 10.1.15.99 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit udp host 172.16.15.30 host 10.1.15.99 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit udp host 172.16.15.30 host 10.1.15.98 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 10.1.96.1 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address inside 172.16.15.1 255.255.255.224&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 2 10.1.96.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 192.168.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 access-list policy-nat outside 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.15.30 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 10.1.96.2 www 172.16.15.30 www netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;             &lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707357#M1022828</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2019-03-11T09:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707358#M1022829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a known problem when using outside nat. Please try implementing following commands and check if this resolves the issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat (outside) 1 access-list policy-nat outside &lt;/P&gt;&lt;P&gt;no global (inside) 1 192.168.0.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonat deny tcp any host 10.1.96.2 eq 80&lt;/P&gt;&lt;P&gt;access-list nonat permit ip any any&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list nonat outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 access-list policy-nat outside &lt;/P&gt;&lt;P&gt;global (inside) 1 192.168.0.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps in resolving your issue. I'll be glad to explain once things work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2007 15:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707358#M1022829</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-22T15:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707359#M1022830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vibhor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the information. I have run the commands that you have suggested. I can now initiate outbound traffic. However the outside NAT does not work so the source IP address of a machine on the outside making an HTTP request is received by the web server unchanged.&lt;/P&gt;&lt;P&gt;The point of doing this was so that all requests appear to the web server with the same IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2007 17:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707359#M1022830</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2007-03-22T17:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707360#M1022831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats wierd, if you have syslogs, could you pass them on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Mar 2007 16:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707360#M1022831</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-24T16:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707361#M1022832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vibhor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing in the syslogs really - see below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;305011: Built static TCP translation from inside:172.16.15.30/80 to outside:10.1.96.2/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;302013: Built inbound TCP connection 38 for outside:10.1.102.60/1701 (10.1.102.60/1701) to inside:172.16.15.30/80 (10.1.96.2/80)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;304001: 10.1.102.60 Accessed URL 10.1.96.2:/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Web Logs are consistent with the above:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Date: 2007-03-26 08:39:57&lt;/P&gt;&lt;P&gt;#Fields: time c-ip s-ip s-port cs-method cs-uri-stem sc-status &lt;/P&gt;&lt;P&gt;08:39:57 10.1.102.60 172.16.15.30 80 GET /Default.htm 200&lt;/P&gt;&lt;P&gt;08:40:42 10.1.102.60 172.16.15.30 80 GET /Default.htm 304&lt;/P&gt;&lt;P&gt;08:41:32 10.1.102.60 172.16.15.30 80 GET /Default.htm 304&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2007 08:56:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707361#M1022832</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2007-03-26T08:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707362#M1022833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the logs. Please try using these commands-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list nonat deny tcp any host 10.1.96.2 eq 80&lt;/P&gt;&lt;P&gt;no access-list nonat permit ip any any&lt;/P&gt;&lt;P&gt;no nat (outside) 0 access-list nonat outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat (outside) 1 access-list policy-nat outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonat deny ip any host 10.1.96.2&lt;/P&gt;&lt;P&gt;access-list nonat permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 access-list policy-nat outside &lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list nonat outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 04:41:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707362#M1022833</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-27T04:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707363#M1022834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vibhor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the info. Unfortunately this just results in the same - traffic flows inbound and outbound but the outside nat fails to work anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see a cut down of the configuration to verify:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 10.1.96.2 eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside deny ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list policy-nat permit tcp any host 10.1.96.2 eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.15.30 host 10.1.15.98 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit tcp host 172.16.15.30 host 10.1.15.99 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit udp host 172.16.15.30 host 10.1.15.99 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside permit udp host 172.16.15.30 host 10.1.15.98 eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonat deny ip any host 10.1.96.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonat permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 10.1.96.1 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address inside 172.16.15.1 255.255.255.224&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 2 10.1.96.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 192.168.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list nonat outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside) 1 access-list policy-nat outside 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.15.30 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 10.1.96.2 www 172.16.15.30 www netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 09:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707363#M1022834</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2007-03-27T09:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707364#M1022835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Gary,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the latest snippet of config, I was looking for that. Now this is not good. The configuration is perfect and things should work. Could you tell me what version is running on PIX? I'm afraid that we may be looking into a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 01:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707364#M1022835</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-28T01:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Translation issue</title>
      <link>https://community.cisco.com/t5/network-security/translation-issue/m-p/707365#M1022836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vibhor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running 6.3(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 08:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-issue/m-p/707365#M1022836</guid>
      <dc:creator>g.leonard</dc:creator>
      <dc:date>2007-03-28T08:25:31Z</dc:date>
    </item>
  </channel>
</rss>

