<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing priority of Static NAT over NAT exempt rule in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/changing-priority-of-static-nat-over-nat-exempt-rule/m-p/3217376#M1042644</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;Here an explain on how may is processed on asa:&lt;BR /&gt;&lt;A href="https://supportforums.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050" target="_blank"&gt;https://supportforums.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Can you share your config and give us the source ip and destination ip? With that information we'll be able to help you.&lt;BR /&gt;</description>
    <pubDate>Thu, 16 Nov 2017 03:55:48 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2017-11-16T03:55:48Z</dc:date>
    <item>
      <title>Changing priority of Static NAT over NAT exempt rule</title>
      <link>https://community.cisco.com/t5/network-security/changing-priority-of-static-nat-over-nat-exempt-rule/m-p/3217266#M1042642</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Suppose we have two NAT rules under 'NAT Rules';&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Original (Source)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Original (Destination)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface (Translated) &amp;nbsp; &amp;nbsp; Address(Translated)&lt;/P&gt;
&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp; Exempt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ANY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ANY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outbound&lt;BR /&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp; Static&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Web_internal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ANY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside (Web_external)&lt;/P&gt;
&lt;P&gt;Firewall accept inbound access to the external IP address (Statically NATed) of Web_external however I'm seeing asymmetric routing issue on ASA log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Asymmetric NAT rules matched for forward and reverse flows- denied due to NAT reverse path failure.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see NAT exemption rule (#1) is overwritting statc NAT for the outbound.&lt;BR /&gt;Is there any way we could put the highest priority on Static NAT over NAT exemption rule?&lt;/P&gt;
&lt;P&gt;There is up/down arrow for both NAT exemption and static rule but static rule can not go above the NAT exemption rule. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-priority-of-static-nat-over-nat-exempt-rule/m-p/3217266#M1042642</guid>
      <dc:creator>jon.seung@applecaremedical.com</dc:creator>
      <dc:date>2020-02-21T14:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Changing priority of Static NAT over NAT exempt rule</title>
      <link>https://community.cisco.com/t5/network-security/changing-priority-of-static-nat-over-nat-exempt-rule/m-p/3217376#M1042644</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Here an explain on how may is processed on asa:&lt;BR /&gt;&lt;A href="https://supportforums.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050" target="_blank"&gt;https://supportforums.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Can you share your config and give us the source ip and destination ip? With that information we'll be able to help you.&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Nov 2017 03:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-priority-of-static-nat-over-nat-exempt-rule/m-p/3217376#M1042644</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-11-16T03:55:48Z</dc:date>
    </item>
  </channel>
</rss>

