<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA NATing doesn't seem to work in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094403#M1070562</link>
    <description>&lt;P&gt;Could you please provide the output of the following commands:&lt;/P&gt;
&lt;P&gt;show run nat | include CD-BFS-NORTH&lt;/P&gt;
&lt;P&gt;show run access-list | include CD-BFS-NORTH&amp;nbsp; !(If you are using IPs instead of objects replace with IP)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, provide a brief description / diagram of your network and where the IPs are located that you are trying to NAT.&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2020 14:30:42 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2020-05-29T14:30:42Z</dc:date>
    <item>
      <title>ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4092821#M1070509</link>
      <description>&lt;P&gt;i have ASA 5510 firewall and Fortigate is connected to vlan interface in ASA. I have public IP address NATed (object NAT) to the outside interface of the Fortigate. the NAT doesn't seems to work, I see the traffic hitting the public IP address but not the outside interface of the Fortigate. any suggestions ?&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 13:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4092821#M1070509</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-27T13:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4093094#M1070519</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you post your NAT and routing configuration.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 21:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4093094#M1070519</guid>
      <dc:creator>Aileron88</dc:creator>
      <dc:date>2020-05-27T21:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4093430#M1070520</link>
      <description>&lt;P&gt;thanks for the reply, please find attached the config, I have changed the original IP addresses.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 09:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4093430#M1070520</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-28T09:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4093876#M1070534</link>
      <description>&lt;P&gt;If the following is correct:&amp;nbsp;* the rules on the outside interface to allow traffic from any to Fortigate-IP on ICMP,http, https&lt;/P&gt;
&lt;P&gt;Then this is the issue.&amp;nbsp; You need to change this access rule to be towards CD-BFS-NORTH.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 20:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4093876#M1070534</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-28T20:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094209#M1070544</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;that's why I called my enquiry "ASA NATing doesn't seem to work".&lt;/P&gt;&lt;P&gt;when I change the destination in the rule to&amp;nbsp;CD-BFS-NORTH , the traffic denied by ACL.&lt;/P&gt;&lt;P&gt;I have attached packet tracer for the rules when the destination&amp;nbsp;&lt;SPAN&gt;CD-BFS-NORTH&lt;/SPAN&gt; and&amp;nbsp;Fortigate-IP.&lt;/P&gt;&lt;P&gt;my understanding that the ASA should first check the NAT before the interface ACL , but that doesn't seem to happen.&lt;/P&gt;&lt;P&gt;Can someone advise ?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 08:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094209#M1070544</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-29T08:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094237#M1070546</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version of ASA code are you running?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 09:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094237#M1070546</guid>
      <dc:creator>Aileron88</dc:creator>
      <dc:date>2020-05-29T09:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094254#M1070547</link>
      <description>&lt;P&gt;its&amp;nbsp;9.1(7)13&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 10:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094254#M1070547</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-29T10:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094295#M1070548</link>
      <description>&lt;P&gt;Is there a reason you are using twice NAT for this? Also, it is always a good practice to specify which interfaces you are NATing between and do not use the any keyword for interface selection.&amp;nbsp; I would suggest changing the NAT to something like the following (change the interface names if needed):&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (INSIDE,OUTSIDE) source static&amp;nbsp;CD-BFS-NORTH&amp;nbsp;Fortigate-IP&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 11:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094295#M1070548</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-29T11:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094302#M1070550</link>
      <description>&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;thanks so much for the reply&lt;/P&gt;&lt;P&gt;there is no particular reason to do the twice NAT , I was just trying everything to make it&amp;nbsp; work.&lt;/P&gt;&lt;P&gt;the command line you have suggested is already there:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(EPL_VPN) to (OUTSIDE) source static CD-BFS-NORTH Fortigate-IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 11:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094302#M1070550</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-29T11:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094340#M1070555</link>
      <description>&lt;P&gt;Could you post a full running configuration for your ASA (remember to remove any public IPs, usernames and passwords).&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 12:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094340#M1070555</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-29T12:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094344#M1070556</link>
      <description>&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;thanks for you help so far&lt;/P&gt;&lt;P&gt;this firewall is old one and the configuration file is very big, hiding all the secure info will take long time, I am more than happy to share the config partially, like show run interface , show run nat ..etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 12:55:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094344#M1070556</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-29T12:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094381#M1070560</link>
      <description>&lt;P&gt;Without seeing more config it's hard to 100% diagnose but it just looks like you have your NAT commands around the wrong way, because you're stating outside&amp;gt;any and not the other way around. I would suggest removing the twice NAT and just adding a rule for this server such as the one you've already mentioned, assuming that the Fortigate is behind the EVL_VPN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(EPL_VPN) to (OUTSIDE) source static CD-BFS-NORTH Fortigate-IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run packet-tracer again and see if this NAT rule is hit. If you want to try it another way try changing your other rule around:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;42 (OUTSIDE) to (&amp;lt;ZONE THAT CONTAINS FORTIGATE&amp;gt;) source static any any destination static CD-BFS-NORTH Fortigate-IP no-proxy-arp&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 13:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094381#M1070560</guid>
      <dc:creator>Aileron88</dc:creator>
      <dc:date>2020-05-29T13:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094403#M1070562</link>
      <description>&lt;P&gt;Could you please provide the output of the following commands:&lt;/P&gt;
&lt;P&gt;show run nat | include CD-BFS-NORTH&lt;/P&gt;
&lt;P&gt;show run access-list | include CD-BFS-NORTH&amp;nbsp; !(If you are using IPs instead of objects replace with IP)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, provide a brief description / diagram of your network and where the IPs are located that you are trying to NAT.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 14:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094403#M1070562</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-29T14:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094427#M1070564</link>
      <description>&lt;P&gt;Hi Both,&lt;/P&gt;&lt;P&gt;I have deleted the double Nating , and added&amp;nbsp;CD-BFS-NORTH instead of&amp;nbsp;Fortigate-IP in the rules, the firewall is denying the traffic.&lt;/P&gt;&lt;P&gt;please find attached the commands output and a little diagram&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your efforts to help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 14:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094427#M1070564</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-29T14:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094487#M1070573</link>
      <description>&lt;P&gt;You still have twice NAT configured...unless this is the one you have removed.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (OUTSIDE,any) source static any any destination static Fortigate-IP CD-BFS-NORTH object network CD-BFS-NORTHW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I suggest removing this and replacing it with the command I provided earlier.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (EPL_VPN,OUTSIDE) source static CD-BFS-NORTH&amp;nbsp;Fortigate-IP&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It is a better practice to NAT from the inside to the outside unless there is a very specific reason for you to NAT from the outside.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 16:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4094487#M1070573</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-29T16:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095066#M1070610</link>
      <description>&lt;P&gt;thanks for your help.&lt;/P&gt;&lt;P&gt;still getting the same issue. please find below the out put of packet tracer after removing the twice NAT:&lt;/P&gt;&lt;P&gt;-FW01/pri/act# show run nat | include CD-BFS-NORTH&lt;BR /&gt;object network CD-BFS-NORTH&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW01/pri/act# show nat | include CD-BFS-NORTH&lt;BR /&gt;1 (EPL_VPN) to (OUTSIDE) source static CD-BFS-NORTH Fortigate-IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW01/pri/act# show access-list | i CD-BFS-NORTH&lt;BR /&gt;access-list OUTSIDE_INGRESS line 27 extended permit object-group DM_INLINE_SERVICE_11 any object CD-BFS-NORTH log informational interval 300 (hitcnt=0) 0x070a3eba&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CD-24LH-FW01/pri/act# packet-tracer input ouTSIDE icmp 92.239.10.100 8 0 80.10.10.51&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 80.10.10.48 255.255.255.248 OUTSIDE&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;access-group OUTSIDE_INGRESS in interface OUTSIDE&lt;BR /&gt;access-list OUTSIDE_INGRESS extended deny ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: OUTSIDE&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: OUTSIDE&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its looks like that translation happening in one direction, not sure why&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 11:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095066#M1070610</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-31T11:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095095#M1070613</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;What protocols are you allowing in your ACL?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;sh run object-group id&amp;nbsp;&lt;SPAN&gt;DM_INLINE_SERVICE_11&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 14:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095095#M1070613</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-31T14:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095097#M1070614</link>
      <description>&lt;P&gt;ICMP, HTTP, HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW01/pri/act# sh run object-group id DM_INLINE_SERVICE_11&lt;BR /&gt;object-group service DM_INLINE_SERVICE_11&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object tcp-udp destination eq www&lt;BR /&gt;service-object tcp destination eq https&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 14:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095097#M1070614</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-05-31T14:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NATing doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095403#M1070625</link>
      <description>&lt;P&gt;sorted,&lt;/P&gt;&lt;P&gt;just re-added the NAT statement at the top of the all NAT rules and its worked.&lt;/P&gt;&lt;P&gt;1 (OUTSIDE) to (any) source static any any destination static Fortigate-IP CD-BFS-NORTHW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks all for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 11:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nating-doesn-t-seem-to-work/m-p/4095403#M1070625</guid>
      <dc:creator>mazin D</dc:creator>
      <dc:date>2020-06-01T11:25:14Z</dc:date>
    </item>
  </channel>
</rss>

