<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisca ASA NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145954#M1073567</link>
    <description>&lt;P&gt;The output seems to confirm an &lt;STRONG&gt;rpf-check&lt;/STRONG&gt; failure.&lt;/P&gt;
&lt;P&gt;Run a capture, e.g. &lt;STRONG&gt;capture CAP type asp-drop nat-rpf-failed &lt;/STRONG&gt;test again and then provide the output of the capture.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2020 17:55:24 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2020-09-03T17:55:24Z</dc:date>
    <item>
      <title>Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145944#M1073564</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326229"&gt;@Richard Burts&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal IP address:&amp;nbsp; 10.150.170.72&amp;nbsp;&lt;/P&gt;&lt;P&gt;External IP: x.x.x.x&lt;/P&gt;&lt;P&gt;I am trying to map&amp;nbsp; External IP to Internal IP over port 587.&amp;nbsp; Please advice which commands I need ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried following commands:&lt;/P&gt;&lt;P&gt;object network obj_10.170.150.72&lt;BR /&gt;host 10.170.150.72&lt;BR /&gt;nat (inside,outside) static x.x.x.x service 587 587&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It came with error message:&lt;/P&gt;&lt;P&gt;TMGHQ5516(config-network-object)# nat (inside,outside) static x.x.x.x ser$&lt;BR /&gt;ERROR: Address x.x.x.x overlaps with outside interface address.&lt;BR /&gt;ERROR: NAT Policy is not downloaded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 17:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145944#M1073564</guid>
      <dc:creator>LovejitSingh1313</dc:creator>
      <dc:date>2020-09-03T17:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145948#M1073565</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Seems like you are natting to the outside interface, replace X.X.X.X with the value "interface". e.g&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nat (INSIDE,OUTSIDE) static &lt;STRONG&gt;interface&lt;/STRONG&gt; service tcp 587 587&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 17:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145948#M1073565</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-03T17:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145951#M1073566</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added that and it does not came back with error message.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i run the packet tracer, it is still coming with error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TMGHQ5516(config)# packet-tracer input outside tcp 8.8.8.8 587 10.170.150.72 5$&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.170.150.72 using egress ifc inside&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-list outside_access_in extended permit ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network obj_10.170.150.72&lt;BR /&gt;nat (inside,outside) static interface service tcp 587 587&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x00005584a16ce44a flow (nat-rpf-failed)/snp_sp_action_cb:1140&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 17:46:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145951#M1073566</guid>
      <dc:creator>LovejitSingh1313</dc:creator>
      <dc:date>2020-09-03T17:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145954#M1073567</link>
      <description>&lt;P&gt;The output seems to confirm an &lt;STRONG&gt;rpf-check&lt;/STRONG&gt; failure.&lt;/P&gt;
&lt;P&gt;Run a capture, e.g. &lt;STRONG&gt;capture CAP type asp-drop nat-rpf-failed &lt;/STRONG&gt;test again and then provide the output of the capture.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 17:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145954#M1073567</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-03T17:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145955#M1073568</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TMGHQ5516(config)# show capture CAP&lt;BR /&gt;Target: OTHER&lt;BR /&gt;Hardware: ASA5516&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.13(1)&lt;BR /&gt;ASLR enabled, text region 55849fa29000-5584a4402d25&lt;/P&gt;&lt;P&gt;0 packet captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;BR /&gt;TMGHQ5516(config)#&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 18:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145955#M1073568</guid>
      <dc:creator>LovejitSingh1313</dc:creator>
      <dc:date>2020-09-03T18:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145983#M1073570</link>
      <description>&lt;P&gt;Change the destination of the packet-tracert to the global ip address (natted) and try it again. Better still generate real traffic&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 18:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145983#M1073570</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-03T18:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145987#M1073571</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read this Article and I tested creating session 587 from Internet and it is working. All good now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0000904" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0000904&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 18:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145987#M1073571</guid>
      <dc:creator>LovejitSingh1313</dc:creator>
      <dc:date>2020-09-03T18:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisca ASA NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145992#M1073572</link>
      <description>&lt;P&gt;Correct, you run packet-tracer from outside to inside using the outside interface IP address (public) as the destination rather than the real IP address - that's what I meant by my last post by specifiying the global IP address (natted).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Glad it's working now.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 18:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisca-asa-nat/m-p/4145992#M1073572</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-03T18:37:17Z</dc:date>
    </item>
  </channel>
</rss>

