<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cant get NAT Loopback working (access FTP on outside IP from inside) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189266#M1076154</link>
    <description>&lt;P&gt;You can add the dns keyword to the end of the NAT statement.&amp;nbsp; When DNS replies enter the ASA for lookups to the FTP server the ASA checks the NAT table to see if there are any entries that match the public IP.&amp;nbsp; If it finds a NAT statement and the DNS keyword is added, the public IP will be re-written to the private IP and then the client can access the server using the private IP.&amp;nbsp; Remember that this will require an access list entry allowing access to the private IP if the client and the FTP server are located off of separate interfaces on the ASA.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2020 13:25:13 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2020-11-26T13:25:13Z</dc:date>
    <item>
      <title>Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189237#M1076151</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some issues to make nat loopback. How do i do that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets say i have local FTP server: 192.168.2.200&lt;/P&gt;&lt;P&gt;I can access that local, and through my NAT from outside: 92.55.67.12.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if im on my local network 192.168.2.x/24, i cant access FTP on&amp;nbsp;92.55.67.12, because i need nat loopback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running ASA software on firepower 1010.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to solve?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 12:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189237#M1076151</guid>
      <dc:creator>Kortermann-IT ApS</dc:creator>
      <dc:date>2020-11-26T12:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189239#M1076152</link>
      <description>&lt;P&gt;NAT, cisco, firewall, firepower, Cisco Adaptive Security Appliance (ASA)&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 12:31:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189239#M1076152</guid>
      <dc:creator>Kortermann-IT ApS</dc:creator>
      <dc:date>2020-11-26T12:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189266#M1076154</link>
      <description>&lt;P&gt;You can add the dns keyword to the end of the NAT statement.&amp;nbsp; When DNS replies enter the ASA for lookups to the FTP server the ASA checks the NAT table to see if there are any entries that match the public IP.&amp;nbsp; If it finds a NAT statement and the DNS keyword is added, the public IP will be re-written to the private IP and then the client can access the server using the private IP.&amp;nbsp; Remember that this will require an access list entry allowing access to the private IP if the client and the FTP server are located off of separate interfaces on the ASA.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 13:25:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189266#M1076154</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-26T13:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189281#M1076155</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you maybe help with a command?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 13:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189281#M1076155</guid>
      <dc:creator>Kortermann-IT ApS</dc:creator>
      <dc:date>2020-11-26T13:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189335#M1076158</link>
      <description>&lt;P&gt;object network FTP_SERVER&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host&amp;nbsp;&lt;SPAN&gt;192.168.2.200&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;nat (inside,outside) static&amp;nbsp;92.55.67.12 dns&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 15:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189335#M1076158</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-26T15:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189555#M1076171</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got this error:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result of the command: "object network FTP_SERVER"&lt;/P&gt;&lt;P&gt;The command has been sent to the device&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Result of the command: "host 192.168.11.219"&lt;/P&gt;&lt;P&gt;The command has been sent to the device&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Result of the command: "nat (inside,outside) static 212.98.71.90 dns"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Address 212.98.71.90 overlaps with outside interface address.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ERROR: NAT Policy is not downloaded&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 07:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189555#M1076171</guid>
      <dc:creator>Kortermann-IT ApS</dc:creator>
      <dc:date>2020-11-27T07:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189575#M1076174</link>
      <description>&lt;P&gt;If you are using the outside interface IP then you need to use the interface keyword instead of the IP address.&amp;nbsp; Be careful when doing this though as you will break all other internet traffic other than the FTP server if using the same IP for internet traffic.&amp;nbsp; If you do not have a spare IP and you have other devices that need access to the internet your best bet would be to use twice nat.&lt;/P&gt;
&lt;P&gt;for example (I would recommend replace the any any with object groups for your local lan or host that is to access the FTP server)&lt;/P&gt;
&lt;P&gt;object network FTP_SERVER&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host&amp;nbsp;&lt;SPAN&gt;192.168.2.200&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (inside,inside) source static any any destination static interface FTP_SERVER&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 08:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189575#M1076174</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-27T08:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189597#M1076178</link>
      <description>&lt;P&gt;How should the any any be?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have all my clients on 192.168.11.0/24.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FTP server: 192.168.11.219&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Public IP: 212.98.71.90&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 09:28:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189597#M1076178</guid>
      <dc:creator>Kortermann-IT ApS</dc:creator>
      <dc:date>2020-11-27T09:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189609#M1076180</link>
      <description>&lt;P&gt;Im using this rule today:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network VM-RDS-01&lt;BR /&gt;nat (inside,outside) static interface service tcp 3389 3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is working from outside, but not from inside..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 09:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189609#M1076180</guid>
      <dc:creator>Kortermann-IT ApS</dc:creator>
      <dc:date>2020-11-27T09:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cant get NAT Loopback working (access FTP on outside IP from inside)</title>
      <link>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189616#M1076182</link>
      <description>&lt;P&gt;You could try the following:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object network FTP_SERVER&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;host 192.168.11.219&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object network LAN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;subnet 192.168.11.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object network LAN-NAT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;host 1.2.3.4&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (inside,inside) source static LAN LAN-NAT destination static interface FTP_SERVER&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The LAN-NAT object is required since your FTP and hosts are on the same network and you will end up with asynchronous routing if you have LAN LAN (traffic flow would be host --&amp;gt; ASA --&amp;gt; FTP --&amp;gt;host) and since the ASA does not see the return traffic from the FTP all other traffic in that flow will be dropped.&amp;nbsp; You could define a completely different subnet for the source also for example:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object network LAN-NAT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;subnet 192.168.12.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;and as long as that subnet is routed towards the ASA NAT will take care of the rest.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 10:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-get-nat-loopback-working-access-ftp-on-outside-ip-from/m-p/4189616#M1076182</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-27T10:13:17Z</dc:date>
    </item>
  </channel>
</rss>

