<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN deployment failed Config Error -- nat (inside,any) dynamic Outside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457756#M1083240</link>
    <description>&lt;P&gt;First VPN config. Missing something simple.&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR: Address X.X.X.X overlaps with outside interface address.&lt;/P&gt;&lt;P&gt;ERROR: NAT Policy is not downloaded.&lt;/P&gt;&lt;P&gt;Firepower 2100 series using FDM for configuration. I have configured the VPN for inside network object X.X.X.0/24 &amp;gt; Dynamic PAT &amp;gt; Outside facing public IP address (configured as HOST object)&lt;/P&gt;&lt;P&gt;From the config error called out in the failed deployment log, I know that I have messed up NAT policy somehow, but can't figure out how. Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Aug 2021 19:43:10 GMT</pubDate>
    <dc:creator>jreynolds4</dc:creator>
    <dc:date>2021-08-31T19:43:10Z</dc:date>
    <item>
      <title>VPN deployment failed Config Error -- nat (inside,any) dynamic Outside</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457756#M1083240</link>
      <description>&lt;P&gt;First VPN config. Missing something simple.&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR: Address X.X.X.X overlaps with outside interface address.&lt;/P&gt;&lt;P&gt;ERROR: NAT Policy is not downloaded.&lt;/P&gt;&lt;P&gt;Firepower 2100 series using FDM for configuration. I have configured the VPN for inside network object X.X.X.0/24 &amp;gt; Dynamic PAT &amp;gt; Outside facing public IP address (configured as HOST object)&lt;/P&gt;&lt;P&gt;From the config error called out in the failed deployment log, I know that I have messed up NAT policy somehow, but can't figure out how. Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 19:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457756#M1083240</guid>
      <dc:creator>jreynolds4</dc:creator>
      <dc:date>2021-08-31T19:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN deployment failed Config Error -- nat (inside,any) dynamic Out</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457803#M1083241</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1241039"&gt;@jreynolds4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to configure Dynamic PAT, use the Option&amp;nbsp;&lt;STRONG&gt;Interface&lt;/STRONG&gt; Instead of specifying an object contains outside interface IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Acc disable policy.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/129314i9F196E23BE2B119D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Acc disable policy.JPG" alt="Acc disable policy.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 21:37:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457803#M1083241</guid>
      <dc:creator>Amine ZAKARIA</dc:creator>
      <dc:date>2021-08-31T21:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN deployment failed Config Error -- nat (inside,any) dynamic Out</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457816#M1083242</link>
      <description>&lt;P&gt;i will try outside interface (instead of any)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 21:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457816#M1083242</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-31T21:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN deployment failed Config Error -- nat (inside,any) dynamic Out</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457898#M1083243</link>
      <description>&lt;P&gt;Thank you so much for the response. My post was incorrect. Although the deploy error lead me to thinking there is an error in "NAT" rules that is incorrect. I have exempted this site to site VPN from NAT. With this in mind I am even more confused as to the config error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ERROR: Address X.X.X.X overlaps with outside interface address.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ERROR: NAT Policy is not downloaded&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Config Error -- nat (inside,any) dynamic OutsidePublicIP&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 00:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457898#M1083243</guid>
      <dc:creator>jreynolds4</dc:creator>
      <dc:date>2021-09-01T00:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN deployment failed Config Error -- nat (inside,any) dynamic Out</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457900#M1083244</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1241039"&gt;@jreynolds4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PAT you should specifiy the outside to nat with, like this :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;nat (inside,&lt;STRONG&gt;outside&lt;/STRONG&gt;) dynamic OutsidePublicIP or&amp;nbsp;nat (inside,&lt;STRONG&gt;outside&lt;/STRONG&gt;) dynamic interface (Check the capture i have shared above for the example)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm assuming you want to "&lt;STRONG&gt;Any&lt;/STRONG&gt; traffic from the inside zone going outside to be PAT", with the NAT Exempt checkbox enabled the local networks and remote networks configured under S2S VPN are going to be exempt from the PAT Policy.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 00:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457900#M1083244</guid>
      <dc:creator>Amine ZAKARIA</dc:creator>
      <dc:date>2021-09-01T00:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN deployment failed Config Error -- nat (inside,any) dynamic Out</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457908#M1083245</link>
      <description>Zakaria,&lt;BR /&gt;Because I am so new to this I think it best to describe the purpose of the site to site VPN. This is to accommodate connections from individual workstations to our Electronic Health Records vendor. The connections are interactive and bi-directional. For this reason the individual IP addresses from the inside network object need to be visible to the vendor and, therefore, need to be exempt from NAT rules.&lt;BR /&gt;I hope this explanation makes sense. I am losing my mind a bit on this. I have opened a ticket with Cisco support. Hopefully they can walk me through. Fast learner, but starting at 0 here.&lt;BR /&gt;</description>
      <pubDate>Wed, 01 Sep 2021 01:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4457908#M1083245</guid>
      <dc:creator>jreynolds4</dc:creator>
      <dc:date>2021-09-01T01:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN deployment failed Config Error -- nat (inside,any) dynamic Out</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4458023#M1083246</link>
      <description>&lt;P&gt;The FDM should take care of exempting the VPN traffic without you to have to create any manual rules. However, if you still need to create a NAT exemption rule for the VPN traffic then that should be a manual static NAT rule where you specify the source in both the original packet and translated packet section as the endpoint source or the whole subnet where those endpoints are located. The same will be for the destination IP/subnet, you will set the same destination address in both the original packet and the translated packet.&lt;/P&gt;&lt;P&gt;Regarding the error you are seeing when you tried to apply the dynamic rule, I think it is simply because you can't use the same IP assigned to an interface in a NAT rule with a custom object. In your case it seems that the public IP&amp;nbsp;65.140.69.98 is assigned already to the outside interface. It would be enough to use a different public IP address associated to the object OutsidePublicIP and specify the destination interface as outside. That NAT rule will translate the traffic sourcing from the&amp;nbsp;WHH-PACS-Network to the public IP 65.140.69.89.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 07:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4458023#M1083246</guid>
      <dc:creator>Aref_Alsouqi</dc:creator>
      <dc:date>2021-09-01T07:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN deployment failed Config Error -- nat (inside,any) dynamic Out</title>
      <link>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4458028#M1083247</link>
      <description>&lt;DIV id="bodyDisplay_5" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;The FDM should take care of exempting the VPN traffic without you to have to create any manual rules. However, if you still need to create a NAT exemption rule for the VPN traffic then that should be a manual static NAT rule where you specify the source in both the original packet and translated packet section as the endpoint source or the whole subnet where those endpoints are located. The same will be for the destination IP/subnet, you will set the same destination address in both the original packet and the translated packet.&lt;/P&gt;
&lt;P&gt;Regarding the error you are seeing when you tried to apply the dynamic rule, I think it is simply because you can't use the same IP assigned to an interface in a NAT rule with a custom object. In your case it seems that the public IP&amp;nbsp;65.140.69.98 is assigned already to the outside interface. It would be enough to use a different public IP address associated to the object OutsidePublicIP and specify the destination interface as outside. That NAT rule will translate the traffic sourcing from the&amp;nbsp;WHH-PACS-Network to the public IP 65.140.69.89.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 01 Sep 2021 07:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-deployment-failed-config-error-nat-inside-any-dynamic/m-p/4458028#M1083247</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2021-09-01T07:08:40Z</dc:date>
    </item>
  </channel>
</rss>

