<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting error after removing object from object-group in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822200#M1099933</link>
    <description>&lt;P&gt;By the looks of it you have two NAT statements referencing the same IP (ISP_2 interface IP).&amp;nbsp; This has most likely been this way for a while so I do not believe it will affect you in any way, but you might want to look into it and clean it up as this can affect future NAT configurations and/or cause problems in the future.&lt;/P&gt;
&lt;P&gt;show xlate local 50.50.50.50&lt;/P&gt;
&lt;P&gt;show nat 50.50.50.50&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2023 13:15:28 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2023-04-26T13:15:28Z</dc:date>
    <item>
      <title>Getting error after removing object from object-group</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822165#M1099931</link>
      <description>&lt;P&gt;Getting the following error after I removed an unused network object from an object group on my ASA. Why am I getting this error? But I have no idea how they can be related? Yes, I understand they overlap, but it never was an issue before? Should I be concerned? Everything seems to be working, there's a bunch of NAT Rules which the object-group&amp;nbsp;IntDataSeg is used in. But so far I don't see anything being an issue.&lt;/P&gt;&lt;P&gt;name 50.50.50.50 fw_1_ext&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;nameif ISP_2&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address fw_1_ext 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;object network fw_1_ext&lt;BR /&gt;host 50.50.50.50&lt;BR /&gt;&lt;BR /&gt;nat (inside,outside) source dynamic IntAllSeg interface&lt;BR /&gt;nat (inside,ISP_2) source dynamic IntAllSeg interface&lt;/P&gt;&lt;P&gt;ASA-1/act# config t&lt;BR /&gt;ASA-1//act(config)# object-group network IntDataSeg&lt;BR /&gt;ASA-1/act(config-network-object-group)# no network-object DataSeg21 255.255.0.0&lt;BR /&gt;ERROR: Address fw_1_ext overlaps with ISP_2 interface address.&lt;BR /&gt;ERROR: NAT Policy is not downloaded&lt;BR /&gt;ASA-1/act(config-network-object-group)#network-object DataSeg21 255.255.0.0&lt;BR /&gt;ERROR: Address fw_1_ext overlaps with ISP_2 interface address.&lt;BR /&gt;ERROR: NAT Policy is not downloaded&lt;BR /&gt;ERROR: object-group (IntDataSeg) updation failed due to internal error&lt;BR /&gt;ASA-1/act(config-network-object-group)# exit&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 12:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822165#M1099931</guid>
      <dc:creator>Fartingdragon</dc:creator>
      <dc:date>2023-04-26T12:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error after removing object from object-group</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822200#M1099933</link>
      <description>&lt;P&gt;By the looks of it you have two NAT statements referencing the same IP (ISP_2 interface IP).&amp;nbsp; This has most likely been this way for a while so I do not believe it will affect you in any way, but you might want to look into it and clean it up as this can affect future NAT configurations and/or cause problems in the future.&lt;/P&gt;
&lt;P&gt;show xlate local 50.50.50.50&lt;/P&gt;
&lt;P&gt;show nat 50.50.50.50&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:15:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822200#M1099933</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-04-26T13:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error after removing object from object-group</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822223#M1099934</link>
      <description>&lt;P&gt;The two NAT one is for the primary isp (outside) and the secondary is (ISP_2) those statements, that isn't a problem is it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822223#M1099934</guid>
      <dc:creator>Fartingdragon</dc:creator>
      <dc:date>2023-04-26T13:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error after removing object from object-group</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822233#M1099935</link>
      <description>&lt;P&gt;&lt;SPAN&gt;IntAllSeg this object group for nat&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;IntDataSeg you delete other object group or I am wrong?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822233#M1099935</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-26T13:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error after removing object from object-group</title>
      <link>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822318#M1099938</link>
      <description>&lt;P&gt;I didn't delete an object group, only an object within the IntDataSeg which had the 10.221.0.0 /16 network it had different objects of the different networks like 10.221.0.0 would be called DataSeg221 10.222.0.0 would be called DataSeg222. The IntAllSeg has additional objects in it, but that one is untouched.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 15:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-error-after-removing-object-from-object-group/m-p/4822318#M1099938</guid>
      <dc:creator>Fartingdragon</dc:creator>
      <dc:date>2023-04-26T15:31:53Z</dc:date>
    </item>
  </channel>
</rss>

