<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5119353#M1113080</link>
    <description>&lt;P&gt;Sorry I make you waiting&amp;nbsp;&lt;BR /&gt;I was busy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jebankshrcu_0-1716657233286x.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219502iA83507C77D6E4AE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="jebankshrcu_0-1716657233286x.png" alt="jebankshrcu_0-1716657233286x.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2024 11:02:22 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-05-29T11:02:22Z</dc:date>
    <item>
      <title>FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115290#M1112934</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;So currently I have a FTD that I manage via FDM. Am trying to access an internal host from the outside via port 8888 but internally it should translate back to ssh (22). Screenshot is my nat rule. Not sure if am doing something wrong and what else am missing cause the rules I have it widely open to see if thats the issue but still nothing.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jebankshrcu_0-1716505051733.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219058iF505507852D2748B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jebankshrcu_0-1716505051733.png" alt="jebankshrcu_0-1716505051733.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 22:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115290#M1112934</guid>
      <dc:creator>jebankshrcu</dc:creator>
      <dc:date>2024-05-23T22:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115394#M1112939</link>
      <description>&lt;P&gt;what is the error you getting when you initiate the connection from outside IP address and port 8888 ?&lt;/P&gt;
&lt;P&gt;does the webserver running service 22 ?&amp;nbsp; web server runs on generally 443 ? so what web server is this ?&lt;/P&gt;
&lt;P&gt;i have tested in my Lab some time it works as expected for reference :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.balajibandi.com/?p=1855" target="_blank"&gt;https://www.balajibandi.com/?p=1855&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Debug - run on FDM or cli see if the packet reaching the outside interface or not first before it process NAT and inside ACL.&lt;/P&gt;
&lt;P&gt;sometime the provider do not allow some incoming packets on odd ports.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 06:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115394#M1112939</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-05-24T06:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115600#M1112954</link>
      <description>&lt;P&gt;Try packet-tracer from the FTD cli and let us know what you get.&lt;/P&gt;
&lt;P&gt;packet-tracer input outside tcp 1.1.1.1 1234 &amp;lt;outside interface address&amp;gt; 8888&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/troubleshooting-access-problems-using-packet-tracer/ta-p/3114976" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/troubleshooting-access-problems-using-packet-tracer/ta-p/3114976&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also make sure there are no other rules or active connections using that same tcp port on the outside interface.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 13:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115600#M1112954</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-05-24T13:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115627#M1112959</link>
      <description>&lt;P&gt;first change the rule from auto to &lt;STRONG&gt;NAT&lt;/STRONG&gt; &lt;STRONG&gt;rules&lt;/STRONG&gt; &lt;STRONG&gt;before&lt;/STRONG&gt;&lt;BR /&gt;second make sure you allow real IP and Port &lt;STRONG&gt;22&lt;/STRONG&gt; in ACP&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 13:38:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5115627#M1112959</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-24T13:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5116176#M1112993</link>
      <description>&lt;P&gt;run a packet tracer from CLI, Verify that the access rules and NAT statements that are being hit are correct and that the action is allowed.&amp;nbsp; If that looks good set up a packet capture on the webportal interface and see if there is traffic being captured in both directions.&amp;nbsp; If you are only seeing traffic out towards the server but nothing in return, the the issue is either with the server itself or in the path between the firewall and the server.&lt;/P&gt;
&lt;P&gt;If possible you can also run a tcpdump on the server in question and see if the SSH session is actually reaching the server.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 22:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5116176#M1112993</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-05-24T22:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5116578#M1113004</link>
      <description>&lt;P&gt;So changing it from auto you mean use manual nat like the image attached?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jebankshrcu_0-1716657233286.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219186i3D3263EF7E93F1EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jebankshrcu_0-1716657233286.png" alt="jebankshrcu_0-1716657233286.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 May 2024 17:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5116578#M1113004</guid>
      <dc:creator>jebankshrcu</dc:creator>
      <dc:date>2024-05-25T17:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5117904#M1113039</link>
      <description>&lt;P&gt;How can I do this nat rule on a Cisco FTD using the FDM rather than the FMC?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jebankshrcu_0-1716844464475.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219269i679D38B38FB71654/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jebankshrcu_0-1716844464475.png" alt="jebankshrcu_0-1716844464475.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 21:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5117904#M1113039</guid>
      <dc:creator>jebankshrcu</dc:creator>
      <dc:date>2024-05-27T21:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5119353#M1113080</link>
      <description>&lt;P&gt;Sorry I make you waiting&amp;nbsp;&lt;BR /&gt;I was busy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jebankshrcu_0-1716657233286x.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219502iA83507C77D6E4AE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="jebankshrcu_0-1716657233286x.png" alt="jebankshrcu_0-1716657233286x.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 11:02:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat/m-p/5119353#M1113080</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-29T11:02:22Z</dc:date>
    </item>
  </channel>
</rss>

