<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Configuration Troubleshooting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5233557#M1118022</link>
    <description>&lt;P&gt;Hi can someone please help troubleshoot our NAT configuration.&amp;nbsp; I am able to ping Google directly from our ASA, however I cannot ping Google from a host located on the INSIDE2 interface (security level 100). We need to be able to reach smtp.office365.com. Please advise, the config is located below.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network VPN_POOL&lt;BR /&gt;subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network inside&lt;/P&gt;&lt;P&gt;subnet 172.31.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list OUTSIDE_TO_IN extended permit ip object VPN_POOL any&lt;BR /&gt;access-list OUTSIDE_TO_IN extended permit tcp object VPN_POOL any&lt;/P&gt;&lt;P&gt;nat (INSIDE2,outside) source static any any destination static VPN_POOL VPN_POOL no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network VPN_POOL&lt;BR /&gt;nat (outside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network inside.&lt;BR /&gt;nat (inside,outside) dynamic interface&lt;BR /&gt;access-group OUTSIDE_TO_IN in interface outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2024 21:47:39 GMT</pubDate>
    <dc:creator>chiguy123</dc:creator>
    <dc:date>2024-12-06T21:47:39Z</dc:date>
    <item>
      <title>NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5233557#M1118022</link>
      <description>&lt;P&gt;Hi can someone please help troubleshoot our NAT configuration.&amp;nbsp; I am able to ping Google directly from our ASA, however I cannot ping Google from a host located on the INSIDE2 interface (security level 100). We need to be able to reach smtp.office365.com. Please advise, the config is located below.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network VPN_POOL&lt;BR /&gt;subnet 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network inside&lt;/P&gt;&lt;P&gt;subnet 172.31.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list OUTSIDE_TO_IN extended permit ip object VPN_POOL any&lt;BR /&gt;access-list OUTSIDE_TO_IN extended permit tcp object VPN_POOL any&lt;/P&gt;&lt;P&gt;nat (INSIDE2,outside) source static any any destination static VPN_POOL VPN_POOL no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network VPN_POOL&lt;BR /&gt;nat (outside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network inside.&lt;BR /&gt;nat (inside,outside) dynamic interface&lt;BR /&gt;access-group OUTSIDE_TO_IN in interface outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 21:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5233557#M1118022</guid>
      <dc:creator>chiguy123</dc:creator>
      <dc:date>2024-12-06T21:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5233564#M1118023</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1820765"&gt;@chiguy123&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best way to track down the problem on this case is running Packet-tracer. It will give you if NAT or ACL is the problem.&lt;/P&gt;
&lt;P&gt;packet-tracer input outside tcp&amp;nbsp; &amp;lt;INSIDE2 &amp;gt;&amp;nbsp; 1234 &amp;lt;smtp.office365.com&amp;gt; 25&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 21:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5233564#M1118023</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-06T21:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5233648#M1118026</link>
      <description>&lt;P&gt;&lt;SPAN&gt;nat &lt;STRONG&gt;(inside2,outside)&lt;/STRONG&gt; dynamic interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That only what you need&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2024 01:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5233648#M1118026</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-07T01:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234578#M1118061</link>
      <description>&lt;P&gt;I have other NAT statements listed below configured.&amp;nbsp; If I add the NAT statement as you suggested will it effect/override the other NAT statement that are currently being translated/untranslated?&amp;nbsp;&lt;/P&gt;&lt;P&gt;KYD-EDI-asa1# sh run nat&lt;BR /&gt;nat (inside2,outside) source static any any destination static VPN_POOL VPN_POOL no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network VPN_POOL&lt;BR /&gt;nat (outside,outside) dynamic interface&lt;BR /&gt;object network inside&lt;BR /&gt;nat (inside,outside) dynamic interface&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 19:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234578#M1118061</guid>
      <dc:creator>chiguy123</dc:creator>
      <dc:date>2024-12-09T19:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234581#M1118062</link>
      <description>&lt;P&gt;Here are the results I couldn't use the FQDN so I used one of Microsoft's public IP's, do you think that could cause an issue not being able to use the FQDN?&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 19:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234581#M1118062</guid>
      <dc:creator>chiguy123</dc:creator>
      <dc:date>2024-12-09T19:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234703#M1118072</link>
      <description>&lt;P&gt;&lt;SPAN&gt;To make Me take review of your network&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (inside2,outside) source static any any destination static VPN_POOL VPN_POOL no-proxy-arp route-lookup &amp;lt;&amp;lt;- this for VPN traffic?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;object network VPN_POOL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nat (outside,outside) dynamic interface &amp;lt;&amp;lt;- this for RA VPN to access Internet ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;object network inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nat (inside,outside) dynamic interface &amp;lt;&amp;lt;- this for Internal Host connect to inside interface of ASA ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;so what I suggest&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network inside2&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;nat&amp;nbsp;&lt;STRONG&gt;(inside2,outside)&lt;/STRONG&gt;&amp;nbsp;dynamic interface &amp;lt;&amp;lt;- if above is correct then this NAT will not effect your traffic at all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;for FQDN, internal Host connect to inside2 get IP from ASA (ASA work as local dhcp?)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if Yes what is the DNS host use ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1- if DNS is 8.8.8.8 or 8.8.4.4 then you need to allow DNS traffic to pass via ASA&amp;nbsp;&lt;BR /&gt;2- if DNS is ASA itself then you need to run dns domain-lookup&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 07:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234703#M1118072</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-10T07:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234939#M1118099</link>
      <description>&lt;P&gt;Yes we do have RA VPN which is setup and working, however the other NAT is configured but not enabled.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The VPN pool object subnet is in the same subnet as the server that needs SMTP communication with the new NAT rule. Will this cause a conflict or should I put the server into another subnet or just create a new object with the same server subnet/host configuration?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 15:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5234939#M1118099</guid>
      <dc:creator>chiguy123</dc:creator>
      <dc:date>2024-12-10T15:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Configuration Troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5235227#M1118116</link>
      <description>&lt;P&gt;Yes it will overlapping, why you config VPN Pool same subent as server connect to inside2 ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 06:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-configuration-troubleshooting/m-p/5235227#M1118116</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-11T06:34:32Z</dc:date>
    </item>
  </channel>
</rss>

