<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD: Port translation is not performed on outside2 interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286608#M1120820</link>
    <description>&lt;P&gt;Sorry I confuse with other issue with anyconnect.&lt;/P&gt;
&lt;P&gt;Anyway&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rpf-check (drop) this cause because of asymmetric traffic.&lt;/P&gt;
&lt;P&gt;Use packet-tracer but this time from inside to outside1/2&lt;/P&gt;
&lt;P&gt;See if NAT is select correctly.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Wed, 30 Apr 2025 13:35:31 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-04-30T13:35:31Z</dc:date>
    <item>
      <title>FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286520#M1120811</link>
      <description>&lt;P&gt;Good morning everyone,&lt;/P&gt;&lt;P&gt;I am using a CSF 1210CE FTD and I need to publish a service so that it can be reached from two public IP addresses provided by different ISPs.&lt;BR /&gt;I configured a second external interface, created two static NATs with port translation (external 32500, internal 8080) one for each external interface and the relative access control rule.&lt;BR /&gt;The server is reachable from the first public IP address but not from the second.&lt;BR /&gt;From the syslog messages analysis it seems that the port translation is not performed on outside2 but only on outside1.&lt;BR /&gt;I checked and the NAT configuration is correct.&lt;BR /&gt;Can anyone help me?&lt;BR /&gt;Thanks&lt;BR /&gt;Have a nice day&lt;BR /&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 09:09:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286520#M1120811</guid>
      <dc:creator>Brunetta7</dc:creator>
      <dc:date>2025-04-30T09:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286526#M1120812</link>
      <description>&lt;P&gt;First&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- are you sure DNS return ISP2 public IP?&lt;/P&gt;
&lt;P&gt;2- are you sure FTD dont use ISP1 for retrun traffic' try use packet tracer to check that.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 09:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286526#M1120812</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-30T09:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286534#M1120813</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;BR /&gt;Users to connect remotely use the public IP address directly, not a domain name resolved by a DNS.&lt;BR /&gt;The remote user's request reaches outside2 correctly, the IP address of outside2 is reported in the syslog message. I don't think there are problems returning to isp1 because the packet is stopped before. To be clearer I'll post the syslog messages.&lt;BR /&gt;I hid the source IP with X.X.X.X&lt;/P&gt;&lt;P&gt;syslog message for connection from isp1,&amp;nbsp; it's ok&lt;BR /&gt;12:28:11 +ACU-FTD+AC0-6+AC0-302013: Built inbound TCP connection 277393 for outside:X.X.X.X/1724/1724 (X.X.X.X/1724) to inside:192.168.0.25/8080 (10.11.13.2/32500) 1 6&lt;BR /&gt;12:28:24 +ACU-FTD+AC0-6+AC0-302014: Teardown TCP connection 277393 for outside:X.X.X.X/1724 to inside:192.168.0.25/8080 duration 0:00:13 bytes 361335 TCP Reset+AC0-O from outside 1 6&lt;/P&gt;&lt;P&gt;syslog message for connection from isp2 ,&amp;nbsp; it's fail&lt;BR /&gt;12:28:27 +ACU-FTD+AC0-6+AC0-302013: Built inbound TCP connection 277416 for outside2:X.X.X.X/1548 (X.X.X.X/1548) to inside:192.168.0.25/32500 (192.168.178.2/32500) 1 6&lt;BR /&gt;12:28:27 +ACU-FTD+AC0-6+AC0-302014: Teardown TCP connection 277416 for outside2:X.X.X.X/1548 to inside:192.168.0.25/32500 duration 0:00:00 bytes 0 TCP Reset+AC0-O from inside 1 6&lt;/P&gt;&lt;P&gt;As you can see from the logs in the second case it seems that the port translation is not done&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 10:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286534#M1120813</guid>
      <dc:creator>Brunetta7</dc:creator>
      <dc:date>2025-04-30T10:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286538#M1120814</link>
      <description>&lt;P&gt;Use packet-tracer to see in which phase the traffic is drop&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 10:41:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286538#M1120814</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-30T10:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286569#M1120815</link>
      <description>&lt;P&gt;I am not very familiar with Packet-tracer.&lt;BR /&gt;I tried the following:&lt;BR /&gt;packet-tracer&amp;nbsp;input&amp;nbsp;outside2&amp;nbsp;t X.X.X.X 32500 192.168.0.25&amp;nbsp;8080&amp;nbsp;&lt;BR /&gt;The result is this:&lt;BR /&gt;.....&lt;BR /&gt;Phase:&amp;nbsp;6&lt;BR /&gt;Type:&amp;nbsp;NAT&lt;BR /&gt;Subtype:&amp;nbsp;rpf-check&lt;BR /&gt;Result:&amp;nbsp;DROP&lt;BR /&gt;Elapsed&amp;nbsp;time:&amp;nbsp;34816&amp;nbsp;ns&lt;BR /&gt;Config:&lt;BR /&gt;nat&amp;nbsp;(inside,outside2)&amp;nbsp;after-auto&amp;nbsp;source&amp;nbsp;static&amp;nbsp;INTERNAL_SERVER ADDGRP_IPEsterni&amp;nbsp;service&amp;nbsp;_|NatOrigSvc_2d46bfc6-21f9-11f0-8111-efd80de64e46&amp;nbsp;_|NatMappedSvc_2d46bfc6-21f9-11f0-8111-efd80de64e46&lt;BR /&gt;Additional&amp;nbsp;Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface:&amp;nbsp;outside2(vrfid:0)&lt;BR /&gt;input-status:&amp;nbsp;up&lt;BR /&gt;input-line-status:&amp;nbsp;up&lt;BR /&gt;output-interface:&amp;nbsp;inside(vrfid:0)&lt;BR /&gt;output-status:&amp;nbsp;up&lt;BR /&gt;output-line-status:&amp;nbsp;up&lt;BR /&gt;Action:&amp;nbsp;drop&lt;BR /&gt;Time&amp;nbsp;Taken:&amp;nbsp;78848&amp;nbsp;ns&lt;BR /&gt;Drop-reason:&amp;nbsp;(acl-drop)&amp;nbsp;Flow&amp;nbsp;is&amp;nbsp;denied&amp;nbsp;by&amp;nbsp;configured&amp;nbsp;rule,&amp;nbsp;Drop-location:&amp;nbsp;frame&amp;nbsp;snp_sp_handle_flow_drop:4208&amp;nbsp;flow&amp;nbsp;(NA)/NA&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 12:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286569#M1120815</guid>
      <dc:creator>Brunetta7</dc:creator>
      <dc:date>2025-04-30T12:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286572#M1120816</link>
      <description>&lt;P&gt;I need to see whole packet tracer&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 12:08:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286572#M1120816</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-30T12:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286577#M1120817</link>
      <description>&lt;P&gt;&amp;gt; packet-tracer input outside2 t X.X.X.X 32500 192.168.0.25 8080&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: No ECMP load balancing&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Elapsed time: 22528 ns&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Destination is locally connected. No ECMP load balancing.&lt;BR /&gt;Found next-hop 192.168.0.25 using egress ifc inside(vrfid:0)&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Elapsed time: 5376 ns&lt;BR /&gt;Config:&lt;BR /&gt;access-group NGFW_ONBOX_ACL global&lt;BR /&gt;access-list NGFW_ONBOX_ACL advanced permit object-group |acSvcg-268435463 ifc outside2 object-group |acSrcNwg-268435463 ifc inside object IP_INTERNAL_SERVER rule-id 268435463 event-log both&lt;BR /&gt;access-list NGFW_ONBOX_ACL remark rule-id 268435463: ACCESS POLICY: NGFW_Access_Policy&lt;BR /&gt;access-list NGFW_ONBOX_ACL remark rule-id 268435463: L7 RULE: RULE3&lt;BR /&gt;object-group service |acSvcg-268435463&lt;BR /&gt;service-object tcp destination eq 8080&lt;BR /&gt;service-object tcp destination eq 32500&lt;BR /&gt;object-group network |acSrcNwg-268435463&lt;BR /&gt;group-object ADDGRP_IPEsterni&lt;BR /&gt;network-object object NOSTRIPPubblico2&lt;BR /&gt;Additional Information:&lt;BR /&gt;This packet will be sent to snort for additional processing where a verdict will be reached&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: CONN-SETTINGS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Elapsed time: 5376 ns&lt;BR /&gt;Config:&lt;BR /&gt;class-map class-default&lt;BR /&gt;match any&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class class-default&lt;BR /&gt;set connection decrement-ttl&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Elapsed time: 5376 ns&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Elapsed time: 5376 ns&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Elapsed time: 34816 ns&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside,outside2) after-auto source static IP_INTERNAL_SERVER ADDGRP_IPEsterni service _|NatOrigSvc_2d46bfc6-21f9-11f0-8111-efd80de64e46 _|NatMappedSvc_2d46bfc6-21f9-11f0-8111-efd80de64e46&lt;BR /&gt;Additional Information:&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: outside2(vrfid:0)&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside(vrfid:0)&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Time Taken: 78848 ns&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame snp_sp_handle_flow_drop:4208 flow (NA)/NA&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 12:21:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286577#M1120817</guid>
      <dc:creator>Brunetta7</dc:creator>
      <dc:date>2025-04-30T12:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286581#M1120818</link>
      <description>&lt;P&gt;Edit&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 13:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286581#M1120818</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-30T13:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286589#M1120819</link>
      <description>&lt;P&gt;I apologize but I did not understand the answer.&lt;BR /&gt;Obviously for privacy reasons I changed addresses and ports.&lt;BR /&gt;Inside my network I have a server with proprietary software that accepts connections from external users without VPN.&lt;BR /&gt;To balance the load of incoming connections, two public IP addresses are used.&lt;BR /&gt;The previous firewall worked like this, now I'm trying to replicate the same behavior on the CSF1210CE FTD,&lt;BR /&gt;is it possible?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 12:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286589#M1120819</guid>
      <dc:creator>Brunetta7</dc:creator>
      <dc:date>2025-04-30T12:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286608#M1120820</link>
      <description>&lt;P&gt;Sorry I confuse with other issue with anyconnect.&lt;/P&gt;
&lt;P&gt;Anyway&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rpf-check (drop) this cause because of asymmetric traffic.&lt;/P&gt;
&lt;P&gt;Use packet-tracer but this time from inside to outside1/2&lt;/P&gt;
&lt;P&gt;See if NAT is select correctly.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 13:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5286608#M1120820</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-30T13:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Port translation is not performed on outside2 interface</title>
      <link>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5287231#M1120847</link>
      <description>&lt;P&gt;Good morning everyone,&lt;BR /&gt;I finally managed to solve it, the problem was a trivial conflict with another nat policy.&lt;BR /&gt;After eliminating the unnecessary static nat, I managed to get my services working on both outside interfaces.&lt;BR /&gt;Thanks to MHM for your time.&lt;BR /&gt;Have a nice day&lt;BR /&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2025 13:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-port-translation-is-not-performed-on-outside2-interface/m-p/5287231#M1120847</guid>
      <dc:creator>Brunetta7</dc:creator>
      <dc:date>2025-05-02T13:39:07Z</dc:date>
    </item>
  </channel>
</rss>

