<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Karsten  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068145#M134240</link>
    <description>&lt;P&gt;Hi Karsten&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;could you please provide any supporting documents for your comments.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tony&lt;/P&gt;</description>
    <pubDate>Sun, 09 Jul 2017 05:34:02 GMT</pubDate>
    <dc:creator>tonysebastian</dc:creator>
    <dc:date>2017-07-09T05:34:02Z</dc:date>
    <item>
      <title>Ping issue with NAT</title>
      <link>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068143#M134238</link>
      <description>&lt;P&gt;Dear All&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial','sans-serif'; color: #333333; background: white;"&gt;In order to meet our requirements we have to configure PAT on 1 external IP addresses to two internal IP in DMZ on different TCP ports. This NAT is configured on ASA 9.1 version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial','sans-serif'; color: #333333; background: white;"&gt;As expected all the applications are working through natting, but &amp;nbsp;we are not able to ping to Mapped IP(external IP) from outside zone . So any one help me to identify is it the default behavior of ASA.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial','sans-serif'; color: #333333; background: white;"&gt;Earlier we had configured static NAT on single external IP to single internal IP without PAT in that case we used to receive ICMP reply &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial','sans-serif'; color: #333333; background: white;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#333333" face="Arial, sans-serif"&gt;Regards&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#333333" face="Arial, sans-serif"&gt;Tony&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068143#M134238</guid>
      <dc:creator>tonysebastian</dc:creator>
      <dc:date>2019-03-12T09:40:23Z</dc:date>
    </item>
    <item>
      <title>For this requirement, you</title>
      <link>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068144#M134239</link>
      <description>&lt;P&gt;For this requirement, you need a 1:1 mapping as you had before. You can't achieve this with pure port-forwarding on the ASA.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2017 19:12:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068144#M134239</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-07-08T19:12:10Z</dc:date>
    </item>
    <item>
      <title>Hi Karsten </title>
      <link>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068145#M134240</link>
      <description>&lt;P&gt;Hi Karsten&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;could you please provide any supporting documents for your comments.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tony&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 05:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068145#M134240</guid>
      <dc:creator>tonysebastian</dc:creator>
      <dc:date>2017-07-09T05:34:02Z</dc:date>
    </item>
    <item>
      <title>It's basic to how port</title>
      <link>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068146#M134242</link>
      <description>&lt;P&gt;It's basic to how port forwarding and "ping" works. An incoming icmp echo request (or "ping") is neither tcp nor udp - it is icmp. As such it is not covered by your specific port forwarding NAT rule. It will either hit a more general dynamic NAT (PAT) rule or be not NATted at all, depending on the other bits of your configuration.&lt;/P&gt;
&lt;P&gt;You can confirm the ASA works this way not only by inspection of the results (which you already have) but in more detail by using the packet-tracer utility.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 06:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068146#M134242</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-09T06:26:43Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin</title>
      <link>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068147#M134244</link>
      <description>&lt;P&gt;Hi Marvin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In packet tracer utility I am getting an error message as below&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 18pt; font-family: Calibri, sans-serif;"&gt;(nat-no-xlate-to-pat-pool)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 18pt; font-family: Calibri, sans-serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri, sans-serif;"&gt;Regards&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri, sans-serif;"&gt;Tony&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 08:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068147#M134244</guid>
      <dc:creator>tonysebastian</dc:creator>
      <dc:date>2017-07-09T08:53:55Z</dc:date>
    </item>
    <item>
      <title>Well there you go. The ASA</title>
      <link>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068148#M134245</link>
      <description>&lt;P&gt;Well there you go. The ASA itself is confirming what Karsten said - that your PAT pool cannot handle the icmp traffic.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 08:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issue-with-nat/m-p/3068148#M134245</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-09T08:58:07Z</dc:date>
    </item>
  </channel>
</rss>

