<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strange in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033547#M134921</link>
    <description>&lt;P&gt;Strange&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;with nat, i cannot reach my ftp behind 217.77.77.210&lt;/P&gt;
&lt;P&gt;Actually i have a pc connecte to outside interface with ip 217.77.77.211&lt;/P&gt;
&lt;P&gt;to test application, i tried ftp to 217.77.77.210 and the host behind reply&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Without nat (dmz-egov,outside) i can reach ftp and with nat (dmz-egov,outside) it's not working&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2017 22:04:03 GMT</pubDate>
    <dc:creator>Rowlands Price</dc:creator>
    <dc:date>2017-06-08T22:04:03Z</dc:date>
    <item>
      <title>Cannot configuring NAT using outside interface ip to Two different dmz servers</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033534#M134908</link>
      <description>&lt;P&gt;Hi Support,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a litte issue&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a Cisco ASA 5525-x using version 8.6 (1)&lt;/P&gt;
&lt;P&gt;My issue is that i cannot configure nat to allow users from Internet to access servers located on dmz1 and dmz4&lt;/P&gt;
&lt;P&gt;The nat should use the outside ip interface.&lt;/P&gt;
&lt;P&gt;outside ip: 172.16.1.1 (for testing)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;dmz1; server ip: 192.168.46.15, ports must be used: https and 8080&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Dmz4: server ip 192.168.35.2, port must be used: tcp 7909, 7910 and 7911&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All servers from dmz must access internet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please help me regarding nat configuration?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attached is my diagram&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 01:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033534#M134908</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2019-03-26T01:00:21Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033535#M134909</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is an example to do the nat statement for dmz1. As nat ports are not contiguous, you'll need to create 2 objects and apply the nat statement. Also the acl needed on your outside interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per example I've done 2 different ace, 1 per port. You can also create a port object and then have only 1 ace referring to that port object for this specific host.&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;object network dmz1-8080&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.46.15&lt;BR /&gt;nat (dmz1,outside) static 172.16.1.1 service tcp 8080 8080&lt;BR /&gt;!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network dmz1-https&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.46.15&lt;BR /&gt;nat (dmz1,outside) static 172.16.1.1 service tcp 443 443&lt;/P&gt;
&lt;P&gt;!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit tcp any object dmz1-https eq https&lt;/P&gt;
&lt;P&gt;!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit tcp any object dmz1-8080 eq 8080&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;For dmz4, as ports are contiguous we can do in another way:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;object network dmz4-srv
 host 192.168.35.2
!
object service Obj-Ports
 service tcp destination range 7909 7911
!&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;nat (outside,inside) source static any any destination static interface dmz4-srv service Obj-Ports Obj-Ports
!&lt;BR /&gt;&lt;SPAN&gt;access-list outside_access_in extended permit tcp any object dmz4-srv range 7909 7911&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;I don't have your config but nat order is important to not overlap things.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for my paging, I'm using my mobile phone to answer your question.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 00:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033535#M134909</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T00:39:40Z</dc:date>
    </item>
    <item>
      <title>Hi Francesco</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033536#M134910</link>
      <description>&lt;P&gt;Hi Francesco&lt;/P&gt;
&lt;P&gt;Many Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;why this line please:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this is a nat from outside to inside, this must be denied by default, or what please&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="pln"&gt;nat &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;outside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;inside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; source &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; any any destination &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;interface&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; dmz4&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;srv service &lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Obj&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Ports&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Obj&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Ports&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 05:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033536#M134910</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T05:00:26Z</dc:date>
    </item>
    <item>
      <title>Hi Francesco</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033537#M134911</link>
      <description>&lt;P&gt;Hi Francesco&lt;/P&gt;
&lt;P&gt;I have an error message when write these commands&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;host 192.168.46.15&lt;BR /&gt; nat (dmz1,outside) static 172.16.1.1 service tcp 8080 8080&lt;BR /&gt; &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;Here is the error message&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;ciscoasa(config-network-object)# nat (dmz1-,outside) static 172.16.1.1 serv$&lt;BR /&gt;ERROR: Address 172.16.1.1 overlaps with outside interface address.&lt;BR /&gt;ERROR: NAT Policy is not downloaded&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 06:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033537#M134911</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T06:25:17Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033538#M134912</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;172.16.1.1 is the IP assigned to your outside interface that's why you get this error message.&lt;/P&gt;
&lt;P&gt;Then you need to change that statement by:&lt;/P&gt;
&lt;P&gt;nat (dmz1,outside) static interface&amp;nbsp;service tcp 443 443&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 11:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033538#M134912</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T11:24:31Z</dc:date>
    </item>
    <item>
      <title>Hi Francesco,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033539#M134913</link>
      <description>&lt;P&gt;Hi Francesco,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Still not working, but the error message disapeared&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attached is my actual config, it's on a test firewall runing version 8.3&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 20:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033539#M134913</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T20:27:36Z</dc:date>
    </item>
    <item>
      <title>Your config isn't attached.</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033540#M134914</link>
      <description>&lt;P&gt;Your config isn't attached.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 20:59:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033540#M134914</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T20:59:15Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033541#M134915</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just reloaded the asa and it's now working well.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;but when i applied theses commands, it's not working&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (dmz-egov,outside) source dynamic dmz-egov_network interface&lt;/P&gt;
&lt;P&gt;this nat is for allowing dmz-egov_network to go internet right&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for support&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033541#M134915</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T21:13:57Z</dc:date>
    </item>
    <item>
      <title>I don't see this nat on your</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033542#M134916</link>
      <description>&lt;P&gt;I don't see this nat on your config.&lt;/P&gt;
&lt;P&gt;Can you apply it and do a packet-tracer?&lt;/P&gt;
&lt;P&gt;packet-tracer input&amp;nbsp;&lt;SPAN&gt;dmz-egov icmp 192.168.46.20 8 0 8.8.8.8&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033542#M134916</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T21:25:21Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033543#M134917</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the nat applied&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (dmz-egov,outside) source dynamic dmz-egov_network interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the packet tracert&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# packet-tracer input dmz-egov icmp 192.168.46.15 8 0 8.8.8.8&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: dmz-egov&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host&lt;/P&gt;
&lt;P&gt;ciscoasa(config)#&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033543#M134917</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T21:43:30Z</dc:date>
    </item>
    <item>
      <title>This message appears if</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033544#M134918</link>
      <description>&lt;P&gt;This message appears if interfaces is down and/or if your default route is not existing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Like before, try to save and reboot your asa&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033544#M134918</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T21:53:13Z</dc:date>
    </item>
    <item>
      <title>Sorry, the cable was</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033545#M134919</link>
      <description>&lt;P&gt;Sorry, the cable was unplugged&lt;/P&gt;
&lt;P&gt;here is the result&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# packet-tracer input dmz-egov icmp 192.168.46.15 8 0 8.8.8.8&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 0.0.0.0 0.0.0.0 outside&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group dmz-egov_access_in in interface dmz-egov&lt;BR /&gt;access-list dmz-egov_access_in extended permit ip object dmz-egov_network any log disable &lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 4 &lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (dmz-egov,outside) source dynamic dmz-egov_network interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;Dynamic translate 192.168.46.15/0 to 217.77.77.210/28229&lt;/P&gt;
&lt;P&gt;Phase: 6&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 751, packet dispatched to next module&lt;/P&gt;
&lt;P&gt;Result: &lt;BR /&gt;input-interface: dmz-egov&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;ciscoasa(config)#&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:55:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033545#M134919</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T21:55:52Z</dc:date>
    </item>
    <item>
      <title>Then it works.</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033546#M134920</link>
      <description>&lt;P&gt;Then it works.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 21:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033546#M134920</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T21:57:22Z</dc:date>
    </item>
    <item>
      <title>Strange</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033547#M134921</link>
      <description>&lt;P&gt;Strange&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;with nat, i cannot reach my ftp behind 217.77.77.210&lt;/P&gt;
&lt;P&gt;Actually i have a pc connecte to outside interface with ip 217.77.77.211&lt;/P&gt;
&lt;P&gt;to test application, i tried ftp to 217.77.77.210 and the host behind reply&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Without nat (dmz-egov,outside) i can reach ftp and with nat (dmz-egov,outside) it's not working&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033547#M134921</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T22:04:03Z</dc:date>
    </item>
    <item>
      <title>I'm sorry I don't get what</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033548#M134922</link>
      <description>&lt;P&gt;I'm sorry I don't get what you said.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you do the packet tracer matching this traffic and paste the output?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033548#M134922</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T22:30:27Z</dc:date>
    </item>
    <item>
      <title>sorry,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033549#M134923</link>
      <description>&lt;P&gt;sorry,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;with this&amp;nbsp;nat (dmz-egov,outside) source dynamic dmz-egov_network interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;here is the packet tracert from outside to access my ftp server, and it's not working&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# packet-tracer input outside tcp 8.8.8.8 ftp 217.77.77.210 ftp&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 217.77.77.210 255.255.255.255 identity&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;P&gt;ciscoasa(config)#&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:36:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033549#M134923</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T22:36:34Z</dc:date>
    </item>
    <item>
      <title>Ok now this is clear. </title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033550#M134924</link>
      <description>&lt;P&gt;Ok now this is clear.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remove the nat:&lt;/P&gt;
&lt;P&gt;No&amp;nbsp;&lt;SPAN&gt;nat (dmz-egov,outside) source dynamic dmz-egov_network interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;And replace by :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (dmz-egov,outside) after-auto source dynamic dmz-egov_network interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033550#M134924</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T22:54:02Z</dc:date>
    </item>
    <item>
      <title>Hi Francesco,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033551#M134925</link>
      <description>&lt;P&gt;Hi Francesco,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It's working fine NOW&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That means, i will need to apply the same nat for all interfaces? (inside and dmz-etax)?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 22:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033551#M134925</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T22:59:56Z</dc:date>
    </item>
    <item>
      <title>For dynamic nat, it's better</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033552#M134926</link>
      <description>&lt;P&gt;For dynamic nat, it's better doing that way then you're sure it'll be the last statement will hit and no overlap with specific nats.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 23:15:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033552#M134926</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-06-08T23:15:29Z</dc:date>
    </item>
    <item>
      <title>Ok, but what about others</title>
      <link>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033553#M134927</link>
      <description>&lt;P&gt;Ok, but what about others interfaces to go to internet?&lt;/P&gt;
&lt;P&gt;About theses nat ?&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source dynamic OBJ_GENERAL_ALL interface&lt;BR /&gt;nat (dmz-etax,outside) source dynamic dmz-etax_network interface&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 23:20:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-configuring-nat-using-outside-interface-ip-to-two/m-p/3033553#M134927</guid>
      <dc:creator>Rowlands Price</dc:creator>
      <dc:date>2017-06-08T23:20:43Z</dc:date>
    </item>
  </channel>
</rss>

