<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA static nat in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035396#M135377</link>
    <description>&lt;P&gt;ASA version 9.6(3)1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;both nat have same configuration except 172.16.100.2 use interface, anyone have same question?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this object work fine&lt;/P&gt;
&lt;P&gt;object network 172.16.100.3_25_xx2&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz) static 202.175.xx.203 service tcp smtp smtp &lt;/P&gt;
&lt;P&gt;this object not work&lt;BR /&gt;&amp;nbsp;object network 172.16.100.2_25_xx1&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz) static interface service tcp smtp smtp&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Cisco Adaptive Security Appliance Software Version 9.6(3)1 &lt;BR /&gt;Device Manager Version 7.2(2)1&lt;BR /&gt;&lt;BR /&gt;Compiled on Thu 30-Mar-17 21:40 PDT by builders&lt;BR /&gt;System image file is "disk0:/asa963-1-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;BR /&gt;&lt;BR /&gt;packet-tracer input xyz tcp 8.8.8.8&amp;nbsp; 1024 202.175.xx.202 25&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 202.175.xx.202 using egress ifc&amp;nbsp; identity&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: xyz&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;&lt;BR /&gt;# packet-tracer input xyz tcp 8.8.8.8&amp;nbsp; 1024 202.175.xx.203 25&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network 172.16.100.3_25_xyz&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz) static 202.175.xx.203 service tcp smtp smtp &lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface DMZ&lt;BR /&gt;Untranslate 202.175.xx.203/25 to 172.16.100.3/25&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group xyz in interface xyz&lt;BR /&gt;access-list xyz extended permit tcp any host 172.16.100.3 eq smtp &lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: inspect-smtp&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect esmtp _default_esmtp_map &lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: FOVER&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (DMZ,xyz) source dynamic any interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 9&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW &lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 10&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 538894, packet dispatched to next module&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: xyz&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: DMZ&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:23:37 GMT</pubDate>
    <dc:creator>shiran.wang</dc:creator>
    <dc:date>2019-03-12T09:23:37Z</dc:date>
    <item>
      <title>ASA static nat</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035396#M135377</link>
      <description>&lt;P&gt;ASA version 9.6(3)1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;both nat have same configuration except 172.16.100.2 use interface, anyone have same question?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this object work fine&lt;/P&gt;
&lt;P&gt;object network 172.16.100.3_25_xx2&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz) static 202.175.xx.203 service tcp smtp smtp &lt;/P&gt;
&lt;P&gt;this object not work&lt;BR /&gt;&amp;nbsp;object network 172.16.100.2_25_xx1&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz) static interface service tcp smtp smtp&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Cisco Adaptive Security Appliance Software Version 9.6(3)1 &lt;BR /&gt;Device Manager Version 7.2(2)1&lt;BR /&gt;&lt;BR /&gt;Compiled on Thu 30-Mar-17 21:40 PDT by builders&lt;BR /&gt;System image file is "disk0:/asa963-1-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;BR /&gt;&lt;BR /&gt;packet-tracer input xyz tcp 8.8.8.8&amp;nbsp; 1024 202.175.xx.202 25&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 202.175.xx.202 using egress ifc&amp;nbsp; identity&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: xyz&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;&lt;BR /&gt;# packet-tracer input xyz tcp 8.8.8.8&amp;nbsp; 1024 202.175.xx.203 25&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network 172.16.100.3_25_xyz&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz) static 202.175.xx.203 service tcp smtp smtp &lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface DMZ&lt;BR /&gt;Untranslate 202.175.xx.203/25 to 172.16.100.3/25&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group xyz in interface xyz&lt;BR /&gt;access-list xyz extended permit tcp any host 172.16.100.3 eq smtp &lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: inspect-smtp&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect esmtp _default_esmtp_map &lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: FOVER&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (DMZ,xyz) source dynamic any interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 9&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW &lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 10&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 538894, packet dispatched to next module&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: xyz&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: DMZ&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035396#M135377</guid>
      <dc:creator>shiran.wang</dc:creator>
      <dc:date>2019-03-12T09:23:37Z</dc:date>
    </item>
    <item>
      <title>Can you post a "sh nat"
Jon</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035397#M135378</link>
      <description>&lt;P&gt;Can you post a "sh nat"&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2017 10:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035397#M135378</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2017-05-20T10:53:57Z</dc:date>
    </item>
    <item>
      <title> service tcp destination eq</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035398#M135383</link>
      <description>&lt;P&gt;&amp;nbsp;service tcp destination eq smtp &lt;BR /&gt;nat (ServerFarm,xyz2) source static object_10.10.120.0 object_10.10.120.0 destination static object_10.10.10.10.0 object_10.10.10.10.0&lt;BR /&gt;nat (ServerFarm,xyz1) source static object_10.10.120.0 object_10.10.120.0 destination static object_10.10.10.10.0 object_10.10.10.10.0&lt;BR /&gt;nat (Inside,xyz2) source dynamic any interface&lt;BR /&gt;nat (DMZ,xyz1) source dynamic any interface&lt;BR /&gt;nat (DMZ,xyz2) source dynamic any interface&lt;BR /&gt;nat (Inside,Informac) source dynamic any interface&lt;BR /&gt;nat (ServerFarm,Informac) source dynamic any interface&lt;BR /&gt;nat (WIFI_AP,xyz2) source dynamic any interface&lt;BR /&gt;nat (WIFI_AP,xyz1) source dynamic any interface&lt;BR /&gt;nat (ServerFarm,xyz1) source dynamic any interface&lt;BR /&gt;nat (ServerFarm,xyz2) source dynamic any interface&lt;BR /&gt;nat (WIFI_Staff,xyz2) source dynamic any interface&lt;BR /&gt;nat (WIFI_Staff,xyz1) source dynamic any interface&lt;BR /&gt;nat (WIFI_Guest,xyz2) source dynamic any interface&lt;BR /&gt;nat (WIFI_Guest,xyz1) source dynamic any interface&lt;BR /&gt;nat (WIFI_Media,xyz2) source dynamic any interface&lt;BR /&gt;nat (WIFI_Media,xyz1) source dynamic any interface&lt;BR /&gt;nat (CCenter,xyz2) source dynamic any interface&lt;BR /&gt;nat (CCenter,xyz1) source dynamic any interface&lt;BR /&gt;nat (Inside,xyz1) source dynamic any interface&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz1) static 202.175.xx.203 service tcp smtp smtp &lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz1) static 202.175.xx.203 service tcp https https &lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz1) static 202.175.xx.203 service tcp www www &lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz1) static 202.175.xx.204&lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz1) static 202.175.xx.205 service tcp https https &lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz1) static 202.175.xx.205 service tcp www www &lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz2) static 182.93.x1.27 service tcp smtp smtp &lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz2) static 182.93.x1.28 service tcp smtp smtp &lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz2) static 182.93.x1.27 service tcp https https &lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz2) static 182.93.x1.27 service tcp www www &lt;BR /&gt;&amp;nbsp;nat (ServerFarm,xyz2) static 182.93.x1.29&lt;BR /&gt;&amp;nbsp;nat (DMZ,xyz1) static 202.175.xx.202 service tcp smtp smtp&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2017 13:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035398#M135383</guid>
      <dc:creator>shiran.wang</dc:creator>
      <dc:date>2017-05-20T13:34:39Z</dc:date>
    </item>
    <item>
      <title>I'm not sure that is the</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035399#M135386</link>
      <description>&lt;P&gt;I'm not sure that is the output of "sh nat" ie. it should show the hits etc.&lt;/P&gt;
&lt;P&gt;I think the problem is with the order of your NAT rules but I need to see the proper output first.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2017 13:55:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat/m-p/3035399#M135386</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2017-05-20T13:55:43Z</dc:date>
    </item>
  </channel>
</rss>

