<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic subnet (123.123.123.192/26) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081568#M146121</link>
    <description>&lt;P&gt;subnet&amp;nbsp;&lt;SPAN&gt;(123.123.123.192/26) is public IP? is it known to your ISP?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2017 17:03:45 GMT</pubDate>
    <dc:creator>Hassan Chalabi</dc:creator>
    <dc:date>2017-03-02T17:03:45Z</dc:date>
    <item>
      <title>ASA Routing/NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081567#M146118</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have an ASA running 9.7 which has a public ip (222.222.222.222) assigned to its outside interface and a default gw pointing to the first address in the 222.222.222 -network.&lt;/P&gt;
&lt;P&gt;I then route another subnet (123.123.123.192/26) to the ASA's outside address.&lt;/P&gt;
&lt;P&gt;When i try to perform dynamic nat (PAT) for one of the &amp;nbsp;inside interfaces to one of the public ip's&amp;nbsp;in the&amp;nbsp;&lt;SPAN&gt;123.123.123.192/27 range, no traffic is passed, even though i can see the states being created and ARP entries in the router.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The 'permit arp not-connected' feature is turned on.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When changing the object nat to the outside ip&amp;nbsp;&lt;SPAN&gt;222.222.222.222, traffic flows without any problem.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any idea why this is?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081567#M146118</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2019-03-12T09:00:12Z</dc:date>
    </item>
    <item>
      <title>subnet (123.123.123.192/26)</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081568#M146121</link>
      <description>&lt;P&gt;subnet&amp;nbsp;&lt;SPAN&gt;(123.123.123.192/26) is public IP? is it known to your ISP?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 17:03:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081568#M146121</guid>
      <dc:creator>Hassan Chalabi</dc:creator>
      <dc:date>2017-03-02T17:03:45Z</dc:date>
    </item>
    <item>
      <title>Yes.</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081569#M146123</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 17:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081569#M146123</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2017-03-02T17:51:20Z</dc:date>
    </item>
    <item>
      <title>check the gateway of 123.123</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081570#M146126</link>
      <description>&lt;P&gt;check the gateway of&amp;nbsp;&lt;SPAN&gt;123.123.123.192/26 if it is reachable, I am assuming this is a secondary subnet from the ISP that comes from the same interface of the edge router to the outside interface of the FW.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 18:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081570#M146126</guid>
      <dc:creator>Hassan Chalabi</dc:creator>
      <dc:date>2017-03-02T18:04:17Z</dc:date>
    </item>
    <item>
      <title>The gateway of 123.123.123</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081571#M146131</link>
      <description>&lt;P&gt;The gateway of &lt;SPAN&gt;123.123.123.192/26&lt;/SPAN&gt; is reachable. And yes, the subnet comes in on the same (outside) interface to the ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 19:57:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081571#M146131</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2017-03-02T19:57:06Z</dc:date>
    </item>
    <item>
      <title>can you post packet tracer</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081572#M146134</link>
      <description>&lt;P&gt;can you post packet tracer output?&lt;/P&gt;
&lt;P&gt;run one from an inside ip icmp to 8.8.8.8 after you NAT to the secondary subnet.&lt;/P&gt;
&lt;P&gt;something like:&lt;/P&gt;
&lt;P&gt;ASA#packet-tracer input inside icmp 10.0.0.1 0 0 8.8.8.8&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 20:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081572#M146134</guid>
      <dc:creator>Hassan Chalabi</dc:creator>
      <dc:date>2017-03-02T20:02:33Z</dc:date>
    </item>
    <item>
      <title>Interface names and public ip</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081573#M146136</link>
      <description>&lt;P&gt;Interface names and public ip's have been changed to obscure the original customer&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; color: #000080;"&gt;packet-tracer input inside icmp &amp;lt;inside-ip&amp;gt; 0 0 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 222.222.222.1 using egress ifc Outside&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network INSIDE-OUTSIDE-NAT&lt;BR /&gt;&amp;nbsp;nat (INSIDE-INTERFACE,OUTSIDE) dynamic &lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: &amp;lt;Inside-interface&amp;gt;&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Action: drop&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Drop-reason: (nat-xlate-failed) NAT failed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 20:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-nat-problem/m-p/3081573#M146136</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2017-03-02T20:48:45Z</dc:date>
    </item>
  </channel>
</rss>

