<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/3042385#M146721</link>
    <description>&lt;P&gt;Dear All&lt;/P&gt;
&lt;P&gt;I have configured two static NAT rules on ASA which is running 9.1 OS version.&lt;/P&gt;
&lt;P&gt;`configuration is like&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ist Nat rule&lt;/P&gt;
&lt;P&gt;Real &amp;nbsp;IP 10.50.1.16 Mapped IP 192.168.200.1 with source port 80 and destination port 80&lt;/P&gt;
&lt;P&gt;Second Nat Rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Real &amp;nbsp;IP 10.50.1.16 Mapped IP 192.168.200.1 with source port 83 and destination port 83&lt;/P&gt;
&lt;P&gt;And all nat rules are object nat.&lt;/P&gt;
&lt;P&gt;first Nat rule is working but second is not working. &amp;nbsp;I have attached the logs also.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Recommended Action is :&lt;/P&gt;
&lt;P class="peaerract"&gt;When not on the same interface as the host using NAT, use the mapped address instead of the actual address to connect to the host. In addition, enable the &lt;B&gt;inspect&lt;/B&gt; command if the application embeds the IP address.&lt;/P&gt;
&lt;P class="peaerract"&gt;Could any can help me to sort out this issue.&lt;/P&gt;
&lt;P class="peaerract"&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P class="peaerract"&gt;Tony&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:53:56 GMT</pubDate>
    <dc:creator>tonysebastian</dc:creator>
    <dc:date>2019-03-12T08:53:56Z</dc:date>
    <item>
      <title>NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/3042385#M146721</link>
      <description>&lt;P&gt;Dear All&lt;/P&gt;
&lt;P&gt;I have configured two static NAT rules on ASA which is running 9.1 OS version.&lt;/P&gt;
&lt;P&gt;`configuration is like&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ist Nat rule&lt;/P&gt;
&lt;P&gt;Real &amp;nbsp;IP 10.50.1.16 Mapped IP 192.168.200.1 with source port 80 and destination port 80&lt;/P&gt;
&lt;P&gt;Second Nat Rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Real &amp;nbsp;IP 10.50.1.16 Mapped IP 192.168.200.1 with source port 83 and destination port 83&lt;/P&gt;
&lt;P&gt;And all nat rules are object nat.&lt;/P&gt;
&lt;P&gt;first Nat rule is working but second is not working. &amp;nbsp;I have attached the logs also.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Recommended Action is :&lt;/P&gt;
&lt;P class="peaerract"&gt;When not on the same interface as the host using NAT, use the mapped address instead of the actual address to connect to the host. In addition, enable the &lt;B&gt;inspect&lt;/B&gt; command if the application embeds the IP address.&lt;/P&gt;
&lt;P class="peaerract"&gt;Could any can help me to sort out this issue.&lt;/P&gt;
&lt;P class="peaerract"&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P class="peaerract"&gt;Tony&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/3042385#M146721</guid>
      <dc:creator>tonysebastian</dc:creator>
      <dc:date>2019-03-12T08:53:56Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/3042386#M146727</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In 1 case, it seems that you're missing a statement in your outside acl and the other shows up an asymmetric routing issue.&lt;/P&gt;
&lt;P&gt;Could you drop a txt file with your config? and also output of packet-tracer command?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 14:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/3042386#M146727</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-02-08T14:18:09Z</dc:date>
    </item>
  </channel>
</rss>

