<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What does the output of &amp;quot;show in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925012#M154360</link>
    <description>&lt;P&gt;What does the output of "show conn count" and "show xlate count" look like when the problem is happening?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please also check with your ISP if they block any ports.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2016 20:24:44 GMT</pubDate>
    <dc:creator>Tristan Cober</dc:creator>
    <dc:date>2016-04-28T20:24:44Z</dc:date>
    <item>
      <title>NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925008#M154356</link>
      <description>&lt;P&gt;Hello folks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have 02 ASA 5555X in H.A and the very strange thing is happening.&lt;/P&gt;
&lt;P&gt;I have many NAT configured, but only NAT to internet stop to work and return only after reboot.&lt;/P&gt;
&lt;P&gt;ASA IOS:&amp;nbsp;asa952-smp-k8.bin&lt;/P&gt;
&lt;P&gt;Anyone know something about this problem?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Marcio&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:41:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925008#M154356</guid>
      <dc:creator>marcio.tormente</dc:creator>
      <dc:date>2019-03-12T07:41:07Z</dc:date>
    </item>
    <item>
      <title>Hi Marcio,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925009#M154357</link>
      <description>&lt;P&gt;Hi Marcio,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any logs during the problem? Do you notice all users getting affected or only few users? Could be a nat pool exhaustion problem?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kanwal&lt;/P&gt;
&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 19:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925009#M154357</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2016-04-28T19:40:20Z</dc:date>
    </item>
    <item>
      <title>Hi Fnu,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925010#M154358</link>
      <description>&lt;P&gt;Hi Fnu,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your support.&lt;/P&gt;
&lt;P&gt;There is no log about, only stop to work and for all users.&lt;/P&gt;
&lt;P&gt;In this ASA there are 02 links and both stop.&lt;/P&gt;
&lt;P&gt;I don´t believe the problem is exhaustion, unless ASA is worst then Checkpoint, because one month ago I migrate from checkpoint to ASA and this problema never happened while the client was using Checkpoint.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 19:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925010#M154358</guid>
      <dc:creator>marcio.tormente</dc:creator>
      <dc:date>2016-04-28T19:55:14Z</dc:date>
    </item>
    <item>
      <title>Hi Marcio,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925011#M154359</link>
      <description>&lt;P&gt;Hi Marcio,&lt;/P&gt;
&lt;P&gt;Thank you for your reply.&lt;/P&gt;
&lt;P&gt;Are you able to ping the default gateway during the problem i.e from the firewall its default gateway? How about ARP status on both gateway and ASA?&lt;/P&gt;
&lt;P&gt;Can you share your configuration? Can you do clear asp drop and then take couple of outputs of "show asp drop" and see which counter is increasing?&lt;/P&gt;
&lt;P&gt;Can we take pcaps on inside and outside interface for one user and see if the packets are making it from inside to outside interface ?&lt;/P&gt;
&lt;P&gt;What is the logging level set on ASA? Can you increase it to debug level during the problem and see what you get ? If firewall is dropping it, it must log the reason for it.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kanwal&lt;/P&gt;
&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 20:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925011#M154359</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2016-04-28T20:19:00Z</dc:date>
    </item>
    <item>
      <title>What does the output of "show</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925012#M154360</link>
      <description>&lt;P&gt;What does the output of "show conn count" and "show xlate count" look like when the problem is happening?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please also check with your ISP if they block any ports.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 20:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925012#M154360</guid>
      <dc:creator>Tristan Cober</dc:creator>
      <dc:date>2016-04-28T20:24:44Z</dc:date>
    </item>
    <item>
      <title>Hi Fnu,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925013#M154361</link>
      <description>&lt;P&gt;Hi Fnu,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Follow the configuration attached.&lt;/P&gt;
&lt;P&gt;Yes, is possible to ping the ASA, everything remain working, only the NAT to internet that stop.&lt;/P&gt;
&lt;P&gt;The problem is not happening now, but when happen, I have no time enoght to collect information. The client want to service orking ASAP, then, reboot is the best option.&lt;/P&gt;
&lt;P&gt;I made many clear comand, such as xlate, but didn´t work.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 20:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925013#M154361</guid>
      <dc:creator>marcio.tormente</dc:creator>
      <dc:date>2016-04-28T20:51:16Z</dc:date>
    </item>
    <item>
      <title>Hi Marcio,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925014#M154362</link>
      <description>&lt;P&gt;Hi Marcio,&lt;/P&gt;
&lt;P&gt;Thank you for the configuration.&lt;/P&gt;
&lt;P&gt;Please tell me which NAT rule stops working? Also, is it random or happens at a specific time or after sometime?&lt;/P&gt;
&lt;P&gt;How often the issue happens? Since we are pressed for time, can we at least take two instances of show tech during the problem before reload is performed?&lt;/P&gt;
&lt;P&gt;Also, if the recurrence of issue is pretty frequent, can we bump up the logging level and wait for the next occurrence?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kanwal&lt;/P&gt;
&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 20:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925014#M154362</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2016-04-28T20:58:12Z</dc:date>
    </item>
    <item>
      <title>Hello Tristan,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925015#M154363</link>
      <description>&lt;P&gt;Hello Tristan,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The problem is not happening now, for this reason the show is normal, but I´m trying to undertand why&amp;nbsp;suddenly its happen.&lt;/P&gt;
&lt;P&gt;ASA-SSP-Pri# sh conn count&lt;BR /&gt;2583 in use, 3380 most used!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ASA-SSP-Pri# sh xlate count&lt;BR /&gt;2274 in use, 3258 most used&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 20:59:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925015#M154363</guid>
      <dc:creator>marcio.tormente</dc:creator>
      <dc:date>2016-04-28T20:59:15Z</dc:date>
    </item>
    <item>
      <title>Hi Fnu,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925016#M154364</link>
      <description>&lt;P&gt;Hi Fnu,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This problem happens in random time, since I made the migration (last month) its happen 03x in diffentes days and hours of the day.&lt;/P&gt;
&lt;P&gt;I can take the show take next time when happen.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 21:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925016#M154364</guid>
      <dc:creator>marcio.tormente</dc:creator>
      <dc:date>2016-04-28T21:03:59Z</dc:date>
    </item>
    <item>
      <title>Hi Marcio,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925017#M154365</link>
      <description>&lt;P&gt;Hi Marcio,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please specify which traffic is affected ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_80 gr-alert gr_gramm gr_run_anim Punctuation multiReplace" id="80" data-gr-id="80"&gt;Also&lt;/G&gt; what NAT is being used for it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Take the following outputs:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sh nat detail&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sh asp drop ( continuous outputs after an interval of few seconds)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show &lt;G class="gr_ gr_183 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="183" data-gr-id="183"&gt;cpu&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show blocks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show memory&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show process &lt;G class="gr_ gr_215 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="215" data-gr-id="215"&gt;cpu&lt;/G&gt;-usage non-zero sorted&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 07:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925017#M154365</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-04-29T07:30:09Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya.</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925018#M154366</link>
      <description>&lt;P&gt;Hi Aditya.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your support&lt;/P&gt;
&lt;P&gt;All the network that is behind Internal interface who whant to access the internet is affected.&lt;/P&gt;
&lt;P&gt;For this networks I´m using Network object Nat.&lt;/P&gt;
&lt;P&gt;Follow attached the commands.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 13:25:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925018#M154366</guid>
      <dc:creator>marcio.tormente</dc:creator>
      <dc:date>2016-04-29T13:25:24Z</dc:date>
    </item>
    <item>
      <title>Hi Marcio,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925019#M154367</link>
      <description>&lt;P&gt;Hi Marcio,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is this taken at the time of the issue ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_148 gr-alert gr_gramm gr_run_anim Punctuation multiReplace" id="148" data-gr-id="148"&gt;Also&lt;/G&gt; when the issue is there please clear asp drop and take multiple outputs of show asp drop.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 13:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925019#M154367</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-04-29T13:31:16Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925020#M154368</link>
      <description>&lt;P&gt;Hi Aditya,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No, at this time, everything is normal.&lt;/P&gt;
&lt;P&gt;In 30 days thys problem happen 03 times, I just want understand why and avoid this happen again.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 13:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem/m-p/2925020#M154368</guid>
      <dc:creator>marcio.tormente</dc:creator>
      <dc:date>2016-04-29T13:45:03Z</dc:date>
    </item>
  </channel>
</rss>

