<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Destination NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985636#M155592</link>
    <description>&lt;P&gt;Please Help. Not able to get the answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/outside_to_inside_nat.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;Using GNS3 with ASA 8.4 &amp;amp; ASDM 7.1.&lt;/P&gt;
&lt;P&gt;Can ping from inside to outside but cannot ping from DMZ to Outside.&lt;/P&gt;
&lt;P&gt;Cannot ping from outside to inside or DMZ.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Router on Outside interface is just to see whether ping packets are reaching or not ( using Debug ip icmp).&lt;/P&gt;
&lt;P&gt;Using Virtual box to access ASDM on XP. So no configuration for Gigabit Ethernet Interface 03.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:13:09 GMT</pubDate>
    <dc:creator>kuskur.vishwanatha</dc:creator>
    <dc:date>2019-03-12T08:13:09Z</dc:date>
    <item>
      <title>Destination NAT</title>
      <link>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985636#M155592</link>
      <description>&lt;P&gt;Please Help. Not able to get the answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/outside_to_inside_nat.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;Using GNS3 with ASA 8.4 &amp;amp; ASDM 7.1.&lt;/P&gt;
&lt;P&gt;Can ping from inside to outside but cannot ping from DMZ to Outside.&lt;/P&gt;
&lt;P&gt;Cannot ping from outside to inside or DMZ.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Router on Outside interface is just to see whether ping packets are reaching or not ( using Debug ip icmp).&lt;/P&gt;
&lt;P&gt;Using Virtual box to access ASDM on XP. So no configuration for Gigabit Ethernet Interface 03.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985636#M155592</guid>
      <dc:creator>kuskur.vishwanatha</dc:creator>
      <dc:date>2019-03-12T08:13:09Z</dc:date>
    </item>
    <item>
      <title>Very Simple by defualt trafic</title>
      <link>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985637#M155593</link>
      <description>&lt;P&gt;Very Simple by defualt trafic from lower security-level to higher security level not permit. As per your config&lt;/P&gt;
&lt;P&gt;Outside security level&amp;nbsp;0&lt;/P&gt;
&lt;P&gt;inside security level is 100&lt;/P&gt;
&lt;P&gt;dmz security level 50&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You have to add below command to allow traffic from same or lower security level to higher oe same security level interafce.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;same-security-traffic permit inter-interface&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Pawan CCIE 52104&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kindly rate for useful post&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2016 12:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985637#M155593</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2016-09-01T12:12:50Z</dc:date>
    </item>
    <item>
      <title>Thank you.</title>
      <link>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985638#M155594</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;But CCNA security exam require&amp;nbsp; to configure these using ASDM only.&lt;/P&gt;
&lt;P&gt;Can you tell me how to configure using ASDM.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;NAT statements are in place. Referred some documents &amp;amp; CBT nuggets. But not able to ping.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Vishwa&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2016 12:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985638#M155594</guid>
      <dc:creator>kuskur.vishwanatha</dc:creator>
      <dc:date>2016-09-01T12:33:10Z</dc:date>
    </item>
    <item>
      <title>When ping from PC 1 to R1 (</title>
      <link>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985639#M155595</link>
      <description>&lt;P&gt;When ping from PC 1 to R1 ( inside to outside ), Ping was successful with&amp;nbsp; following debug output on ASA.&lt;/P&gt;
&lt;P&gt;ciscoasa# ICMP echo request from inside:10.1.0.2 to outside:1.2.3.4 ID=27351 seq=1 len=56&lt;BR /&gt;ICMP echo request translating &lt;STRONG&gt;inside&lt;/STRONG&gt;:&lt;STRONG&gt;10.1.0.2 to outside:1.2.3.10&lt;/STRONG&gt;&lt;BR /&gt;ICMP echo reply from outside:1.2.3.4 to inside:1.2.3.10 ID=27351 seq=1 len=56&lt;BR /&gt;ICMP echo reply untranslating &lt;STRONG&gt;outside&lt;/STRONG&gt;:&lt;STRONG&gt;1.2.3.10 to inside:10.1.0.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When Ping from PC 2 to R1 ( dmz to outside ), 1.2.3.4 icmp_seq=1 timeout observed with debug output on ASA.&lt;/P&gt;
&lt;P&gt;ciscoasa# ICMP echo request from dmz:172.16.0.2 to outside:1.2.3.4 ID=48344 seq=1 len=56&lt;BR /&gt;ICMP echo request translating &lt;STRONG&gt;dmz&lt;/STRONG&gt;:&lt;STRONG&gt;172.16.0.2 to outside:1.2.3.10&lt;/STRONG&gt;&lt;BR /&gt;ICMP echo reply from outside:1.2.3.4 to inside:1.2.3.10 ID=48344 seq=1 len=56&lt;BR /&gt;ICMP echo reply untranslating &lt;STRONG&gt;outside:1.2.3.10 to inside:10.1.0.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Not able to make out why the untranslation going to 10.1.0.2 instead of 172.16.0.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Vishwa&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2016 01:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/destination-nat/m-p/2985639#M155595</guid>
      <dc:creator>kuskur.vishwanatha</dc:creator>
      <dc:date>2016-09-02T01:44:11Z</dc:date>
    </item>
  </channel>
</rss>

