<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic @ryan.lambert   in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/server-w-static-nat-can-t-browse-internet/m-p/2927135#M156974</link>
    <description>&lt;P&gt;&lt;SPAN&gt;[@ryan.lambert]&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please take these below packet-tracers:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#packet-tracer input outside match icmp 8.8.8.8 8 0 &amp;lt;server_public_ip&amp;gt; det&lt;/P&gt;
&lt;P&gt;#packet-tracer input inside &amp;lt;server_private_ip&amp;gt; 8 0 8.8.8.8 det&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can try also take captures on ASA inside and outside interfaces to see if traffic reach and left the ASA:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jul 2016 06:03:26 GMT</pubDate>
    <dc:creator>Dina Odeh</dc:creator>
    <dc:date>2016-07-18T06:03:26Z</dc:date>
    <item>
      <title>Server w/static NAT can't browse internet</title>
      <link>https://community.cisco.com/t5/network-security/server-w-static-nat-can-t-browse-internet/m-p/2927133#M156972</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a server that is NATed from a private address to a public address (static 1:1), and while inbound traffic to it works, if it tries to browse the internet it cannot. Other things on the internal 10.x.12.x network can browse just fine, unless they also have a static NAT. Name resolution works fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This definitely seems related to NAT, but not sure what. There's a lot of cruft in this config that needs removed, but I'll post it here. Most of this looks like leftovers from an upgrade/translate.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Doc attached. Any ideas why static NAT hosts can't get out, but inbound works fine?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thx.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-w-static-nat-can-t-browse-internet/m-p/2927133#M156972</guid>
      <dc:creator>ryan.lambert</dc:creator>
      <dc:date>2019-03-12T08:01:27Z</dc:date>
    </item>
    <item>
      <title>Should note:</title>
      <link>https://community.cisco.com/t5/network-security/server-w-static-nat-can-t-browse-internet/m-p/2927134#M156973</link>
      <description>&lt;P&gt;Should note:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The host with the static NAT is found on interface "inside". Probably relevant info. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 19:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-w-static-nat-can-t-browse-internet/m-p/2927134#M156973</guid>
      <dc:creator>ryan.lambert</dc:creator>
      <dc:date>2016-07-14T19:36:56Z</dc:date>
    </item>
    <item>
      <title>@ryan.lambert  </title>
      <link>https://community.cisco.com/t5/network-security/server-w-static-nat-can-t-browse-internet/m-p/2927135#M156974</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[@ryan.lambert]&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please take these below packet-tracers:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#packet-tracer input outside match icmp 8.8.8.8 8 0 &amp;lt;server_public_ip&amp;gt; det&lt;/P&gt;
&lt;P&gt;#packet-tracer input inside &amp;lt;server_private_ip&amp;gt; 8 0 8.8.8.8 det&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can try also take captures on ASA inside and outside interfaces to see if traffic reach and left the ASA:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 06:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-w-static-nat-can-t-browse-internet/m-p/2927135#M156974</guid>
      <dc:creator>Dina Odeh</dc:creator>
      <dc:date>2016-07-18T06:03:26Z</dc:date>
    </item>
  </channel>
</rss>

