<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Marius, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-v8-2-4-no-matching-global-nat-problem/m-p/2901389#M167940</link>
    <description>&lt;P&gt;Hello Marius,&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;The nat-control is disabled:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA-5520-1p2-CORE# show run nat-control&lt;BR /&gt;no nat-control&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So the only way is to add nat 0 statement for the storage interface?&lt;/P&gt;
&lt;P&gt;Why I don't have any problems with communication between mgm and storage?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2016 11:56:52 GMT</pubDate>
    <dc:creator>Daave2016</dc:creator>
    <dc:date>2016-02-25T11:56:52Z</dc:date>
    <item>
      <title>Cisco ASA v8.2(4) - No matching global NAT problem.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-v8-2-4-no-matching-global-nat-problem/m-p/2901387#M167936</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I am new in Cisco ASA Firewalls. Now I'm using Cisco ASA with IOS Version 8.2(4). Appliance is configured and properly working, but I need to make some configuration changes. I want to allow communication between VLANs: 80 (emp) and 101 (storage). To do that I have put following command to avoid translation between VLANs:&lt;BR /&gt;&lt;BR /&gt;static (emp,storage) 10.1.8.0 10.1.8.0 netmask 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;but it doesn't work:&lt;BR /&gt;&lt;BR /&gt;# packet-tracer input emp tcp 10.1.8.10 www 172.16.0.254 www&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 172.16.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; storage&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group emp_acl in interface emp&lt;BR /&gt;access-list emp_acl extended permit ip 10.1.8.0 255.255.255.0 any&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (emp,storage) 10.1.8.0 10.1.8.0 netmask 255.255.255.0&lt;BR /&gt;&amp;nbsp; match ip emp 10.1.8.0 255.255.255.0 storage any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.1.8.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 131, untranslate_hits = 19&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 10.1.8.0/0 to 10.1.8.0/0 using netmask 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (emp,BMS) 10.1.8.0 10.1.8.0 netmask 255.255.255.0&lt;BR /&gt;&amp;nbsp; match ip emp 10.1.8.0 255.255.255.0 BMS any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.1.8.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 3187127, untranslate_hits = 3209014&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (storage) 1 172.16.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp; match ip storage 172.16.0.0 255.255.255.0 emp any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 3, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: emp&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: storage&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;I am confused because communication between VLANs 100 and 101 occurs:&lt;BR /&gt;&lt;BR /&gt;# packet-tracer input mgm tcp 10.1.10.200 www 172.16.0.254 www&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 172.16.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; storage&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group mgm_acl in interface mgm&lt;BR /&gt;access-list mgm_acl extended permit ip 10.1.10.0 255.255.255.0 any&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (mgm,storage) 10.1.10.0 10.1.10.0 netmask 255.255.255.0&lt;BR /&gt;&amp;nbsp; match ip mgm 10.1.10.0 255.255.255.0 storage any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.1.10.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 2413235, untranslate_hits = 219750&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 10.1.10.0/0 to 10.1.10.0/0 using netmask 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (mgm,DNS) 10.1.10.0 10.1.10.0 netmask 255.255.255.0&lt;BR /&gt;&amp;nbsp; match ip mgm 10.1.10.0 255.255.255.0 DNS any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.1.10.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (storage,BMS) 172.16.0.0 172.16.0.0 netmask 255.255.255.0&lt;BR /&gt;&amp;nbsp; match ip storage 172.16.0.0 255.255.255.0 BMS any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 172.16.0.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 66, untranslate_hits = 1138372&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 9&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 287955213, packet dispatched to next module&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: mgm&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: storage&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;Current config below:&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.80&lt;BR /&gt;&amp;nbsp;vlan 80&lt;BR /&gt;&amp;nbsp;nameif emp&lt;BR /&gt;&amp;nbsp;security-level 90&lt;BR /&gt;&amp;nbsp;ip address 10.1.8.1 255.255.255.0 standby 10.1.8.2&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.100&lt;BR /&gt;&amp;nbsp;vlan 100&lt;BR /&gt;&amp;nbsp;nameif mgm&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.1.10.1 255.255.255.0 standby 10.1.10.2&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.101&lt;BR /&gt;&amp;nbsp;vlan 101&lt;BR /&gt;&amp;nbsp;nameif storage&lt;BR /&gt;&amp;nbsp;security-level 91&lt;BR /&gt;&amp;nbsp;ip address 172.16.0.1 255.255.255.0 standby 172.16.0.2&lt;BR /&gt;!&lt;BR /&gt;...&lt;BR /&gt;!&lt;BR /&gt;global (outside) 1 XX.YY.ZZ.238&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;global (outside) 2 XX.YY.ZZ.237&lt;BR /&gt;global (outside) 3 XX.YY.ZZ.236&lt;BR /&gt;global (outside) 4 XX.YY.ZZ.235&lt;BR /&gt;global (outside) 5 XX.YY.ZZ.100&lt;BR /&gt;global (outside) 6 XX.YY.ZZ.160&lt;BR /&gt;global (outside) 7 192.168.1.10&lt;BR /&gt;global (outside) 8 XX.YY.ZZ.112&lt;BR /&gt;nat (BMS) 0 access-list r-vpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nat (BMS) 1 10.1.0.0 255.255.254.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;nat (blue) 5 10.1.2.0 255.255.255.0&lt;BR /&gt;nat (grey) 8 10.1.12.0 255.255.255.0&lt;BR /&gt;nat (parking) 3 10.44.9.0 255.255.255.0&lt;BR /&gt;nat (emp) 0 access-list r-vpn&lt;BR /&gt;nat (emp) 6 10.1.8.0 255.255.255.0&lt;BR /&gt;nat (mgm) 2 10.1.10.0 255.255.255.0&lt;BR /&gt;nat (storage) 1 172.16.0.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;...&lt;BR /&gt;!&lt;BR /&gt;static (mgm,storage) 10.1.10.0 10.1.10.0 netmask 255.255.255.0&lt;BR /&gt;static (emp,storage) 10.1.8.0 10.1.8.0 netmask 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;...&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;What should I do? &lt;BR /&gt;Modify: nat (storage) 1 172.16.0.0 255.255.255.0 or increase VLANs 80 security-level to 91?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-v8-2-4-no-matching-global-nat-problem/m-p/2901387#M167936</guid>
      <dc:creator>Daave2016</dc:creator>
      <dc:date>2019-03-12T07:23:58Z</dc:date>
    </item>
    <item>
      <title>I am assuming you have NAT</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-v8-2-4-no-matching-global-nat-problem/m-p/2901388#M167938</link>
      <description>&lt;P&gt;I am assuming you have NAT control configure?&lt;/P&gt;
&lt;P&gt;show run nat-control&lt;/P&gt;
&lt;P&gt;I would suggest either disabling nat-control or adding a nat 0 statement for the storage interface.&lt;/P&gt;
&lt;P&gt;Personally I would disable nat-control.&lt;/P&gt;
&lt;P&gt;raising the security level will not have any effect in this situation. &amp;nbsp;And if you have access-lists configured on the interfaces the security levels are not even used.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 11:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-v8-2-4-no-matching-global-nat-problem/m-p/2901388#M167938</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2016-02-25T11:51:48Z</dc:date>
    </item>
    <item>
      <title>Hello Marius,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-v8-2-4-no-matching-global-nat-problem/m-p/2901389#M167940</link>
      <description>&lt;P&gt;Hello Marius,&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;The nat-control is disabled:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA-5520-1p2-CORE# show run nat-control&lt;BR /&gt;no nat-control&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So the only way is to add nat 0 statement for the storage interface?&lt;/P&gt;
&lt;P&gt;Why I don't have any problems with communication between mgm and storage?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 11:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-v8-2-4-no-matching-global-nat-problem/m-p/2901389#M167940</guid>
      <dc:creator>Daave2016</dc:creator>
      <dc:date>2016-02-25T11:56:52Z</dc:date>
    </item>
  </channel>
</rss>

