<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Gelo, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792217#M173595</link>
    <description>&lt;P&gt;Hi Gelo,&lt;/P&gt;
&lt;P&gt;As per my understanding inside users would like to access the server from the public IP. If your server and users who want&amp;nbsp;to connect are in the same interface then you can configure a hair-pin NAT for this.&lt;/P&gt;
&lt;P&gt;Below is the configuration template for OS version 8.3 and above.&lt;/P&gt;
&lt;P&gt;nat (inside,inside) source dynamic &amp;lt;Private-Addresses object&amp;gt; interface destination static [PUBLIC-ADDRESS-OBJECT][[PRIVATE-ADDRESS-OBJECT]&lt;/P&gt;
&lt;P&gt;Also you need to enable traffic between the same security level.&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jan 2016 06:54:38 GMT</pubDate>
    <dc:creator>Shivapramod M</dc:creator>
    <dc:date>2016-01-05T06:54:38Z</dc:date>
    <item>
      <title>Can't Access Translated Public FTP server via Internal Network</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792216#M173594</link>
      <description>&lt;P&gt;Hi Cisco Support,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Greetings and Happy New year!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible from internal users can access the translated public ftp server? The ASA itself translate the internal FTP to public. The client wants to access the FTP server using Public IP even they're on the internal network. Hope your prompt response as soonest.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you and Have a great day!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Gelo&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792216#M173594</guid>
      <dc:creator>geloangelo00</dc:creator>
      <dc:date>2019-03-12T07:06:20Z</dc:date>
    </item>
    <item>
      <title>Hi Gelo,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792217#M173595</link>
      <description>&lt;P&gt;Hi Gelo,&lt;/P&gt;
&lt;P&gt;As per my understanding inside users would like to access the server from the public IP. If your server and users who want&amp;nbsp;to connect are in the same interface then you can configure a hair-pin NAT for this.&lt;/P&gt;
&lt;P&gt;Below is the configuration template for OS version 8.3 and above.&lt;/P&gt;
&lt;P&gt;nat (inside,inside) source dynamic &amp;lt;Private-Addresses object&amp;gt; interface destination static [PUBLIC-ADDRESS-OBJECT][[PRIVATE-ADDRESS-OBJECT]&lt;/P&gt;
&lt;P&gt;Also you need to enable traffic between the same security level.&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 06:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792217#M173595</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2016-01-05T06:54:38Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792218#M173596</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;yes it is possible. It is similar to Users accessing Internet. Make sure you are translating the Client ip address so that they could reach Internet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are the users able to access Internet?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Run packet tracer and check where the connection is failing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Bhavik Shah&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 07:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792218#M173596</guid>
      <dc:creator>bhavsha2</dc:creator>
      <dc:date>2016-01-05T07:11:30Z</dc:date>
    </item>
    <item>
      <title>Hi Shivap,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792219#M173597</link>
      <description>&lt;P&gt;Hi Shivap,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What do you mean by "&amp;lt;Private-Addresses object&amp;gt;" is this the whole subnet (192.168.1.0/24 for example)? and the "[PUBLIC-ADDRESS-OBJECT]" is this the translated public address of the ftp server(1.1.1.50 for example)?&amp;nbsp; Sorry if i misunderstood something about the natting thing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 07:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792219#M173597</guid>
      <dc:creator>geloangelo00</dc:creator>
      <dc:date>2016-01-05T07:21:42Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792220#M173598</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, here is a sample configuration. change&amp;nbsp;your IP address accordingly.&lt;/P&gt;
&lt;P&gt;int Eth0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; ip address 1.2.3.1 255.255.255.0&lt;BR /&gt; security-level 0&lt;/P&gt;
&lt;P&gt;int Eth0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; ip address 192.168.1.1 255.255.255.0&lt;BR /&gt; security-level 90&lt;/P&gt;
&lt;P&gt;obj net obj-host-192.168.1.250&lt;BR /&gt; host 192.168.1.250&lt;/P&gt;
&lt;P&gt;obj net obj-host-1.2.3.250&lt;BR /&gt; host 1.2.3.250&lt;BR /&gt; nat (inside,outside) static obj-host-192.168.1.250&lt;/P&gt;
&lt;P&gt;nat (inside,inside) source dynamic any interface destination static obj-host-1.2.3.250 obj-host-192.168.1.250&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;here&amp;nbsp;&lt;SPAN&gt;192.168.1.250 is the server real IP and&amp;nbsp;1.2.3.250 is the public IP of the server&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;&lt;SPAN&gt;Shivapramod M&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Please remember to select a correct answer and rate helpful posts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 07:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792220#M173598</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2016-01-05T07:29:00Z</dc:date>
    </item>
    <item>
      <title>Hi again,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792221#M173600</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;
&lt;P&gt;Is it ok for this configuration? I think you gave me is the reverse public to internal translation of the server. To make us understand is from internal to public translation.&lt;/P&gt;
&lt;P&gt;obj net obj-host-192.168.1.250&lt;BR /&gt; host 192.168.1.250&lt;/P&gt;
&lt;P&gt;nat (inside,outside) obj-host-1.2.3.250&lt;/P&gt;
&lt;P&gt;obj net obj-host-1.2.3.250&lt;BR /&gt; host 1.2.3.250&lt;/P&gt;
&lt;P&gt;nat (inside,inside) source dynamic any interface destination static obj-host-192.168.1.250 obj-host-1.2.3.250&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Thank you.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 08:54:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-translated-public-ftp-server-via-internal-network/m-p/2792221#M173600</guid>
      <dc:creator>geloangelo00</dc:creator>
      <dc:date>2016-01-05T08:54:37Z</dc:date>
    </item>
  </channel>
</rss>

