<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA (8.6) pat-pool not working for dynamic NAT. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786803#M174022</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;In Cisco ASA (5515, 8.6), NAT is working only for outside interface but when I configured NAT using Public-IP pool, it didn’t translate the local IP. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Like –&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;interface GigabitEthernet0&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt; &lt;BR /&gt;nameif inside&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt; &lt;BR /&gt;security-level 100&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;ip address 10.10.10.1 255.255.255.252&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;!&lt;BR /&gt;interface GigabitEthernet1&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;ip address 120.122.50.2 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;!&lt;BR /&gt;&lt;/SPAN&gt;object network LAN-USER&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt; &lt;BR /&gt;range 192.168.150.0 192.168.150.100&lt;BR /&gt;!&lt;BR /&gt;object network Public-IP-Pool&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;range 110.80.20.2 110.80.20.3&lt;BR /&gt;!&lt;BR /&gt;access-list OUT-IN extended permit ip any any&lt;BR /&gt;access-list IN-OUT extended permit ip any any&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;!&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;access-group IN-OUT in interface inside&lt;BR /&gt;access-group OUT-IN in interface outside&lt;BR /&gt;!&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 120.122.50.1&lt;BR /&gt;route inside 192.168.150.0 255.255.255.0 10.10.10.2&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) source dynamic LAN-USER interface&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Above NAT configuration is working fine but when try to use Public-IP pool its not working, like -&lt;SPAN class="no-js"&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;nat (inside,outside) source dynamic LAN-USER pat-pool Public-IP-Pool &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Troubleshooting steps was –&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Remove existing NAT –&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;no nat (inside,outside) source dynamic LAN-USER interface&lt;BR /&gt;clear xlate&lt;BR /&gt;nat (inside,outside) source dynamic LAN-USER pat-pool Public-IP-Pool &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Also tried, &lt;SPAN class="no-js"&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;object network LAN-USER&lt;BR /&gt;range 192.168.150.0 192.168.150.100&lt;BR /&gt;!&lt;BR /&gt;object network Public-IP&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;host 110.80.20.4&lt;BR /&gt;!&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;nat (inside,outside) source dynamic LAN-USER Public-IP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;H6 class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;Above configuration also not working.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H6&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;Run packet-tracer command, showed all phase allowed.&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Any help would be greatly appreciated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Thanks in advance.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:02:15 GMT</pubDate>
    <dc:creator>ashabe003</dc:creator>
    <dc:date>2019-03-12T07:02:15Z</dc:date>
    <item>
      <title>Cisco ASA (8.6) pat-pool not working for dynamic NAT.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786803#M174022</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;In Cisco ASA (5515, 8.6), NAT is working only for outside interface but when I configured NAT using Public-IP pool, it didn’t translate the local IP. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Like –&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;interface GigabitEthernet0&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt; &lt;BR /&gt;nameif inside&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt; &lt;BR /&gt;security-level 100&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;ip address 10.10.10.1 255.255.255.252&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;!&lt;BR /&gt;interface GigabitEthernet1&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;ip address 120.122.50.2 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;!&lt;BR /&gt;&lt;/SPAN&gt;object network LAN-USER&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt; &lt;BR /&gt;range 192.168.150.0 192.168.150.100&lt;BR /&gt;!&lt;BR /&gt;object network Public-IP-Pool&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;range 110.80.20.2 110.80.20.3&lt;BR /&gt;!&lt;BR /&gt;access-list OUT-IN extended permit ip any any&lt;BR /&gt;access-list IN-OUT extended permit ip any any&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;!&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;access-group IN-OUT in interface inside&lt;BR /&gt;access-group OUT-IN in interface outside&lt;BR /&gt;!&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 120.122.50.1&lt;BR /&gt;route inside 192.168.150.0 255.255.255.0 10.10.10.2&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) source dynamic LAN-USER interface&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Above NAT configuration is working fine but when try to use Public-IP pool its not working, like -&lt;SPAN class="no-js"&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;nat (inside,outside) source dynamic LAN-USER pat-pool Public-IP-Pool &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Troubleshooting steps was –&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Remove existing NAT –&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;no nat (inside,outside) source dynamic LAN-USER interface&lt;BR /&gt;clear xlate&lt;BR /&gt;nat (inside,outside) source dynamic LAN-USER pat-pool Public-IP-Pool &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Also tried, &lt;SPAN class="no-js"&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;object network LAN-USER&lt;BR /&gt;range 192.168.150.0 192.168.150.100&lt;BR /&gt;!&lt;BR /&gt;object network Public-IP&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;host 110.80.20.4&lt;BR /&gt;!&lt;BR /&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;nat (inside,outside) source dynamic LAN-USER Public-IP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;H6 class="prettyprint"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;Above configuration also not working.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H6&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;Run packet-tracer command, showed all phase allowed.&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Any help would be greatly appreciated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 115%; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Thanks in advance.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786803#M174022</guid>
      <dc:creator>ashabe003</dc:creator>
      <dc:date>2019-03-12T07:02:15Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786804#M174024</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This does not look like the configuration issue,&lt;/P&gt;
&lt;P&gt;Can you provide the output of the packet tracer which is taken on CLI.&lt;/P&gt;
&lt;P&gt;-packet-tracer in inside icmp&amp;nbsp;192.168.150.10 8 0 4.2.2.2 det&lt;/P&gt;
&lt;P&gt;Also provide the output of the "show xlate"&lt;/P&gt;
&lt;P&gt;Are you seeing any log in ASDM when you initiate the traffic from&amp;nbsp;&lt;SPAN&gt;192.168.150.0 subnet?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;You can try to take the capture on inside and outside interface using real traffic to verify whether the ASA is passing the traffic or not.&lt;/P&gt;
&lt;P&gt;cap capin int insde match icmp host &amp;lt;source IP&amp;gt; host &amp;lt;dest IP&amp;gt;&lt;/P&gt;
&lt;P&gt;cap capout int outside match icmp any host &amp;lt;dest IP&amp;gt;&lt;/P&gt;
&lt;P&gt;to view the captures "show cap capin" and "show cap capout"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2015 01:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786804#M174024</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-16T01:24:34Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786805#M174025</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please run the below command :&lt;/P&gt;
&lt;P&gt;conf t)#arp permit-nonconnected&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This command was added from version 8.4.5 for permitting arp request coming for non connected subnet:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/a3.html#pgfId-1837762&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The pool you are using for dynamic nat is in different subnet than Outside interface. You ASA Outside interface would not respond to the ARP query coming from Upstream Device.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remember to rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2015 05:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786805#M174025</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-12-16T05:38:11Z</dc:date>
    </item>
    <item>
      <title>Hi Shivapramod M,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786806#M174026</link>
      <description>&lt;P&gt;Hi Shivapramod M,&lt;/P&gt;
&lt;P&gt;Thanks for your response.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; Please find the attached file of packet-tracer output.&lt;/P&gt;
&lt;P&gt;I apologize; I’m currently out of the office. Later I’ll provide you the “show xlate” output.&lt;/P&gt;
&lt;P&gt;In time of initiate the traffic from 192.168.150.0 subnet, got ASDM log like –&lt;/P&gt;
&lt;P&gt;“ Deny TCP reverse path check from 192.168.150.2 to 8.8.8.8 on interface outside “&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2015 05:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786806#M174026</guid>
      <dc:creator>ashabe003</dc:creator>
      <dc:date>2015-12-16T05:38:37Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786807#M174027</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif'; text-decoration: none; text-underline: none;"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Please find the attached logs file.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;SPAN style="text-decoration: none;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;And this time didn’t find any ASDM log. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 09:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786807#M174027</guid>
      <dc:creator>ashabe003</dc:creator>
      <dc:date>2015-12-17T09:17:41Z</dc:date>
    </item>
    <item>
      <title>Hi ,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786808#M174028</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;Hi &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;(conf ig)#arp permit-nonconnected&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Cambria','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN style="font-size: 10pt; font-family: verdana,geneva,sans-serif;"&gt;This command is not working in my ASA (8.6). I think its not ARP related issue because dynamic NAT translation is working for interface like –&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-family: 'Cambria','serif';"&gt;# nat (inside,outside) source dynamic LAN-USER interface&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: 'Cambria','serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: 'Cambria','serif'; font-size: 10pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;But not working for Public-IP-Pool or single Public-IP. Configured that Public –IP in workstation which want to use for NAT translate and its working.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: 'Cambria','serif'; font-size: 10pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: 'Cambria','serif'; font-size: 10pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 09:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786808#M174028</guid>
      <dc:creator>ashabe003</dc:creator>
      <dc:date>2015-12-17T09:21:23Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786809#M174029</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It looks like the response is not coming back to ASA. The ICMp request is correctly transmitting by ASA with the correct NAT address but there is no response.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even if the firewall is dropping&amp;nbsp;we should see the packets in the capture. Usually only hardware drops on the interface will not be captured in the capture. You may have to check the upstream devices.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the PAT IP does not belong to the same subnet as the firewall interface this might be ARP issue. The command&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;arp permit-nonconnected&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp; is not available in 8.6&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/intro_intro.html#wp1325357&lt;/P&gt;
&lt;P&gt;You can try to configure the NAT with the interface IP, if this works then it should be issue about arp itself and you may have to upgrade the device&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;object network LAN-USER
 nat (inside,outside) dynamic interface&lt;/PRE&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 09:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786809#M174029</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-17T09:31:07Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786810#M174030</link>
      <description>&lt;H5 style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt;Hi,&lt;/SPAN&gt;&lt;/H5&gt;
&lt;H5 style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;H5 style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt;I already mention that NAT is working with interface IP for LAN-USER object but I want to use PAT IP or single Public IP for NAT translates.&lt;/SPAN&gt;&lt;/H5&gt;
&lt;H5 style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;H5 style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt; I omitted point to point subnet IP and used same subnet for both interface and PAT IP but same result as before, dynamic interface is working but not PAT IP. &lt;/SPAN&gt;&lt;/H5&gt;
&lt;H5 style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;H5&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt; Maybe need to check the upstream devices.&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;H5&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif; font-size: 10pt;"&gt;Thanks a lot for your time.&lt;/SPAN&gt;&lt;/H5&gt;</description>
      <pubDate>Thu, 17 Dec 2015 10:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786810#M174030</guid>
      <dc:creator>ashabe003</dc:creator>
      <dc:date>2015-12-17T10:43:12Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786811#M174031</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It is an arp issue with mapped ip not in the same subnet as outside interface. Please add the route on next hop router for this mapped ip pointing towards ASA outside interface IP. &amp;nbsp;It is an ARP issue. The next hop has no arp entry or route to send the packet back to ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 14:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-6-pat-pool-not-working-for-dynamic-nat/m-p/2786811#M174031</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-12-17T14:46:28Z</dc:date>
    </item>
  </channel>
</rss>

