<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Akash, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat/m-p/2796266#M174346</link>
    <description>&lt;P&gt;Hi Akash,&lt;/P&gt;
&lt;P&gt;It looks like you have only dynamic PAT in your NAT configuration for this particular IP. So the translation will be one directional only. So if you initate the traffic from outside to inside it will not hit any NAT but the reverse traffic will hit a dynamic PAT hence the incoming NAT and outgoing NAT are difference. So the firewall drops the packet.&lt;/P&gt;
&lt;P&gt;You can try to configure a static NAT for this specific traffic which should allow you for bidrectional NAT.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2015 04:18:12 GMT</pubDate>
    <dc:creator>Shivapramod M</dc:creator>
    <dc:date>2015-12-04T04:18:12Z</dc:date>
    <item>
      <title>NAT</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796260#M174340</link>
      <description>&lt;P&gt;can you tell me what is it mean and how can it get sorted out&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Dec 03 2015 04:08:43 NJSE-CORP-ASA5585-1 : %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for icmp src outside:166.77.235.144 dst inside:166.77.174.123 (type 8, code 0) denied due to NAT reverse path failure&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796260#M174340</guid>
      <dc:creator>akash.deep</dc:creator>
      <dc:date>2019-03-12T06:59:08Z</dc:date>
    </item>
    <item>
      <title>Hi Akash,</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796261#M174341</link>
      <description>&lt;P&gt;Hi Akash,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Looks like different NAT rules are matching for forwardd and reverse path of traffic.&lt;/P&gt;
&lt;P&gt;You can run packet tracer and check which NAT rule is evaluated for forward and reverse path.&lt;/P&gt;
&lt;P&gt;Based on the packet tracer output and network requirement you can try to alter the definition or order of nat rule in &amp;nbsp;your netowrk.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can share the packet tracer output and nat configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Rishabh Seth&lt;/P&gt;
&lt;P&gt;Rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 09:46:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796261#M174341</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-12-03T09:46:55Z</dc:date>
    </item>
    <item>
      <title>Post your NAT config and the</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796262#M174342</link>
      <description>&lt;P&gt;Post your NAT config and the output of "show nat"&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 12:37:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796262#M174342</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-12-03T12:37:26Z</dc:date>
    </item>
    <item>
      <title>please have a look of nat</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796263#M174343</link>
      <description>&lt;P&gt;please have a look of nat config&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;
&lt;DIV class="field-items"&gt;
&lt;DIV class="field-item even"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;P&gt;I am having a issue to undertand the NATTING in ASA, below is the issue which i am having as of now.&lt;/P&gt;
&lt;P&gt;getting drop:- can you please go through it and let me know what can be the issue&lt;/P&gt;
&lt;P&gt;packet-tracer input outside tcp 166.77.235.144 2020 166.77.174.123 123&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 166.77.35.2 using egress ifc&amp;nbsp; inside&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group acl-outside in interface outside&lt;BR /&gt;access-list acl-outside extended permit ip host 166.77.235.144 host 166.77.174.123&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: CONN-SETTINGS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map RT881625&lt;BR /&gt;&amp;nbsp;match access-list rt881625-conns-acl&lt;BR /&gt;policy-map RT881625-conns&lt;BR /&gt;&amp;nbsp;class RT881625&lt;BR /&gt;&amp;nbsp; set connection conn-max 0 embryonic-conn-max 0 random-sequence-number enable&lt;BR /&gt;service-policy RT881625-conns interface inside&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network natobj-166.77.0.0-16&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;P&gt;====================&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source dynamic natobj-via-axciom natobj-axciom-natpool destination static natobj-axiom-nets natobj-axiom-nets&lt;BR /&gt;nat (dmz-dot12,outside) source static natobj-src-166.77.12.0-22 natobj-src-166.77.12.0-22 destination static natobj-dst-a2m natobj-dst-a2m&lt;BR /&gt;nat (dmz-dot12,outside) source dynamic natobj-src-166.77.12.0-22 natobj-global-nat destination static natobj-dst-hosting natobj-dst-hosting&lt;BR /&gt;nat (dmz-dot9,outside) source dynamic natobj-src-166.77.9.0-24 natobj-global-nat destination static natobj-dst-hosting natobj-dst-hosting&lt;BR /&gt;nat (outside,outside) source dynamic natobj-vpn-pool-uturn pat-pool natobj-default-natpool destination static natobj-dst-nets-uturn natobj-dst-nets-uturn&lt;BR /&gt;nat (outside,outside) source static servicenow-natobj-src-nets-uturn servicenow-natobj-src-nets-uturn destination static servicenow-natobj-dst-nets-uturn servicenow-natobj-dst-nets-uturn&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static wordpress-129.228.35.64 wordpress-129.228.35.64&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static 129.228.0.0 129.228.0.0&lt;BR /&gt;nat (inside,outside) source static any any destination static redspace-172.18.0.80 redspace-172.18.0.80&lt;BR /&gt;nat (inside,outside) source dynamic natobj-src-oneoffs pat-pool natobj-global-oneoffs&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool natobj-global-oneoffs destination static natobj-dst-oneoffs natobj-dst-oneoffs&lt;BR /&gt;nat (outside,outside) source static VPN_Hairpin VPN_Hairpin destination static VPN_Hairpin VPN_Hairpin&lt;BR /&gt;nat (inside,outside) source static natobj-src-tacacs natobj-src-tacacs destination static natobj-dst-tacas-devices natobj-dst-tacas-devices&lt;BR /&gt;nat (inside,outside) source static singapore-dr-us singapore-dr-us destination static singapore-dr-asia singapore-dr-asia&lt;BR /&gt;nat (dmz-dot12,outside) source static natobj-src-a2m natobj-src-a2m destination static natobj-dst-a2m natobj-dst-a2m route-lookup&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-vpn-lan-to-lan-new natobj-dst-vpn-lan-to-lan-new&lt;BR /&gt;nat (dmz-dot8,outside) source static natobj-src-larsentoubro-local natobj-src-larsentoubro-local destination static natobj-dst-larsentoubro-remote natobj-dst-larsentoubro-remote&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-vpn-lan-to-lan natobj-dst-vpn-lan-to-lan&lt;BR /&gt;nat (inside,outside) source static natobj-src-network-tools natobj-src-network-tools destination static natobj-dst-network-devices natobj-dst-network-devices&lt;BR /&gt;nat (inside,outside) source static pp-cl1-10-6-0-0 pp-cl1-10-6-0-0 destination static pp-bet-172-20-20-0 pp-bet-172-20-20-0&lt;BR /&gt;nat (inside,dmz-paramount) source static obj-1515-52fl-printers obj-1515-52fl-printers destination static obj-ppc-192-168-148-0 obj-ppc-192-168-148-0&lt;BR /&gt;nat (inside,outside) source static obj-10-0-0-0-24 obj-10-0-0-0-24 destination static obj-no-nat-bet obj-no-nat-bet&lt;BR /&gt;nat (inside,dmz-paramount) source static obj-no-nat-to-ppc obj-no-nat-to-ppc destination static obj-ppc-no-nat obj-ppc-no-nat&lt;BR /&gt;nat (inside,outside) source static natobj-172.16.0.0-12 166.77.6.4 destination static SterlingASA SterlingASA&lt;BR /&gt;nat (inside,dmz-paramount) source dynamic any interface&lt;BR /&gt;nat (inside,outside) source static natobj-166.77.0.0-16 166.77.6.4 destination static SterlingASA SterlingASA&lt;BR /&gt;nat (inside,outside) source static xbox-166.77.216.203 xbox-166.77.216.203&lt;BR /&gt;nat (inside,outside) source static xbox-216-184 xbox-public-6-218&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool nielsen-vpn-local destination static nielsen-vpn-remote nielsen-vpn-remote&lt;BR /&gt;nat (inside,dmz-paramount) source static natobj-src-viacom-no-nat natobj-src-viacom-no-nat destination static natobj-dst-paramount-no-nat natobj-dst-paramount-no-nat&lt;BR /&gt;nat (inside,outside) source static natobj-src-166.77.200.105 natobj-src-166.77.200.105 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (inside,outside) source static 166.77.200.57 166.77.200.57 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (inside,dmz-dot5) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot7) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot9) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot11) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot12) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,outside) source static 166.77.186.224 166.77.186.224 destination static 69.195.244.238 69.195.244.238&lt;BR /&gt;nat (inside,outside) source static natobj-src-166.77.200.105 natobj-src-166.77.200.105 destination static 69.195.244.238 69.195.244.238&lt;BR /&gt;nat (inside,outside) source static 166.77.199.147 166.77.199.147 destination static 172.20.90.0 172.20.90.0&lt;BR /&gt;nat (inside,outside) source static 166.77.199.223 166.77.199.223 destination static 172.20.90.0 172.20.90.0&lt;BR /&gt;nat (inside,outside) source static NATPOOL-166.77.35.128 NATPOOL-166.77.35.128 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (dmz-lb-dmz,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-larsentoubro-remote natobj-dst-larsentoubro-remote&lt;BR /&gt;nat (inside,outside) source static 10.40.122.20 10.40.122.20 destination static SterlingDECRU SterlingDECRU&lt;BR /&gt;nat (inside,outside) source static 10.40.122.21 10.40.122.21 destination static SterlingDECRU SterlingDECRU&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool natobj-global-bluejeans destination static GLB-bluejeans-nets GLB-bluejeans-nets&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_172.18.251.0_24 NETWORK_OBJ_172.18.251.0_24 no-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-aws-servers natobj-dst-aws-servers&lt;BR /&gt;nat (inside,outside) source static Jenkins_Server Jenkins_Server destination static DMQA_Network DMQA_Network&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static 129.228.31.145 129.228.31.145&lt;BR /&gt;nat (inside,outside) source static VPN-Wireless_Pools-DMQA VPN-Wireless_Pools-DMQA destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.13 obj_166.77.185.13 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.14 obj_166.77.185.14 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.15 obj_166.77.185.15 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.123 obj_166.77.185.123 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.124 obj_166.77.185.124 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.206.28 obj_166.77.206.28 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static natobj-src-sap natobj-src-sap&lt;BR /&gt;nat (inside,outside) source static natobj-src-sap natobj-src-sap destination static natobj-src-sap natobj-src-sap&lt;BR /&gt;nat (inside,outside) source static obj_imailrelay-server obj_imailrelay-server destination static DMQA_Router DMQA_Router&lt;BR /&gt;!&lt;BR /&gt;object network natobj-172.18.3.0-25&lt;BR /&gt;&amp;nbsp;nat (dmz-corpvpn,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-10.10.4.0-24&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-192.21.120.0-23&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-166.77.0.0-16&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Dec 2015 02:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796263#M174343</guid>
      <dc:creator>akash.deep</dc:creator>
      <dc:date>2015-12-04T02:09:37Z</dc:date>
    </item>
    <item>
      <title>I am having a issue to</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796264#M174344</link>
      <description>&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;
&lt;DIV class="field-items"&gt;
&lt;DIV class="field-item even"&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;P&gt;I am having a issue to undertand the NATTING in ASA, below is the issue which i am having as of now.&lt;/P&gt;
&lt;P&gt;getting drop:- can you please go through it and let me know what can be the issue&lt;/P&gt;
&lt;P&gt;packet-tracer input outside tcp 166.77.235.144 2020 166.77.174.123 123&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 166.77.35.2 using egress ifc&amp;nbsp; inside&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group acl-outside in interface outside&lt;BR /&gt;access-list acl-outside extended permit ip host 166.77.235.144 host 166.77.174.123&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: CONN-SETTINGS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map RT881625&lt;BR /&gt;&amp;nbsp;match access-list rt881625-conns-acl&lt;BR /&gt;policy-map RT881625-conns&lt;BR /&gt;&amp;nbsp;class RT881625&lt;BR /&gt;&amp;nbsp; set connection conn-max 0 embryonic-conn-max 0 random-sequence-number enable&lt;BR /&gt;service-policy RT881625-conns interface inside&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network natobj-166.77.0.0-16&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;P&gt;====================&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source dynamic natobj-via-axciom natobj-axciom-natpool destination static natobj-axiom-nets natobj-axiom-nets&lt;BR /&gt;nat (dmz-dot12,outside) source static natobj-src-166.77.12.0-22 natobj-src-166.77.12.0-22 destination static natobj-dst-a2m natobj-dst-a2m&lt;BR /&gt;nat (dmz-dot12,outside) source dynamic natobj-src-166.77.12.0-22 natobj-global-nat destination static natobj-dst-hosting natobj-dst-hosting&lt;BR /&gt;nat (dmz-dot9,outside) source dynamic natobj-src-166.77.9.0-24 natobj-global-nat destination static natobj-dst-hosting natobj-dst-hosting&lt;BR /&gt;nat (outside,outside) source dynamic natobj-vpn-pool-uturn pat-pool natobj-default-natpool destination static natobj-dst-nets-uturn natobj-dst-nets-uturn&lt;BR /&gt;nat (outside,outside) source static servicenow-natobj-src-nets-uturn servicenow-natobj-src-nets-uturn destination static servicenow-natobj-dst-nets-uturn servicenow-natobj-dst-nets-uturn&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static wordpress-129.228.35.64 wordpress-129.228.35.64&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static 129.228.0.0 129.228.0.0&lt;BR /&gt;nat (inside,outside) source static any any destination static redspace-172.18.0.80 redspace-172.18.0.80&lt;BR /&gt;nat (inside,outside) source dynamic natobj-src-oneoffs pat-pool natobj-global-oneoffs&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool natobj-global-oneoffs destination static natobj-dst-oneoffs natobj-dst-oneoffs&lt;BR /&gt;nat (outside,outside) source static VPN_Hairpin VPN_Hairpin destination static VPN_Hairpin VPN_Hairpin&lt;BR /&gt;nat (inside,outside) source static natobj-src-tacacs natobj-src-tacacs destination static natobj-dst-tacas-devices natobj-dst-tacas-devices&lt;BR /&gt;nat (inside,outside) source static singapore-dr-us singapore-dr-us destination static singapore-dr-asia singapore-dr-asia&lt;BR /&gt;nat (dmz-dot12,outside) source static natobj-src-a2m natobj-src-a2m destination static natobj-dst-a2m natobj-dst-a2m route-lookup&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-vpn-lan-to-lan-new natobj-dst-vpn-lan-to-lan-new&lt;BR /&gt;nat (dmz-dot8,outside) source static natobj-src-larsentoubro-local natobj-src-larsentoubro-local destination static natobj-dst-larsentoubro-remote natobj-dst-larsentoubro-remote&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-vpn-lan-to-lan natobj-dst-vpn-lan-to-lan&lt;BR /&gt;nat (inside,outside) source static natobj-src-network-tools natobj-src-network-tools destination static natobj-dst-network-devices natobj-dst-network-devices&lt;BR /&gt;nat (inside,outside) source static pp-cl1-10-6-0-0 pp-cl1-10-6-0-0 destination static pp-bet-172-20-20-0 pp-bet-172-20-20-0&lt;BR /&gt;nat (inside,dmz-paramount) source static obj-1515-52fl-printers obj-1515-52fl-printers destination static obj-ppc-192-168-148-0 obj-ppc-192-168-148-0&lt;BR /&gt;nat (inside,outside) source static obj-10-0-0-0-24 obj-10-0-0-0-24 destination static obj-no-nat-bet obj-no-nat-bet&lt;BR /&gt;nat (inside,dmz-paramount) source static obj-no-nat-to-ppc obj-no-nat-to-ppc destination static obj-ppc-no-nat obj-ppc-no-nat&lt;BR /&gt;nat (inside,outside) source static natobj-172.16.0.0-12 166.77.6.4 destination static SterlingASA SterlingASA&lt;BR /&gt;nat (inside,dmz-paramount) source dynamic any interface&lt;BR /&gt;nat (inside,outside) source static natobj-166.77.0.0-16 166.77.6.4 destination static SterlingASA SterlingASA&lt;BR /&gt;nat (inside,outside) source static xbox-166.77.216.203 xbox-166.77.216.203&lt;BR /&gt;nat (inside,outside) source static xbox-216-184 xbox-public-6-218&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool nielsen-vpn-local destination static nielsen-vpn-remote nielsen-vpn-remote&lt;BR /&gt;nat (inside,dmz-paramount) source static natobj-src-viacom-no-nat natobj-src-viacom-no-nat destination static natobj-dst-paramount-no-nat natobj-dst-paramount-no-nat&lt;BR /&gt;nat (inside,outside) source static natobj-src-166.77.200.105 natobj-src-166.77.200.105 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (inside,outside) source static 166.77.200.57 166.77.200.57 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (inside,dmz-dot5) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot7) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot9) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot11) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot12) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,outside) source static 166.77.186.224 166.77.186.224 destination static 69.195.244.238 69.195.244.238&lt;BR /&gt;nat (inside,outside) source static natobj-src-166.77.200.105 natobj-src-166.77.200.105 destination static 69.195.244.238 69.195.244.238&lt;BR /&gt;nat (inside,outside) source static 166.77.199.147 166.77.199.147 destination static 172.20.90.0 172.20.90.0&lt;BR /&gt;nat (inside,outside) source static 166.77.199.223 166.77.199.223 destination static 172.20.90.0 172.20.90.0&lt;BR /&gt;nat (inside,outside) source static NATPOOL-166.77.35.128 NATPOOL-166.77.35.128 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (dmz-lb-dmz,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-larsentoubro-remote natobj-dst-larsentoubro-remote&lt;BR /&gt;nat (inside,outside) source static 10.40.122.20 10.40.122.20 destination static SterlingDECRU SterlingDECRU&lt;BR /&gt;nat (inside,outside) source static 10.40.122.21 10.40.122.21 destination static SterlingDECRU SterlingDECRU&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool natobj-global-bluejeans destination static GLB-bluejeans-nets GLB-bluejeans-nets&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_172.18.251.0_24 NETWORK_OBJ_172.18.251.0_24 no-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-aws-servers natobj-dst-aws-servers&lt;BR /&gt;nat (inside,outside) source static Jenkins_Server Jenkins_Server destination static DMQA_Network DMQA_Network&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static 129.228.31.145 129.228.31.145&lt;BR /&gt;nat (inside,outside) source static VPN-Wireless_Pools-DMQA VPN-Wireless_Pools-DMQA destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.13 obj_166.77.185.13 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.14 obj_166.77.185.14 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.15 obj_166.77.185.15 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.123 obj_166.77.185.123 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.124 obj_166.77.185.124 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.206.28 obj_166.77.206.28 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static natobj-src-sap natobj-src-sap&lt;BR /&gt;nat (inside,outside) source static natobj-src-sap natobj-src-sap destination static natobj-src-sap natobj-src-sap&lt;BR /&gt;nat (inside,outside) source static obj_imailrelay-server obj_imailrelay-server destination static DMQA_Router DMQA_Router&lt;BR /&gt;!&lt;BR /&gt;object network natobj-172.18.3.0-25&lt;BR /&gt;&amp;nbsp;nat (dmz-corpvpn,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-10.10.4.0-24&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-192.21.120.0-23&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-166.77.0.0-16&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Dec 2015 02:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796264#M174344</guid>
      <dc:creator>akash.deep</dc:creator>
      <dc:date>2015-12-04T02:09:59Z</dc:date>
    </item>
    <item>
      <title>Can you please post the</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796265#M174345</link>
      <description>&lt;P&gt;Can you please post the output of "show nat"&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 04:16:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796265#M174345</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-12-04T04:16:03Z</dc:date>
    </item>
    <item>
      <title>Hi Akash,</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796266#M174346</link>
      <description>&lt;P&gt;Hi Akash,&lt;/P&gt;
&lt;P&gt;It looks like you have only dynamic PAT in your NAT configuration for this particular IP. So the translation will be one directional only. So if you initate the traffic from outside to inside it will not hit any NAT but the reverse traffic will hit a dynamic PAT hence the incoming NAT and outgoing NAT are difference. So the firewall drops the packet.&lt;/P&gt;
&lt;P&gt;You can try to configure a static NAT for this specific traffic which should allow you for bidrectional NAT.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 04:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796266#M174346</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-04T04:18:12Z</dc:date>
    </item>
    <item>
      <title>acket-tracer input outside</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796267#M174347</link>
      <description>&lt;P&gt;acket-tracer input outside tcp 166.77.235.144 2020 166.77.174.123 123&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 166.77.35.2 using egress ifc&amp;nbsp; inside&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group acl-outside in interface outside&lt;BR /&gt;access-list acl-outside extended permit ip host 166.77.235.144 host 166.77.174.123&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: CONN-SETTINGS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map RT881625&lt;BR /&gt;&amp;nbsp;match access-list rt881625-conns-acl&lt;BR /&gt;policy-map RT881625-conns&lt;BR /&gt;&amp;nbsp;class RT881625&lt;BR /&gt;&amp;nbsp; set connection conn-max 0 embryonic-conn-max 0 random-sequence-number enable&lt;BR /&gt;service-policy RT881625-conns interface inside&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network natobj-166.77.0.0-16&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 04:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796267#M174347</guid>
      <dc:creator>akash.deep</dc:creator>
      <dc:date>2015-12-04T04:22:47Z</dc:date>
    </item>
    <item>
      <title>his NAT rule below, as per</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796268#M174348</link>
      <description>&lt;P&gt;his NAT rule below, as per your packet tracer output is matching your traffic from inside to outside.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;STRONG&gt;object network natobj-166.77.0.0-16&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This could be your issue.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 04:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796268#M174348</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-12-04T04:30:32Z</dc:date>
    </item>
    <item>
      <title>you mena if i can use the</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796269#M174349</link>
      <description>&lt;P&gt;you mena if i can use the identify nat it should work like as below&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source static 166.77.174.123 166.77.174.123&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 06:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796269#M174349</guid>
      <dc:creator>akash.deep</dc:creator>
      <dc:date>2015-12-04T06:52:27Z</dc:date>
    </item>
    <item>
      <title>Hi Akash,</title>
      <link>https://community.cisco.com/t5/network-security/nat/m-p/2796270#M174350</link>
      <description>&lt;P&gt;Hi Akash,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes you can try nat exemption or you can configure a static nat with a mpped ip and the real IP as&amp;nbsp;&lt;SPAN&gt;166.77.174.123. This should resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;sample config:&lt;/P&gt;
&lt;P&gt;object network obj-test&lt;BR /&gt; host 166.77.174.123&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source static obj-test obj-test&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 07:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat/m-p/2796270#M174350</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-04T07:03:22Z</dc:date>
    </item>
  </channel>
</rss>

