<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814106#M175057</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use 'Route-lookup' keyward at the end of these manual statement. Use for top statement and intiate it for that private address. If that works, then perform the same on rest of the statement&lt;/P&gt;
&lt;P&gt;or else..&lt;/P&gt;
&lt;P&gt;Instead of creating these Manual NAT, create object nats something like :&lt;/P&gt;
&lt;P&gt;Object net-&lt;SPAN&gt;repo-1.abcxremote.com-PRIVATE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host &amp;lt;private-ip&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (default, internet-wan) static&amp;nbsp;&lt;SPAN&gt;repo-1.abcxremote.com-PUBLIC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Same thing for other public IP. In this case, it would always use route-lookup for selecting egress interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2015 10:54:11 GMT</pubDate>
    <dc:creator>Akshay Rastogi</dc:creator>
    <dc:date>2015-11-10T10:54:11Z</dc:date>
    <item>
      <title>Static NAT &amp; Routing</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814101#M175052</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I need to pick your brains on this one as I have run out of ideas and still cannot figure out why I am unable to reach new destinations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just recently we added a new site into our WAN estate and connectivity is over SHDS to the other end. Both ends have cisco ASAs and next hop/gateway are the ASAs on each side.&amp;nbsp;We have created a transit VLAN which is connecting the two sites, x.x.x.1 is the remote ASA and x.x.x.5 is my ASA. I have used a new interface E0/4 for the transite VLAN and have setup the required routing and firewall policies to allow traffic to 172.16/16 network which is reacheable via x.x.x.1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So far things are looking good as I am can get to the other end but have come across a strange thing with servers that have a static NAT in place. These hosts are unable to reach this network as traffic hits the firewall and then it goes out the WAN interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Traceroute from a server that has default gateway as the core switch and the core switch with default route of the firewall.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Tracing route to 172.16.101.50 over a maximum of 30 hops&lt;/P&gt;
&lt;P&gt;1 3 ms 4 ms 2 ms colo-coresw.matches.com [10.0.0.245] - &lt;SPAN style="color: #ff0000;"&gt;CORE SWITCH VIP&lt;/SPAN&gt;&lt;BR /&gt; 2 2 ms &amp;lt;1 ms &amp;lt;1 ms 10.0.0.254 - &lt;SPAN style="color: #ff0000;"&gt;FIREWALL INTERFACE (INSIDE)&lt;/SPAN&gt;&lt;BR /&gt; 3 3 ms 3 ms 3 ms 172.16.101.50&lt;/P&gt;
&lt;P&gt;Trace complete.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Traceroute from a server that has default gateway as the core switch and the core switch with default route of the firewall but with a static NAT.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Tracing route to 172.16.101.50 over a maximum of 30 hops&lt;/P&gt;
&lt;P&gt;1 3 ms 2 ms 2 ms colo-coresw.matches.com [10.0.0.245]&lt;BR /&gt; 2 &amp;lt;1 ms &amp;lt;1 ms &amp;lt;1 ms 10.0.0.254&lt;BR /&gt; 3 &amp;lt;1 ms &amp;lt;1 ms &amp;lt;1 ms 154.59.137.105 - &lt;SPAN style="color: #ff0000;"&gt;INTERNET ROUTER&lt;/SPAN&gt;&lt;BR /&gt; 4 2 ms 2 ms 2 ms port-40-199.xxxxxxxxxxxxxxxx&lt;BR /&gt; 5 2 ms 2 ms 2 ms port-98-199.&lt;SPAN&gt;xxxxxxxxxxxxxxxx&lt;/SPAN&gt;&lt;BR /&gt; 6 2 ms 2 ms 2 ms port-83-199.&lt;SPAN&gt;xxxxxxxxxxxxxxxx&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I don't understand why traffic is going out the WAN interface since there is a static route on the firewall for the 172.16/16 network&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;S*&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;0.0.0.0 0.0.0.0 [10/0] via 154.59.137.105, INTERNET-WAN&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.0.0 255.255.252.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;C&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.0.0 255.255.255.0 is directly connected, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;L&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.0.254 255.255.255.255 is directly connected, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.50.0 255.255.254.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.60.0 255.255.254.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.100.0 255.255.255.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.101.0 255.255.255.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.150.0 255.255.255.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.155.0 255.255.255.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.200.0 255.255.248.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.208.0 255.255.255.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;C&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.254.0 255.255.255.0 is directly connected, MGMT&lt;/P&gt;
&lt;P class="p1"&gt;L&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.254.254 255.255.255.255 is directly connected, MGMT&lt;/P&gt;
&lt;P class="p1"&gt;C&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.255.16 255.255.255.248 is directly connected, FAILOVER-LAN&lt;/P&gt;
&lt;P class="p1"&gt;L&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.255.17 255.255.255.255 is directly connected, FAILOVER-LAN&lt;/P&gt;
&lt;P class="p1"&gt;C&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.255.24 255.255.255.248 is directly connected, STATEFULL-FAILOVER&lt;/P&gt;
&lt;P class="p1"&gt;L&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.0.255.25 255.255.255.255 is directly connected, STATEFULL-FAILOVER&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.2.0.0 255.255.0.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.3.0.0 255.255.0.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.4.0.0 255.255.0.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.33.52.0 255.255.252.0 [1/0] via 10.0.0.245, DEFAULT&lt;/P&gt;
&lt;P class="p1"&gt;C&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.255.255.0 255.255.255.240 is directly connected, P2P-COLO-DR&lt;/P&gt;
&lt;P class="p1"&gt;L&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;10.255.255.5 255.255.255.255 is directly connected, P2P-COLO-DR&lt;/P&gt;
&lt;P class="p1"&gt;C&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;154.59.xxx.xxx 255.255.255.248 is directly connected, INTERNET-WAN&lt;/P&gt;
&lt;P class="p1"&gt;L&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;154.59.xxx.xxx 255.255.255.255 is directly connected, INTERNET-WAN&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN style="color: #ff0000;"&gt;S&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;172.16.0.0 255.255.0.0 [1/0] via 10.255.255.1, P2P-COLO-DR&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;C&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;192.168.200.0 255.255.255.240 is directly connected, P2P-COLO-DC&lt;/P&gt;
&lt;P class="p1"&gt;L&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;192.168.200.10 255.255.255.255 is directly connected, P2P-COLO-DC&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;STATIC NAT's&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;show nat&lt;/P&gt;
&lt;P class="p1"&gt;Manual NAT Policies (Section 1)&lt;/P&gt;
&lt;P class="p1"&gt;1 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static repo-1.abcxremote.com-PUBLIC repo-1.abcxremote.com-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 21, untranslate_hits = 70325&lt;/P&gt;
&lt;P class="p1"&gt;2 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static prd-inf-perc-01-PUBLIC prd-inf-perc-01-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 454368, untranslate_hits = 522017&lt;/P&gt;
&lt;P class="p1"&gt;3 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static OWL.abcx.com-PUBLIC OWL.abcx.com-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 42324485, untranslate_hits = 44275688&lt;/P&gt;
&lt;P class="p1"&gt;4 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static stg-inf-www-01-PUBLIC stg-inf-www-01-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 207, untranslate_hits = 70459&lt;/P&gt;
&lt;P class="p1"&gt;5 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static prd-inf-mon-01-PUBLIC prd-inf-mon-01-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 2995324, untranslate_hits = 8470375&lt;/P&gt;
&lt;P class="p1"&gt;6 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static test-hyb-app-01-PUBLIC test-hyb-app-01-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 8385052, untranslate_hits = 8617839&lt;/P&gt;
&lt;P class="p1"&gt;7 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static TEST-PUBLIC 10.0.2.49-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 104, untranslate_hits = 941&lt;/P&gt;
&lt;P class="p1"&gt;8 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static uat-inf-www-vip-PUBLIC uat-inf-www-vip-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 3082, untranslate_hits = 54812&lt;/P&gt;
&lt;P class="p1"&gt;9 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static HO-Mail1-PUBLIC HO-Mail1-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 2382362, untranslate_hits = 2864656&lt;/P&gt;
&lt;P class="p1"&gt;10 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static HO-Mail3-PUBLIC HO-Mail3-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 357752, untranslate_hits = 645180&lt;/P&gt;
&lt;P class="p1"&gt;11 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static test2-hyb-app-01-PUBLIC test2-hyb-app-01-PRIVATE unidirectional no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 50089&lt;/P&gt;
&lt;P class="p1"&gt;12 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static chef.abcxremote.com-PUBLIC chef.abcxremote.com-PRIVATE no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 399518, untranslate_hits = 626786&lt;/P&gt;
&lt;P class="p1"&gt;13 (INTERNET-WAN) to (DEFAULT) source static any any &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static Exch-Hybrid-Public Exch-Hybrid-Private no-proxy-arp&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 55956, untranslate_hits = 145420&lt;/P&gt;
&lt;P class="p1"&gt;14 (DEFAULT) to (INTERNET-WAN) source static DM_INLINE_NETWORK_16 DM_INLINE_NETWORK_16 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static Store-POPUP-PRIVATE Store-POPUP-PRIVATE no-proxy-arp route-lookup&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 0&lt;/P&gt;
&lt;P class="p1"&gt;15 (DEFAULT) to (INTERNET-WAN) source static DM_INLINE_NETWORK_23 DM_INLINE_NETWORK_23 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static 75LedburyOffice 75LedburyOffice no-proxy-arp route-lookup&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 147515, untranslate_hits = 154175&lt;/P&gt;
&lt;P class="p1"&gt;16 (DEFAULT) to (INTERNET-WAN) source static DM_INLINE_NETWORK_25 DM_INLINE_NETWORK_25 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static TestHOADSL-VPN TestHOADSL-VPN no-proxy-arp route-lookup&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 1119485, untranslate_hits = 1120465&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Would be grateful if anyone can identify what the issue could be ??&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Waiting for your reply.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Regards,&lt;/P&gt;
&lt;P class="p1"&gt;Syed&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:51:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814101#M175052</guid>
      <dc:creator>itops</dc:creator>
      <dc:date>2019-03-12T06:51:39Z</dc:date>
    </item>
    <item>
      <title>Hi there,</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814102#M175053</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Is your Destination IP&amp;nbsp;&lt;SPAN&gt;172.16.101.50 matching any of the above mentioned nat. ASA use egress interface with the help of Manual NAT if the destination keyword is used. As i couldn't find any nat statement with mapped-interface as ' P2P-COLO-DR', ASA would be choosing the Internet-WAN as the egrees interface inspite of having a route pointing towards&amp;nbsp; P2P-COLO-DR interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Find the statement and correct it. Your traffic should not overlap with the existing manual nat or configure manual nat on line one for your concerned traffic and mapped address as P2P-COLO-DR.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 09:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814102#M175053</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T09:50:53Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814103#M175054</link>
      <description>&lt;P&gt;Hi Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No there is no manual Nat for any of the hosts in 172.0/16 range. The issue, as explained previously, only applies to hosts that have a public static NAT on the firewall. I have about 14 static nats on the firewall and all of these 14 hosts are unable to reach the new subnet (172.16.0/16) every other server, user is able to get to the destination network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just noticed that same issue applies to site-to-stite VPN networks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Host (10.0.0.2) with a public static NAT is unable to get to 10.0.111.1 (Remote VPN Firewall)&lt;/P&gt;
&lt;P&gt;Host (10.0.096) with no public NAT can get to 10.0.111.1 ??&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I think I have not setup static NAT's right&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 10:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814103#M175054</guid>
      <dc:creator>itops</dc:creator>
      <dc:date>2015-11-10T10:24:20Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814104#M175055</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is your traffic &amp;nbsp;is being initated from behind 'DEFAULT' interface. &amp;nbsp;I could see that all your starting 13 NAT statements are something like:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1 (INTERNET-WAN) to (DEFAULT) source static any any &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;destination static repo-1.abcxremote.com-PUBLIC repo-1.abcxremote.com-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I belive as the traffic is initiated from interface DEFAULT from host&amp;nbsp;repo-1.abcxremote.com-PRIVATE(as in your nat); so for them Static any any is the destination and that covers your Sever 172.16 range servers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Akshay Rastogi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 10:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814104#M175055</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T10:36:15Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814105#M175056</link>
      <description>&lt;P&gt;Hi Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ok that makes sense and yes all traffic is originated from Default Interface. What's the solution for this ? There is an auto NAT policy at the bottom as well&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1 (any) to (INTERNET-WAN) source dynamic OBJ_NAT-Any (0.0.0.0/0) interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 10:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814105#M175056</guid>
      <dc:creator>itops</dc:creator>
      <dc:date>2015-11-10T10:44:49Z</dc:date>
    </item>
    <item>
      <title>Hi, </title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814106#M175057</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use 'Route-lookup' keyward at the end of these manual statement. Use for top statement and intiate it for that private address. If that works, then perform the same on rest of the statement&lt;/P&gt;
&lt;P&gt;or else..&lt;/P&gt;
&lt;P&gt;Instead of creating these Manual NAT, create object nats something like :&lt;/P&gt;
&lt;P&gt;Object net-&lt;SPAN&gt;repo-1.abcxremote.com-PRIVATE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host &amp;lt;private-ip&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (default, internet-wan) static&amp;nbsp;&lt;SPAN&gt;repo-1.abcxremote.com-PUBLIC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Same thing for other public IP. In this case, it would always use route-lookup for selecting egress interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 10:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814106#M175057</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T10:54:11Z</dc:date>
    </item>
    <item>
      <title>Ok mate that has worked for</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814107#M175058</link>
      <description>&lt;P&gt;Ok mate that has worked for me thank you very much. Had to setup Object Nat's to achieve this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;One last thing I am unable to get to from Natted hostst is the VPN network Ledbury75. On the NAT statements you can see Ledbury75 is a VPN subnet with Route Lookup defined.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 11:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814107#M175058</guid>
      <dc:creator>itops</dc:creator>
      <dc:date>2015-11-10T11:06:53Z</dc:date>
    </item>
    <item>
      <title>You're Welcome.</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814108#M175059</link>
      <description>&lt;P&gt;You're Welcome.&lt;/P&gt;
&lt;P&gt;Is that stopped working after these changes or was not working from starting?&lt;/P&gt;
&lt;P&gt;I could not find any nat statement with Ledbury75? could you please mention that form 'show run nat' output. Also check if the natted ip is being added in cryptomap access-lists&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 11:23:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814108#M175059</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T11:23:57Z</dc:date>
    </item>
    <item>
      <title>No actually that never worked</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814109#M175060</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No actually that never worked for me.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;show run nat&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static repo-1.abcxremote.com-PUBLIC repo-1.abcxremote.com-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static prd-inf-perc-01-PUBLIC prd-inf-perc-01-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static OWL.abcx.com-PUBLIC OWL.abcx.com-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static stg-inf-www-01-PUBLIC stg-inf-www-01-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static prd-inf-mon-01-PUBLIC prd-inf-mon-01-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static test-hyb-app-01-PUBLIC test-hyb-app-01-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static uat-inf-www-vip-PUBLIC uat-inf-www-vip-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static HO-mail1-PUBLIC HO-mail1-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static HO-mail3-PUBLIC HO-mail3-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static test2-hyb-app-01-PUBLIC test2-hyb-app-01-PRIVATE unidirectional no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static chef.abcxremote.com-PUBLIC chef.abcxremote.com-PRIVATE no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (INTERNET-WAN,DEFAULT) source static any any destination static Exch-Hybrid-Public Exch-Hybrid-Private no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1" style="color: #ff0000;"&gt;nat (DEFAULT,INTERNET-WAN) source static DM_INLINE_NETWORK_23 DM_INLINE_NETWORK_23 destination static 75LedburyOffice 75LedburyOffice no-proxy-arp route-lookup&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;nat (DEFAULT,INTERNET-WAN) source static DM_INLINE_NETWORK_25 DM_INLINE_NETWORK_25 destination static TestHOADSL-VPN TestHOADSL-VPN no-proxy-arp route-lookup&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;object network 10.0.2.49-PRIVATE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; nat (DEFAULT,INTERNET-WAN) static TEST-PUBLIC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;object network OBJ_NAT-Any&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; nat (any,INTERNET-WAN) dynamic interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Crypto Mat access list has the entire network VLAN 10.0.0.0/24 so that shouldn't be an issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Syed&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 11:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814109#M175060</guid>
      <dc:creator>itops</dc:creator>
      <dc:date>2015-11-10T11:37:24Z</dc:date>
    </item>
    <item>
      <title>Hi Syed,</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814110#M175061</link>
      <description>&lt;P&gt;Hi Syed,&lt;/P&gt;
&lt;P&gt;From the statement, i believe that the Ledburyoffice is behind Default.&lt;/P&gt;
&lt;P&gt;It is not alone this side, your traffic should be allowed on the other side as well(check the other end cryptop-map acl?&lt;/P&gt;
&lt;P&gt;First thing you could do is to put this statement on line 1. Edit the same NAT and 1 after :&amp;nbsp;&lt;SPAN&gt;nat (DEFAULT,INTERNET-WAN) 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now check if it works. It migh be overlapping with above or something(can not say).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Try checking your traffic through packet-tracer utility if it is hitting a correct nat statement and access-lists to permit the traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 11:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814110#M175061</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T11:45:04Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814111#M175062</link>
      <description>&lt;P&gt;Hi Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No Ledbury75 is a VPN site&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object-group network DM_INLINE_NETWORK_23&lt;BR /&gt; network-object object&amp;nbsp;DC_Object&lt;BR /&gt; network-object object Head_Office_VLAN-50&lt;BR /&gt; network-object object Head_Office_VLAN-60&lt;BR /&gt; network-object object Network_VLAN-1&lt;BR /&gt; network-object object FRA-SSRS&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I can ping the natted host 10.0.0.2 (behind Default) from Ledbury's firewall (10.0.111.1) but when I try to ping from 10.0.0.2 to 10.0.111.1 i get no response.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Traceroute chucks traffic to WAN interface&lt;/P&gt;
&lt;P&gt;Tracing route to 10.0.111.1 over a maximum of 30 hops&lt;/P&gt;
&lt;P&gt;1 101 ms 63 ms 3 ms colo-coresw.matches.com [10.0.0.245]&lt;BR /&gt; 2 &amp;lt;1 ms &amp;lt;1 ms &amp;lt;1 ms 154.59.xxx.xxx&lt;BR /&gt; 3 2 ms 1 ms 1 ms port-40-199&lt;BR /&gt; 4 201 ms 6 ms 2 ms port-98-199&lt;BR /&gt; 5 2 ms 2 ms 2 ms port-83-199&lt;BR /&gt; 6 127 ms 206 ms 2 ms port-82-199&lt;BR /&gt; 7 * * * Request timed out.&lt;BR /&gt; 8 * * * Request timed out.&lt;BR /&gt; 9 * * * Request timed out.&lt;BR /&gt; 10 * * * Request timed out.&lt;BR /&gt; 11 * port-82-199 reports: Destination host unreachable.&lt;/P&gt;
&lt;P&gt;Trace complete.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 11:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814111#M175062</guid>
      <dc:creator>itops</dc:creator>
      <dc:date>2015-11-10T11:52:52Z</dc:date>
    </item>
    <item>
      <title>Ignore me please everything</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814112#M175063</link>
      <description>&lt;P&gt;Ignore me please everything is working after your suggested changes.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks for all your help today &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Syed&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 12:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814112#M175063</guid>
      <dc:creator>itops</dc:creator>
      <dc:date>2015-11-10T12:12:16Z</dc:date>
    </item>
    <item>
      <title>You are welcome, Syed.</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814113#M175064</link>
      <description>&lt;P&gt;You are welcome, Syed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remember to rate the helpful the helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 12:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-routing/m-p/2814113#M175064</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-10T12:18:20Z</dc:date>
    </item>
  </channel>
</rss>

