<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Mark, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788939#M177468</link>
    <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;Could you please share the complete output of packet-tracer on the ASA including&amp;nbsp;packet-tracer command you are running.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2015 12:27:53 GMT</pubDate>
    <dc:creator>Akshay Rastogi</dc:creator>
    <dc:date>2015-11-19T12:27:53Z</dc:date>
    <item>
      <title>NAT reverse path failure</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788932#M177457</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope somenone can help with this particulary frustrating issue I've got.&lt;/P&gt;
&lt;P&gt;I should say that I'm fairly new to Cisco firewalls, so please bear with me.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a piece of software on my print server that sends toner level information to my print supplier. The software periodically uses a telnet session to test connectivity, but this is failing.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My print server has a static NAT through the firewall. The settings are;&lt;/P&gt;
&lt;P&gt;Inside IP: 11.0.214.8&lt;/P&gt;
&lt;P&gt;Outside: 10.199.155.250&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;According to packet tracer, the traffic&amp;nbsp;is getting from my print server out to my suppliers server, but is getting dropped on the way back in by a NAT rule.&lt;/P&gt;
&lt;P&gt;The message in the log is;&lt;/P&gt;
&lt;P&gt;"Asymmetric NAT rules matched for forward and reverse flows; Connection for protocol 0 src outside:168.63.28.202 dst inside:11.0.214.8 denied due to NAT reverse path failure."&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can anyone shed some light on what I might be doing wrong?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Mark&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788932#M177457</guid>
      <dc:creator>Mark Crawford</dc:creator>
      <dc:date>2019-03-12T06:54:44Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788933#M177458</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;From the description I see that you have a public IP on the inside and a private IP on outside. Is it correct as per your network?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In case it is dropping in rpf then, there might be other NAT rule which might be getting evaluated for the return path. You can check in the packet tracer output whether same NAT rule is evaluated for incoming and outgoing traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If different NAT rules are hit then try to rearrange NAT rules.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also share the ASA version that you are running and more details about the NAT rule.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;RS&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 16:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788933#M177458</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-18T16:06:07Z</dc:date>
    </item>
    <item>
      <title>Hi Rishabh,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788934#M177459</link>
      <description>&lt;P&gt;Hi Rishabh,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The IP config is correct.&amp;nbsp;That's the way our vendor set everything up.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I can confirm that the same rule is being evaluated for both outgoing and incoming traffic.&lt;/P&gt;
&lt;P&gt;My ASA version is 9.1(5)&lt;/P&gt;
&lt;P&gt;The NAT rule in config is this:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;nat (inside,outside) source static OR-SRV-ORDC-PS1_Inside OR-SRV-ORDC-PS1_Outside&lt;/PRE&gt;
&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 16:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788934#M177459</guid>
      <dc:creator>Mark Crawford</dc:creator>
      <dc:date>2015-11-18T16:20:54Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788935#M177460</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;For checking testing, you could perform followings thing. There is possibility that there might be some more preferred MAnual NAT which is getting hit with &amp;nbsp;traffic.&lt;/P&gt;
&lt;P&gt;First thing is, place this NAT on line 1 with below command :&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="pln"&gt;nat &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;inside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;,&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;outside&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; 1 source &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;static&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; OR&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;SRV&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ORDC&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;PS1_Inside OR&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;SRV&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ORDC&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;PS1_Outside&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;If this also doesn't work and try with Object NAT once:&lt;/P&gt;
&lt;P&gt;Object network obj-internal-printserver&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host &amp;lt;internal server ip&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static &amp;lt;mapped-ip&amp;gt;&lt;/P&gt;
&lt;P&gt;use 'interface' keyward instead of IP address if you are using the outside interface ip as natted ip.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Note: Remove your already existing Manual NAT. It looks more of an NAT rearrangement issue. More information could be find out if you share more details on other existing nat statements.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 16:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788935#M177460</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-18T16:36:54Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788936#M177461</link>
      <description>&lt;P&gt;Hi Akshay,&lt;/P&gt;
&lt;P&gt;My NAT rules are as follows in the order that they are in this list;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;nat (inside,outside) source static OR-SRV-ORDC-PS1_Inside OR-SRV-ORDC-PS1_Outside&lt;BR /&gt;nat (inside,outside) source dynamic RIVERS_NEW_LAN interface&lt;BR /&gt;nat (inside,outside) source static Smoothwall_BYOD_Interface BOYD_LAN_Outside&lt;BR /&gt;nat (inside,outside) source static Parent_reporting_system_inside Parent_reporting_system_outside&lt;BR /&gt;nat (inside,outside) source static Spiceworks_Inside Spiceworks_Outside&lt;/PRE&gt;
&lt;P&gt;If I create an object NAT and remove the manual NAT, the traffic is picked up by the dynamic NAT and dropped on the return.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 17:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788936#M177461</guid>
      <dc:creator>Mark Crawford</dc:creator>
      <dc:date>2015-11-18T17:01:18Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788937#M177463</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;It is always recommanded to have Auto/Object NAT for Dynamic Statements if you are not using destination nat. It might cause wrong NAT to match. Manual NAT are processed from Top to Bottom:&lt;/P&gt;
&lt;P&gt;So Change your dynamic statement something like:&lt;/P&gt;
&lt;P&gt;object network obj-Rievers_new_lan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;subnet &amp;lt;this subnet&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside ) dynamic interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also try to configure Object NAT for your Actual required traffic as i had mentioned in my last post.&lt;/P&gt;
&lt;P&gt;Note : Remove both the Manual NAT statement.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 17:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788937#M177463</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-18T17:07:32Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788938#M177465</link>
      <description>&lt;P&gt;Hi Akshay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have made the modification you suggested, but the traffic is still being dropped, but now by the object rule for the static mapping.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 10:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788938#M177465</guid>
      <dc:creator>Mark Crawford</dc:creator>
      <dc:date>2015-11-19T10:27:52Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788939#M177468</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;Could you please share the complete output of packet-tracer on the ASA including&amp;nbsp;packet-tracer command you are running.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 12:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788939#M177468</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-19T12:27:53Z</dc:date>
    </item>
    <item>
      <title>ORA-ASA-RTR-001# packet</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788940#M177470</link>
      <description>&lt;PRE class="prettyprint"&gt;ORA-ASA-RTR-001# packet-tracer input outside tcp 168.63.28.202 23 11.0.214.8 23&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 11.0.192.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.224.0&amp;nbsp;&amp;nbsp; inside&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group external_access_in in interface outside&lt;BR /&gt;access-list external_access_in extended permit ip any object RIVERS_NEW_LAN &lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network OR-SRV-ORDC-PS1&lt;BR /&gt;&amp;nbsp;nat (inside,outside) static 10.199.155.250&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 Nov 2015 13:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788940#M177470</guid>
      <dc:creator>Mark Crawford</dc:creator>
      <dc:date>2015-11-19T13:00:04Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788941#M177471</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is the object definition mentioned below is correct?&lt;/P&gt;
&lt;P&gt;OR-SRV-ORDC-PS1_Inside = 10.199.155.250&lt;BR /&gt; OR-SRV-ORDC-PS1_Outside = 11.0.214.8&lt;BR /&gt;OR-SRV-ORDC-PS1 =&amp;nbsp;&lt;SPAN&gt;11.0.214.8&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;in your first post you have mentioned that the ouside IP is&amp;nbsp;&lt;SPAN&gt;10.199.155.250 and inside IP is&amp;nbsp;11.0.214.8.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Going by that description, I would expect the input interface in the packet tracer command to be Inside and not Outside.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also try the Object NAT as:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object network OR-SRV-ORDC-PS-test&lt;BR /&gt; host 10.199.155.250&lt;BR /&gt; object network OR-SRV-ORDC-PS-test&lt;BR /&gt; nat (outside,inside) static 11.0.214.8&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;RS&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 14:03:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788941#M177471</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-19T14:03:45Z</dc:date>
    </item>
    <item>
      <title>Hi Rishabh,</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788942#M177472</link>
      <description>&lt;P&gt;Hi Rishabh,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The definitions are:&lt;/P&gt;
&lt;P&gt;OR-SRV-ORDC-PS1_Inside = 11.0.214.8&lt;/P&gt;
&lt;P&gt;OR-SRV-ORDC-PS1_Outside = 10.199.155.250&lt;/P&gt;
&lt;P&gt;OR-SRV-ORDC-PS1 = 11.0.214.8&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On the packet trace command I set the input interface as Outside because it's only on the return path that traffic is dropped.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 15:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788942#M177472</guid>
      <dc:creator>Mark Crawford</dc:creator>
      <dc:date>2015-11-19T15:08:49Z</dc:date>
    </item>
    <item>
      <title>Testing reverse traffic that</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788943#M177473</link>
      <description>&lt;P&gt;Testing reverse traffic that way would not be correct. Try the traffic from actual host to destination through correct interface.&lt;/P&gt;
&lt;P&gt;In actual scenario the return traffic will the session created for outgoing traffic and will get processed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let us know if the packet tracer from source machine to destination server is working fine or not.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And is the traffic always initiated from the printer to outside server or the other way is also expected.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;RS&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 15:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788943#M177473</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-19T15:40:11Z</dc:date>
    </item>
    <item>
      <title>Using packet trace, traffic</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788944#M177474</link>
      <description>&lt;P&gt;Using packet trace, traffic from the internal source to external destination is allowed.&lt;/P&gt;
&lt;P&gt;However, the reporting software on my print server is unable able to communicate with the external destination.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 16:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788944#M177474</guid>
      <dc:creator>Mark Crawford</dc:creator>
      <dc:date>2015-11-19T16:21:53Z</dc:date>
    </item>
    <item>
      <title>If packet tracer is showing</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788945#M177475</link>
      <description>&lt;P&gt;If packet tracer is showing that the traffic is allowed then I would suggest you to see connections in the ASA for the relevant host.&lt;/P&gt;
&lt;P&gt;use following command.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show conn address &amp;lt;ip address&amp;gt; long detail&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you see the connection in the connection table then try to find the state of the connection with the felt of connection flags in above mentioned command.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It is possible that the remote device is not responding to your printer application.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;RS&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 16:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788945#M177475</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-11-19T16:59:47Z</dc:date>
    </item>
    <item>
      <title>Similar issue solved here:</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788946#M177476</link>
      <description>&lt;P&gt;Similar issue solved here:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/discussion/12708501/nat-reverse-path-failure" target="_blank"&gt;https://supportforums.cisco.com/discussion/12708501/nat-reverse-path-failure&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2017 11:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/2788946#M177476</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2017-01-10T11:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Similar issue solved here:</title>
      <link>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/3393266#M177477</link>
      <description>&lt;P&gt;This is just a link to the same thread&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jun 2018 16:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-reverse-path-failure/m-p/3393266#M177477</guid>
      <dc:creator>jether</dc:creator>
      <dc:date>2018-06-03T16:55:50Z</dc:date>
    </item>
  </channel>
</rss>

