<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic %ASA-3-305006: portmap translation creation failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-3-305006-portmap-translation-creation-failed/m-p/2749819#M192451</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have ASA5520&amp;nbsp; configured with below interfaces&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;nameif VISITOR&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.2.1 255.255.255.0&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;description Connection to ISP SHAW&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address dhcp setroute&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA version is 8.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;USers with IP address is unable to get to internet and when I do nslookup on user pc for 4.2.2.2 DNS times out.&lt;/P&gt;&lt;P&gt;Below is log from ASA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%ASA-3-305006: portmap translation creation failed for udp src VISITOR:192.168.2.4/60499 dst outside:64.59.144.19/53&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;below is nat config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA5520# sh run nat&lt;BR /&gt;nat (VISITOR) 1 192.168.2.0 255.255.255.0&lt;BR /&gt;nat (VISITOR) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;ASA5520# sh nat de&lt;BR /&gt;ASA5520# sh nat ?&lt;/P&gt;&lt;P&gt;Current available interface(s):&lt;BR /&gt;&amp;nbsp; MGMT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface Ethernet0/0&lt;BR /&gt;&amp;nbsp; VISITOR&amp;nbsp; Name of interface Ethernet0/3&lt;BR /&gt;&amp;nbsp; WLC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface Ethernet0/2&lt;BR /&gt;&amp;nbsp; outside&amp;nbsp; Name of interface Ethernet0/1&lt;BR /&gt;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output modifiers&lt;BR /&gt;&amp;nbsp; &amp;lt;cr&amp;gt;&lt;BR /&gt;ASA5520# sh nat VI&lt;BR /&gt;ASA5520# sh nat VISITOR&lt;BR /&gt;&amp;nbsp; match ip VISITOR 192.168.2.0 255.255.255.0 MGMT any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR 192.168.2.0 255.255.255.0 outside any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 279, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR 192.168.2.0 255.255.255.0 VISITOR any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR any MGMT any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR any outside any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR any VISITOR any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;ASA5520#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:29:10 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2019-03-12T06:29:10Z</dc:date>
    <item>
      <title>%ASA-3-305006: portmap translation creation failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-3-305006-portmap-translation-creation-failed/m-p/2749819#M192451</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have ASA5520&amp;nbsp; configured with below interfaces&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;nameif VISITOR&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.2.1 255.255.255.0&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;description Connection to ISP SHAW&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address dhcp setroute&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA version is 8.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;USers with IP address is unable to get to internet and when I do nslookup on user pc for 4.2.2.2 DNS times out.&lt;/P&gt;&lt;P&gt;Below is log from ASA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%ASA-3-305006: portmap translation creation failed for udp src VISITOR:192.168.2.4/60499 dst outside:64.59.144.19/53&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;below is nat config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA5520# sh run nat&lt;BR /&gt;nat (VISITOR) 1 192.168.2.0 255.255.255.0&lt;BR /&gt;nat (VISITOR) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;ASA5520# sh nat de&lt;BR /&gt;ASA5520# sh nat ?&lt;/P&gt;&lt;P&gt;Current available interface(s):&lt;BR /&gt;&amp;nbsp; MGMT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface Ethernet0/0&lt;BR /&gt;&amp;nbsp; VISITOR&amp;nbsp; Name of interface Ethernet0/3&lt;BR /&gt;&amp;nbsp; WLC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface Ethernet0/2&lt;BR /&gt;&amp;nbsp; outside&amp;nbsp; Name of interface Ethernet0/1&lt;BR /&gt;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output modifiers&lt;BR /&gt;&amp;nbsp; &amp;lt;cr&amp;gt;&lt;BR /&gt;ASA5520# sh nat VI&lt;BR /&gt;ASA5520# sh nat VISITOR&lt;BR /&gt;&amp;nbsp; match ip VISITOR 192.168.2.0 255.255.255.0 MGMT any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR 192.168.2.0 255.255.255.0 outside any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 279, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR 192.168.2.0 255.255.255.0 VISITOR any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR any MGMT any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR any outside any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp; match ip VISITOR any VISITOR any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;ASA5520#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-3-305006-portmap-translation-creation-failed/m-p/2749819#M192451</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T06:29:10Z</dc:date>
    </item>
    <item>
      <title>Mahesh,</title>
      <link>https://community.cisco.com/t5/network-security/asa-3-305006-portmap-translation-creation-failed/m-p/2749820#M192452</link>
      <description>&lt;P&gt;Mahesh,&lt;/P&gt;
&lt;P&gt;Your (pre-8.3 style) NAT statements reference global pool 1.&lt;/P&gt;
&lt;P&gt;As your show output indicates, you&amp;nbsp;do not have any global pool or address defined ("&lt;SPAN style="font-size: 14.3999996185303px;"&gt;No matching global&lt;/SPAN&gt;"). You would need something like:&lt;/P&gt;

&lt;PRE&gt;
global (outside) 1 &amp;lt;public IP&amp;gt; netmask &amp;lt;netmask&amp;gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 24 Aug 2015 02:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-3-305006-portmap-translation-creation-failed/m-p/2749820#M192452</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-08-24T02:14:43Z</dc:date>
    </item>
    <item>
      <title>Seems when I had typo</title>
      <link>https://community.cisco.com/t5/network-security/asa-3-305006-portmap-translation-creation-failed/m-p/2749821#M192453</link>
      <description>&lt;P&gt;Seems when I had typo with&lt;/P&gt;&lt;P&gt;global (outside) 101 interface&lt;/P&gt;&lt;P&gt;when I run the command sh run nat above command was not showing up.&lt;/P&gt;&lt;P&gt;sh run all I was able to see and fix it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 02:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-3-305006-portmap-translation-creation-failed/m-p/2749821#M192453</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-08-24T02:51:20Z</dc:date>
    </item>
  </channel>
</rss>

