<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The translated address was in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758671#M192822</link>
    <description>&lt;P&gt;The translated address was used in the ACL in ASA versions up to 8.2. With the new NAT-model it changed that the real IP has to be used.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Aug 2015 19:11:58 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2015-08-14T19:11:58Z</dc:date>
    <item>
      <title>Have problem with static nat on cisco ASA ver 9.1</title>
      <link>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758668#M192815</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;My English is'n good . I have trouble with static nat on asa run version 9.1.&lt;/P&gt;&lt;P&gt;This is my configuration file&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;BR /&gt;&amp;nbsp;nameif outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;des # Connect to&amp;nbsp;router&amp;nbsp;of&amp;nbsp;ISP #&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 222.255.23.166 255.255.255.252&lt;/P&gt;&lt;P&gt;!interface GigabitEthernet0/2&lt;BR /&gt;&amp;nbsp;nameif dmz&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 199.1.10.33 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 222.255.23.165 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network NASU_DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;sub 199.1.10.32 255.255.255.224&lt;/P&gt;&lt;P&gt;objecdt network NASU_ISA&lt;/P&gt;&lt;P&gt;&amp;nbsp;host 199.1.10.62&lt;/P&gt;&lt;P&gt;objecdt network NASU_ISA_PUB&lt;/P&gt;&lt;P&gt;&amp;nbsp;host 222.255.20.186&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (dmz,outside) after-auto source dynamic NASU_DMZ interface&lt;/P&gt;&lt;P&gt;nat (dmz,outside) source static NASU_ISA NASU_ISA_PUB (static nat)&lt;/P&gt;&lt;P&gt;Case1 : if I use alc " access-list Outside_policy_in extendend&amp;nbsp;permit ip any any " ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;access-group Outside_policy_in in interface outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Result: Static nat on ASA will be worked&amp;nbsp;correct&lt;/P&gt;&lt;P&gt;Case 2 : If I use acl "&amp;nbsp; access-list Outside_policy_in extendend&amp;nbsp;permit tcp any host 222.255.20.186 eq 443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;access-list Outside_policy_in extendend&amp;nbsp;permit tcp any host 222.255.20.186 eq 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;access-group Outside_policy_in in interface outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Result: Static nat on ASA will be worked&amp;nbsp;incorrect. I can't&amp;nbsp;use&amp;nbsp;all service&amp;nbsp;include&amp;nbsp;443 and 80&amp;nbsp;.&lt;/P&gt;&lt;P&gt;Can you help me solve this problem ?&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758668#M192815</guid>
      <dc:creator>sonphamngoc</dc:creator>
      <dc:date>2019-03-12T06:25:41Z</dc:date>
    </item>
    <item>
      <title>In the ACL you have to use</title>
      <link>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758669#M192817</link>
      <description>&lt;P&gt;In the ACL you have to use the real server IP-address:&lt;/P&gt;

&lt;PRE style="font-size: 14px;"&gt;
access-list Outside_policy_in extendend permit tcp any object NASU_ISA eq 443
access-list Outside_policy_in extendend permit tcp any object NASU_ISA eq 80&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Aug 2015 08:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758669#M192817</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-14T08:22:08Z</dc:date>
    </item>
    <item>
      <title>Thank for your support !So,</title>
      <link>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758670#M192820</link>
      <description>&lt;P&gt;Thank for your support !&lt;/P&gt;&lt;P&gt;So, can you explain for me? All document show&amp;nbsp;me that&amp;nbsp;have to use IP map with static nat on asa.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 18:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758670#M192820</guid>
      <dc:creator>sonphamngoc</dc:creator>
      <dc:date>2015-08-14T18:18:15Z</dc:date>
    </item>
    <item>
      <title>The translated address was</title>
      <link>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758671#M192822</link>
      <description>&lt;P&gt;The translated address was used in the ACL in ASA versions up to 8.2. With the new NAT-model it changed that the real IP has to be used.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 19:11:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/have-problem-with-static-nat-on-cisco-asa-ver-9-1/m-p/2758671#M192822</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-08-14T19:11:58Z</dc:date>
    </item>
  </channel>
</rss>

