<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Nat Statement suddenly not works in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-statement-suddenly-not-works/m-p/2579774#M198063</link>
    <description>&lt;P&gt;Firewall:&amp;nbsp; ASA 5550 VPN Premium license Version 9.1(5)16&lt;/P&gt;&lt;P&gt;Incident as below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nat statement as below&lt;/P&gt;&lt;P&gt;===================&lt;/P&gt;&lt;P&gt;name 9.x.x.x NAT-E23ESMTP01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (SMTP-YELLOW,inside) static 9.x.x.x&lt;BR /&gt;object network obj-202.x.x.x&lt;/P&gt;&lt;P&gt;object network NAT-E23ESMTP01&lt;BR /&gt;&amp;nbsp;host 9.x.x.x&lt;/P&gt;&lt;P&gt;object-group network NAT-AU-SMTP-Svrs_8&lt;BR /&gt;&amp;nbsp;network-object object NAT-E23ESMTP01&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Above configuration suddenly stop works&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have added below host under object group then its again working&lt;/P&gt;&lt;P&gt;object-group network NAT-AU-SMTP-Svrs_8&lt;BR /&gt;&amp;nbsp;network-object object NAT-E23ESMTP01&lt;/P&gt;&lt;P&gt;network-object host 202.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am also not understanding why suddenly stop working and works after add host which is natted by 202.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:19:33 GMT</pubDate>
    <dc:creator>mm6646</dc:creator>
    <dc:date>2019-03-12T05:19:33Z</dc:date>
    <item>
      <title>Nat Statement suddenly not works</title>
      <link>https://community.cisco.com/t5/network-security/nat-statement-suddenly-not-works/m-p/2579774#M198063</link>
      <description>&lt;P&gt;Firewall:&amp;nbsp; ASA 5550 VPN Premium license Version 9.1(5)16&lt;/P&gt;&lt;P&gt;Incident as below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nat statement as below&lt;/P&gt;&lt;P&gt;===================&lt;/P&gt;&lt;P&gt;name 9.x.x.x NAT-E23ESMTP01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (SMTP-YELLOW,inside) static 9.x.x.x&lt;BR /&gt;object network obj-202.x.x.x&lt;/P&gt;&lt;P&gt;object network NAT-E23ESMTP01&lt;BR /&gt;&amp;nbsp;host 9.x.x.x&lt;/P&gt;&lt;P&gt;object-group network NAT-AU-SMTP-Svrs_8&lt;BR /&gt;&amp;nbsp;network-object object NAT-E23ESMTP01&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Above configuration suddenly stop works&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have added below host under object group then its again working&lt;/P&gt;&lt;P&gt;object-group network NAT-AU-SMTP-Svrs_8&lt;BR /&gt;&amp;nbsp;network-object object NAT-E23ESMTP01&lt;/P&gt;&lt;P&gt;network-object host 202.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am also not understanding why suddenly stop working and works after add host which is natted by 202.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-statement-suddenly-not-works/m-p/2579774#M198063</guid>
      <dc:creator>mm6646</dc:creator>
      <dc:date>2019-03-12T05:19:33Z</dc:date>
    </item>
    <item>
      <title>Hi, Can you check the NAT</title>
      <link>https://community.cisco.com/t5/network-security/nat-statement-suddenly-not-works/m-p/2579775#M198064</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you check the NAT configuration again and paste it here. Seems to me that there is something missing from your above output or it seems confusing to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, you first mention the actual "nat" command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (SMTP-YELLOW,inside) static 9.x.x.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I am not sure under which &lt;STRONG&gt;"network object"&lt;/STRONG&gt; command this is configured? And what is the actual &lt;STRONG&gt;"host"&lt;/STRONG&gt; address under the &lt;STRONG&gt;"object"&lt;/STRONG&gt;? The info might be in your above post but I want to make sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you mention an &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; configuration? This should have nothing to do with the above &lt;STRONG&gt;"nat"&lt;/STRONG&gt; command as its a Auto NAT / Network Object NAT and &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; are not used as a parameter of those configurations.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Perhaps the &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; is related to an ACL? So the problem might actually be some ACL that is using the &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; that you mention.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you also provide a &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command output of the traffic that does not work or stops working? The format is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input &amp;lt;source interface&amp;gt; tcp &amp;lt;source ip&amp;gt; 12345 &amp;lt;destination ip&amp;gt; &amp;lt;destination port&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 11:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-statement-suddenly-not-works/m-p/2579775#M198064</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-12T11:45:47Z</dc:date>
    </item>
    <item>
      <title>Hi Jouni,</title>
      <link>https://community.cisco.com/t5/network-security/nat-statement-suddenly-not-works/m-p/2579776#M198065</link>
      <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;
&lt;P&gt;Before add host&lt;/P&gt;

&lt;PRE class="logpre" style="font-family:Courier New;margin-left:3px;margin-right:3px;white-space:pre-wrap;word-wrap:normal;"&gt;
Phase: 3
Type: ACCESS-LIST
Subtype: log
Result: DROP
Config:
access-group inside-IN-20130424 in interface inside
access-list inside-IN-20130424 extended deny tcp any4 any4 eq smtp 

&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The packet tracer show traffic deny by any any rule for stop working connection as above&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;below is Phase 3 of packet tracer after add below host under AU-MAIL-RELAY-SRV-NAT_8&lt;/P&gt;

&lt;PRE class="logpre" style="font-family:Courier New;margin-left:3px;margin-right:3px;white-space:pre-wrap;word-wrap:normal;"&gt;
network-object host 202.x.x.x&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;PRE class="logpre" style="font-family:Courier New;margin-left:3px;margin-right:3px;white-space:pre-wrap;word-wrap:normal;"&gt;
Phase: 3
Type: ACCESS-LIST
Subtype: log
Result: ALLOW
Config:
access-group inside-IN-20130424 in interface inside
access-list inside-IN-20130424 extended permit tcp object-group SMTP-DLP-AU object-group AU-MAIL-RELAY-SRV-NAT_8 eq smtp 
object-group network SMTP-DLP-AU
 description: SMTP DLP Sensor AU 
 network-object host 9.x.x.x
object-group network AU-MAIL-RELAY-SRV-NAT_8
network-object object NAT-E23ESMTP01      &amp;gt;&amp;gt; user said was working before with this 
                                             Line, Before add below Host
 network-object host 202.x.x.x

 &lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have just add natted ip of NAT-E23ESMTP01(9.x.x.x)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;PRE class="logpre" style="font-family:Courier New;margin-left:3px;margin-right:3px;white-space:pre-wrap;word-wrap:normal;"&gt;
Phase: 1
Type: UN-NAT
Subtype: static
Result: ALLOW
Config:
object network obj-202.x.x.x
 nat (SMTP-YELLOW,inside) static 9.110.x.x 
Additional Information:
NAT divert to egress interface SMTP-YELLOW
Untranslate 9.110.x.x/25 to 202.x.x.x/25
&lt;/PRE&gt;

&lt;PRE class="logpre" style="font-family:Courier New;margin-left:3px;margin-right:3px;white-space:pre-wrap;word-wrap:normal;"&gt;

&amp;nbsp;&lt;/PRE&gt;

&lt;PRE class="logpre" style="font-family:Courier New;margin-left:3px;margin-right:3px;white-space:pre-wrap;word-wrap:normal;"&gt;
Phase: 8
Type: NAT
Subtype: rpf-check
Result: ALLOW
Config:
object network obj-202.x.x.x
 nat (SMTP-YELLOW,inside) static 9.x.x.x
Additional Information:&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Jan 2015 13:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-statement-suddenly-not-works/m-p/2579776#M198065</guid>
      <dc:creator>mm6646</dc:creator>
      <dc:date>2015-01-14T13:57:22Z</dc:date>
    </item>
  </channel>
</rss>

