<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic asa 9.3.1 - issue - nat - single real ip and 2 mapped ip in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575580#M202839</link>
    <description>&lt;P&gt;I'm having a strange issue with ASA 9.3.1 on 5515-X.&lt;BR /&gt;&lt;BR /&gt;A vpn device is connected inside LAN and is natted to 2 different public IPs. The problem is that when the primary isp fails and comes back, the remote side is unable to connect to the vpn device thru primary isp(unable to ping) all remaining nats work without any issue.&lt;BR /&gt;&lt;BR /&gt;Traffic is permitted for VPN device in ACLs for ISP_1, ISP_2 interfaces and inside_access_in&lt;BR /&gt;&lt;BR /&gt;Apart from this tracking is enabled for ISP_1 &amp;amp; ISP_2.&lt;BR /&gt;&lt;BR /&gt;*****************************&lt;BR /&gt;object network VPN-LAN-Ip&lt;BR /&gt;&amp;nbsp;host 172.16.200.270&lt;BR /&gt;&lt;BR /&gt;object network VPN-Public-IP-ISP_1&lt;BR /&gt;&amp;nbsp;host 10.200.250.10&lt;BR /&gt;&lt;BR /&gt;object network VPN-Public-IP-ISP_1&lt;BR /&gt;&amp;nbsp;host 192.200.250.10&lt;BR /&gt;&lt;BR /&gt;nat (inside,isp_1) source static VPN-LAN-Ip VPN-Public-IP-ISP_1&lt;BR /&gt;nat (inside,isp_2) source static VPN-LAN-Ip VPN-Public-IP-ISP_2&lt;BR /&gt;*******************************&lt;BR /&gt;&lt;BR /&gt;Am i missing something ?. i even tried creating second object name for use with isp_2 and used with nat.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:09:55 GMT</pubDate>
    <dc:creator>Eby Mani</dc:creator>
    <dc:date>2019-03-12T05:09:55Z</dc:date>
    <item>
      <title>asa 9.3.1 - issue - nat - single real ip and 2 mapped ip</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575580#M202839</link>
      <description>&lt;P&gt;I'm having a strange issue with ASA 9.3.1 on 5515-X.&lt;BR /&gt;&lt;BR /&gt;A vpn device is connected inside LAN and is natted to 2 different public IPs. The problem is that when the primary isp fails and comes back, the remote side is unable to connect to the vpn device thru primary isp(unable to ping) all remaining nats work without any issue.&lt;BR /&gt;&lt;BR /&gt;Traffic is permitted for VPN device in ACLs for ISP_1, ISP_2 interfaces and inside_access_in&lt;BR /&gt;&lt;BR /&gt;Apart from this tracking is enabled for ISP_1 &amp;amp; ISP_2.&lt;BR /&gt;&lt;BR /&gt;*****************************&lt;BR /&gt;object network VPN-LAN-Ip&lt;BR /&gt;&amp;nbsp;host 172.16.200.270&lt;BR /&gt;&lt;BR /&gt;object network VPN-Public-IP-ISP_1&lt;BR /&gt;&amp;nbsp;host 10.200.250.10&lt;BR /&gt;&lt;BR /&gt;object network VPN-Public-IP-ISP_1&lt;BR /&gt;&amp;nbsp;host 192.200.250.10&lt;BR /&gt;&lt;BR /&gt;nat (inside,isp_1) source static VPN-LAN-Ip VPN-Public-IP-ISP_1&lt;BR /&gt;nat (inside,isp_2) source static VPN-LAN-Ip VPN-Public-IP-ISP_2&lt;BR /&gt;*******************************&lt;BR /&gt;&lt;BR /&gt;Am i missing something ?. i even tried creating second object name for use with isp_2 and used with nat.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575580#M202839</guid>
      <dc:creator>Eby Mani</dc:creator>
      <dc:date>2019-03-12T05:09:55Z</dc:date>
    </item>
    <item>
      <title>Hi ,How is your vpn</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575581#M202840</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;How is your vpn configured what is the peer address for your remote client ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2014 05:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575581#M202840</guid>
      <dc:creator>Murali</dc:creator>
      <dc:date>2014-12-03T05:37:37Z</dc:date>
    </item>
    <item>
      <title>Hi,VPN initiates site-to-site</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575582#M202841</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;VPN initiates site-to-site tunnel to the other end. Both ends private IP is mapped to the VPN box and only server traffic goes thru the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT on ASA to the real ip works well when testing in lab setup, even with physically un/plugging the cable.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2014 11:25:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575582#M202841</guid>
      <dc:creator>Eby Mani</dc:creator>
      <dc:date>2014-12-04T11:25:08Z</dc:date>
    </item>
    <item>
      <title>hi can you post your asa</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575583#M202842</link>
      <description>&lt;P&gt;hi can you post your asa config related to vpn setup , route configurations and nat config that is relevant.&lt;/P&gt;&lt;P&gt;I hope this link is helpful for you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/blog/150001/ipsec-vpn-redundancy-failover-over-redundant-isp-links&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Murali&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2014 19:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-1-issue-nat-single-real-ip-and-2-mapped-ip/m-p/2575583#M202842</guid>
      <dc:creator>Murali</dc:creator>
      <dc:date>2014-12-06T19:04:25Z</dc:date>
    </item>
  </channel>
</rss>

