<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5520 Static NAT problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5520-static-nat-problem/m-p/2591791#M202849</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting the following error when I try to implement a statement that was removed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR: access-list used in static has different local addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were migrating to a new ASA. We shut the interfaces on the Old asa down (admin down)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A static statement was missing when we had to revert back to old ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise on what to do to resolve thi&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:10:44 GMT</pubDate>
    <dc:creator>Steve Coady</dc:creator>
    <dc:date>2019-03-12T05:10:44Z</dc:date>
    <item>
      <title>ASA5520 Static NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-static-nat-problem/m-p/2591791#M202849</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting the following error when I try to implement a statement that was removed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR: access-list used in static has different local addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were migrating to a new ASA. We shut the interfaces on the Old asa down (admin down)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A static statement was missing when we had to revert back to old ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise on what to do to resolve thi&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-static-nat-problem/m-p/2591791#M202849</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2019-03-12T05:10:44Z</dc:date>
    </item>
    <item>
      <title>Hi, Not sure if I have ever</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-static-nat-problem/m-p/2591792#M202850</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if I have ever encountered this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On first glance it would almost seem like you were using the wrong ACL (or configured in a way thats not supported for this NAT) for the &lt;STRONG&gt;"static"&lt;/STRONG&gt; command you are trying to insert?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you share the full &lt;STRONG&gt;"static"&lt;/STRONG&gt; command you are trying to enter and also the configuration of the &lt;STRONG&gt;"access-list"&lt;/STRONG&gt; that you are using in that &lt;STRONG&gt;"static"&lt;/STRONG&gt; command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ERROR message specifies that there are &lt;STRONG&gt;"different local addresses"&lt;/STRONG&gt;. Perhaps this indicates a situation where you have several different source addresses (on several&amp;nbsp; ACL lines) specified in the &lt;STRONG&gt;"access-list"&lt;/STRONG&gt; when you are actually trying to translate one hosts local IP address to one mapped/nat IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2014 11:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-static-nat-problem/m-p/2591792#M202850</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-12-04T11:02:36Z</dc:date>
    </item>
    <item>
      <title>Jouni Thank you for the</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-static-nat-problem/m-p/2591793#M202851</link>
      <description>&lt;P&gt;Jouni&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a strange problem indeed. The statement causing the issue is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; static (inside,outside) 170.x.x.94&amp;nbsp; access-list MYPROD_PNAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This statement has been in ASA for sometime and worked well.&lt;/P&gt;&lt;P&gt;Recently there were some new ACL statements referencing this same ACL. All worked well "Until"&lt;/P&gt;&lt;P&gt;we had to reboot the ASA. After reboot, that particular static was missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had to remove the newest acl statements, apply the static and then re-enter the new statements for the work around.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2014 15:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-static-nat-problem/m-p/2591793#M202851</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2014-12-04T15:59:54Z</dc:date>
    </item>
  </channel>
</rss>

