<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the output of the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563846#M206103</link>
    <description>&lt;P&gt;What is the output of the packet-tracer when simulating traffic for that device?&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;packet-tracer input DMZ udp 192.168.69.125 1234 172.16.69.239 1234&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Oct 2014 16:22:22 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2014-10-13T16:22:22Z</dc:date>
    <item>
      <title>NAT Rule not working Static</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563845#M206102</link>
      <description>&lt;P&gt;Hello I have a problem with a nat rule, I have setup a device(Video Conferencing) on the DMZ that needs to talk to the internet.&lt;/P&gt;&lt;P&gt;The nat rule is just a normal setup&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (DMZ,Outside) source static obj-192.168.69.125 obj-172.16.69.239&lt;/P&gt;&lt;P&gt;there is only one ACL list for the 192.168.69.125 it is a permit IP any&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list DMZ&amp;nbsp;line 2 extended permit ip host 192.168.69.125 any log debugging interval 300&lt;/P&gt;&lt;P&gt;I have done a few capture off the firewall&amp;nbsp;&lt;/P&gt;&lt;P&gt;capture video interface dmZ match ip any host 192.168.69.125&lt;/P&gt;&lt;P&gt;I never see the 172.16.69.239 address&lt;/P&gt;&lt;P&gt;capture video interface outside match ip any host 172.16.69.239&lt;/P&gt;&lt;P&gt;I never see the 192.168.69.125 address&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is capture i was trying&amp;nbsp;&lt;/P&gt;&lt;P&gt;capture video type raw-data interface DMZ [Capturing - 0 bytes]&lt;BR /&gt;&amp;nbsp; match ip host 192.168.69.125 host 172.16.69.239&lt;/P&gt;&lt;P&gt;any ideas or commands i can run&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563845#M206102</guid>
      <dc:creator>Adam Coombs</dc:creator>
      <dc:date>2019-03-12T04:55:02Z</dc:date>
    </item>
    <item>
      <title>What is the output of the</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563846#M206103</link>
      <description>&lt;P&gt;What is the output of the packet-tracer when simulating traffic for that device?&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;packet-tracer input DMZ udp 192.168.69.125 1234 172.16.69.239 1234&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 16:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563846#M206103</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-10-13T16:22:22Z</dc:date>
    </item>
    <item>
      <title>Result:input-interface:</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563847#M206104</link>
      <description>&lt;P&gt;Result:&lt;BR /&gt;input-interface: DMZ&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (sp-security-failed) Slowpath security checks failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After Phase 1 though 9 results are allow&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 18:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563847#M206104</guid>
      <dc:creator>Adam Coombs</dc:creator>
      <dc:date>2014-10-13T18:22:03Z</dc:date>
    </item>
    <item>
      <title>Please show the actual config</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563848#M206105</link>
      <description>&lt;P&gt;Please show the actual config of the ASA.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 19:18:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563848#M206105</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-10-13T19:18:39Z</dc:date>
    </item>
    <item>
      <title>Firewall# packet-tracer input</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563849#M206106</link>
      <description>&lt;P&gt;Firewall# packet-tracer input dmZ udp 192.168.69.125 1234 172.16.69.239 $&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: CAPTURE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 172.16.69.224 &amp;nbsp;255.255.255.224 Outside&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group DMZ in interface DMZ&lt;BR /&gt;access-list DMZ extended permit ip host 192.168.69.125 any log debugging&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (DMZ,Outside) source static obj-192.168.69.125 obj-172.16.69.239&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 192.168.69.125/1234 to 172.16.69.239/1234&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group OUTSIDE out interface Outside control-plane&lt;BR /&gt;access-list OUTSIDE extended permit ip any4 any4 log debugging&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (DMZ,Outside) source static obj-192.168.69.125 obj-172.16.69.239&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: DMZ&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (sp-security-failed) Slowpath security checks failed&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 19:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563849#M206106</guid>
      <dc:creator>Adam Coombs</dc:creator>
      <dc:date>2014-10-13T19:55:22Z</dc:date>
    </item>
    <item>
      <title>In your first post you say</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563850#M206107</link>
      <description>&lt;P&gt;In your first post you say that you translate to 172.16.69.125, but in the packet-tracer you translate to .239.&lt;/P&gt;&lt;P&gt;Please specify exactly how you want to translate the traffic and which systems should communicate exactly.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 20:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563850#M206107</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-10-13T20:43:12Z</dc:date>
    </item>
    <item>
      <title>Sorry I correct it it is</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563851#M206108</link>
      <description>&lt;P&gt;Sorry I correct it&amp;nbsp;&lt;/P&gt;&lt;P&gt;it is .239&lt;/P&gt;&lt;P&gt;I found that I was missing a outside acl line as well I am getting a username and password problem now, instead of server has rejected the connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 12:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563851#M206108</guid>
      <dc:creator>Adam Coombs</dc:creator>
      <dc:date>2014-10-14T12:51:36Z</dc:date>
    </item>
    <item>
      <title>That means, for the ASA</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563852#M206109</link>
      <description>&lt;P&gt;That means, for the ASA-config everything is fine now?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 13:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563852#M206109</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-10-14T13:38:07Z</dc:date>
    </item>
    <item>
      <title>Still working on this problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563853#M206110</link>
      <description>&lt;P&gt;Still working on this problem but I believe this part is fixed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2014 13:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-rule-not-working-static/m-p/2563853#M206110</guid>
      <dc:creator>Adam Coombs</dc:creator>
      <dc:date>2014-10-14T13:43:00Z</dc:date>
    </item>
  </channel>
</rss>

