<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5510_Ver 8.3 can not forward port in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508765#M235065</link>
    <description>&lt;P&gt;ASA is 5510, ver 8.3(1), I can't forward ports (www, ftp) from outside to DMZ.&lt;/P&gt;&lt;P&gt;My configuration:&lt;/P&gt;&lt;P&gt;outside:&amp;nbsp; IP Public (X.X.X.X)&lt;BR /&gt;DMZ:&amp;nbsp; 10.10.10.0/24&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit tcp any interface outside eq www&lt;BR /&gt;access-group outside-in in interface outside&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) source dynamic DMZ interface&lt;/P&gt;&lt;P&gt;object network WEB&lt;BR /&gt;&amp;nbsp; host 10.10.10.5&lt;BR /&gt;&amp;nbsp; nat (DMZ,outside) static interface service tcp www www&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa#sh xlate type static&lt;BR /&gt;TCP PAT from DMZ:10.10.10.5 80-80 to outside:X.X.X.X 80-80&lt;/P&gt;&lt;P&gt;asa#sh nat&lt;BR /&gt;&amp;nbsp; (DMZ) to (outside) source static WEB interface service tcp www www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;asa#sh access-list&lt;BR /&gt;access-list outside-in line 2 extended permit tcp any interface outside eq www (hitcnt=0) 0xacb645cb&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;Syslog: ASA-3-710003: TCP access denied by ACL from Y.Y.Y.Y/64141 to outside:X.X.X.X/80&lt;/P&gt;&lt;P&gt;******************************************************************&lt;BR /&gt;ASA# packet-tracer input outside tcp X.X.X.X 80 10.10.10.5 80 detailed&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 10.10.10.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; DMZ&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in&amp;nbsp; id=0xa88943e0, priority=500, domain=permit, deny=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=11, user_data=0x6, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=X.X.X.X, mask=255.255.255.255, port=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: DMZ&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;*************************************************&lt;/P&gt;&lt;P&gt;In access-list, I've changed destination to real IP (10.10.10.5) or public IP, the result was the same.&lt;/P&gt;&lt;P&gt;I don't know which mistake in my configuration. Could anyone help me?&lt;/P&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:42:41 GMT</pubDate>
    <dc:creator>khanhlaan</dc:creator>
    <dc:date>2019-03-12T04:42:41Z</dc:date>
    <item>
      <title>ASA5510_Ver 8.3 can not forward port</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508765#M235065</link>
      <description>&lt;P&gt;ASA is 5510, ver 8.3(1), I can't forward ports (www, ftp) from outside to DMZ.&lt;/P&gt;&lt;P&gt;My configuration:&lt;/P&gt;&lt;P&gt;outside:&amp;nbsp; IP Public (X.X.X.X)&lt;BR /&gt;DMZ:&amp;nbsp; 10.10.10.0/24&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit tcp any interface outside eq www&lt;BR /&gt;access-group outside-in in interface outside&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) source dynamic DMZ interface&lt;/P&gt;&lt;P&gt;object network WEB&lt;BR /&gt;&amp;nbsp; host 10.10.10.5&lt;BR /&gt;&amp;nbsp; nat (DMZ,outside) static interface service tcp www www&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa#sh xlate type static&lt;BR /&gt;TCP PAT from DMZ:10.10.10.5 80-80 to outside:X.X.X.X 80-80&lt;/P&gt;&lt;P&gt;asa#sh nat&lt;BR /&gt;&amp;nbsp; (DMZ) to (outside) source static WEB interface service tcp www www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;asa#sh access-list&lt;BR /&gt;access-list outside-in line 2 extended permit tcp any interface outside eq www (hitcnt=0) 0xacb645cb&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;Syslog: ASA-3-710003: TCP access denied by ACL from Y.Y.Y.Y/64141 to outside:X.X.X.X/80&lt;/P&gt;&lt;P&gt;******************************************************************&lt;BR /&gt;ASA# packet-tracer input outside tcp X.X.X.X 80 10.10.10.5 80 detailed&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 10.10.10.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; DMZ&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in&amp;nbsp; id=0xa88943e0, priority=500, domain=permit, deny=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=11, user_data=0x6, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=X.X.X.X, mask=255.255.255.255, port=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: DMZ&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;*************************************************&lt;/P&gt;&lt;P&gt;In access-list, I've changed destination to real IP (10.10.10.5) or public IP, the result was the same.&lt;/P&gt;&lt;P&gt;I don't know which mistake in my configuration. Could anyone help me?&lt;/P&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508765#M235065</guid>
      <dc:creator>khanhlaan</dc:creator>
      <dc:date>2019-03-12T04:42:41Z</dc:date>
    </item>
    <item>
      <title>The destination address in</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508766#M235066</link>
      <description>&lt;P&gt;The destination address in the ACL has to be the real IP of the server. And upgrade the ASA to something newer. 8.3(1) was probably the worst version ever on the ASA.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 10:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508766#M235066</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-09-05T10:00:30Z</dc:date>
    </item>
    <item>
      <title>Dear Karsten Iwen,Yes, I've</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508767#M235067</link>
      <description>&lt;P&gt;Dear &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/karsteniwen" title="View user profile."&gt;Karsten Iwen,&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;Yes, I've replaced Real IP in ACL, but everything is still the same as before&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;I think port forwarding is normally on every firewall, should I upgrade the ASA to newer version ?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Sep 2014 01:28:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508767#M235067</guid>
      <dc:creator>khanhlaan</dc:creator>
      <dc:date>2014-09-06T01:28:01Z</dc:date>
    </item>
    <item>
      <title>Show your actual config (at</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508768#M235068</link>
      <description>&lt;P&gt;Show your actual config (at least NAT/ACL). And yes, you should upgrade.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Sep 2014 07:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508768#M235068</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-09-06T07:28:25Z</dc:date>
    </item>
    <item>
      <title>Dear Karsten IwenASA's ACL</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508769#M235069</link>
      <description>&lt;P&gt;Dear &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/karsteniwen" title="View user profile."&gt;Karsten Iwen&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#0000FF;"&gt;ASA's ACL/NAT:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.3(1)&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;description WAN1&lt;BR /&gt;&amp;nbsp;duplex full&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;pppoe client vpdn group WAN1&lt;BR /&gt;&amp;nbsp;ip address pppoe&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2.5&lt;BR /&gt;&amp;nbsp;description DMZ&lt;BR /&gt;&amp;nbsp;vlan 5&lt;BR /&gt;&amp;nbsp;nameif DMZ&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 10.10.10.1 255.255.255.0&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit tcp any host 10.10.10.5 eq www&lt;BR /&gt;access-list outside-in extended permit tcp any host 10.10.10.5 eq ftp&lt;/P&gt;&lt;P&gt;access-group outside-in in interface outside&lt;/P&gt;&lt;P&gt;object network DMZ_NET&lt;BR /&gt;&amp;nbsp;subnet 10.10.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) source dynamic DMZ_NET interface&lt;/P&gt;&lt;P&gt;object network WEB&lt;BR /&gt;&amp;nbsp; host 10.10.10.5&lt;BR /&gt;&amp;nbsp; nat (DMZ,outside) static interface service tcp www www&lt;BR /&gt;object network FTP&lt;BR /&gt;&amp;nbsp; host 10.10.10.5&lt;BR /&gt;&amp;nbsp; nat (DMZ,outside) static interface service tcp ftp ftp&lt;BR /&gt;*************************************************&lt;BR /&gt;&lt;SPAN style="color:#0000FF;"&gt;I 've checked NAT (show nat detail, show xlate,...), translation is OK. DMZ to internet is OK, Internet can ping to outside.&lt;BR /&gt;Show access-list:&lt;BR /&gt;&amp;nbsp; access-list outside-in line 2 extended permit tcp any host 10.10.10.5 eq www (hitcnt=0) 0xacb645cb&lt;BR /&gt;&amp;nbsp; access-list outside-in line 3 extended permit tcp any host 10.10.10.5 eq ftp (hitcnt=0) 0xea857100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#0000FF;"&gt;Packet-tracer:&amp;nbsp; Web &amp;amp; FTP were dropped at ACCESS-LIST (phase 2 or 3) with Implicit Rule.&lt;BR /&gt;Does Implicit Rule concern about NAT?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#0000FF;"&gt;Port Forwarding is a basic function of ASA, should I upgrade?&lt;BR /&gt;Thanks for your reply.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Sep 2014 09:35:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508769#M235069</guid>
      <dc:creator>khanhlaan</dc:creator>
      <dc:date>2014-09-06T09:35:52Z</dc:date>
    </item>
    <item>
      <title>You object NAT is fine, but</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508770#M235070</link>
      <description>&lt;P&gt;You object NAT is fine, but the following rule is wrong:&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;CODE&gt;nat (DMZ,outside) source dynamic DMZ_NET interface&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;That one needs to go to the end of the NAT-List:&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;no nat (DMZ,outside) source dynamic DMZ_NET interface&lt;BR /&gt;nat (DMZ,outside) after-auto source dynamic DMZ_NET interface&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Sep 2014 09:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508770#M235070</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-09-06T09:42:08Z</dc:date>
    </item>
    <item>
      <title>Dear Karsten IwenI 've</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508771#M235071</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/karsteniwen" title="View user profile."&gt;Dear Karsten Iwen&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I 've configured:&amp;nbsp; &lt;CODE&gt;nat (DMZ,outside) after-auto source dynamic DMZ_NET interface&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;the result was still the same.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2014 01:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508771#M235071</guid>
      <dc:creator>khanhlaan</dc:creator>
      <dc:date>2014-09-08T01:46:23Z</dc:date>
    </item>
    <item>
      <title>did you remove the old rule?</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508772#M235072</link>
      <description>&lt;P&gt;did you remove the old rule? Please show your complete NAT-config.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2014 07:33:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508772#M235072</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-09-08T07:33:12Z</dc:date>
    </item>
    <item>
      <title>Sorry Karsten Iwen, I 've not</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508773#M235073</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/karsteniwen" title="View user profile."&gt;Sorry Karsten Iwen&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;, I 've not been at work last time.&lt;/P&gt;&lt;P&gt;Yes, i removed the old rule, show nat detail:&lt;/P&gt;&lt;P&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (inside) to (outside) source dynamic LAN_NET interface&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1214968, untranslate_hits = 115784&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Source - Origin: 192.168.100.0/24, Translated: X.X.X.X/32&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (DMZ) to (outside) source static FTP interface service tcp ftp ftp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source - Origin: 10.10.10.5/32, Translated: X.X.X.X/32&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service - Protocol: tcp Real: ftp Mapped: ftp&lt;BR /&gt;2 (DMZ) to (outside) source static WEB interface service tcp www www&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source - Origin: 10.10.10.5/32, Translated: X.X.X.X/32&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service - Protocol: tcp Real: www Mapped: www&lt;/P&gt;&lt;P&gt;Manual NAT Policies (Section 3)&lt;BR /&gt;1 (DMZ) to (outside) source dynamic DMZ_NET interface&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 2103, untranslate_hits = 8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source - Origin: 10.10.10.0/24, Translated: X.X.X.X/32&lt;/P&gt;&lt;P&gt;I've read &lt;SPAN style="color:#0000FF;"&gt;Syslog,&lt;/SPAN&gt; and realized that something is wrong:&lt;BR /&gt;WEB: ASA-3-710003: TCP access denied by ACL from 123.17.96.224/64141 to outside:X.X.X.X/80&lt;BR /&gt;FTP:&amp;nbsp; ASA-2-106016: Deny IP spoof from (X.X.X.X) to 10.10.10.5 on interface outside&lt;/P&gt;&lt;P&gt;With WEB: packet was dropped at outside, but FTP: packet&amp;nbsp; was dropped&amp;nbsp; behind outside although they were configured with the same ACL/NAT rule.&lt;BR /&gt;Do you know which ASA's functions can affect NAT/ACL ?&lt;BR /&gt;&lt;SPAN style="color:#0000FF;"&gt;Thanks for your help.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2014 01:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-ver-8-3-can-not-forward-port/m-p/2508773#M235073</guid>
      <dc:creator>khanhlaan</dc:creator>
      <dc:date>2014-09-09T01:37:21Z</dc:date>
    </item>
  </channel>
</rss>

