<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, Can you post the complete in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519975#M235232</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post the complete output of the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command and the actual command used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you mean that you want to use a NAT Pool in this case? If so you should have something like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (INTERNAL) 2 10.100.43.1-10.100.43.253&lt;BR /&gt;global (INTERNAL) 2 10.100.43.254&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
    <pubDate>Wed, 27 Aug 2014 19:07:37 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2014-08-27T19:07:37Z</dc:date>
    <item>
      <title>ASA 8.2 Twice NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519974#M235229</link>
      <description>&lt;P&gt;I have a production scenario where I need to implement twice NAT in my ASA(8.2(5)). I cannot upgrade this Firewall as of now.&lt;/P&gt;&lt;P&gt;The Topology goes like this,&lt;/P&gt;&lt;P&gt;&amp;nbsp;(172.16.0.0/12)&lt;STRONG&gt;SPOKE&lt;/STRONG&gt;----&amp;gt;(OUTSIDE)&lt;STRONG&gt;ASA&lt;/STRONG&gt;(INTERNAL)----&amp;gt;&lt;STRONG&gt;3rdPARTY FW&lt;/STRONG&gt;(172.23.102.92)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Requirement is, the Spoke Location users should access Webserver 172.23.102.92 via IP:172.25.1.42(This IP is advertised over WAN)&lt;/P&gt;&lt;P&gt;2. Now my 3rd Party wants to NAT my Source Traffic(172.16.0.0/12) to 10.100.43.0/24 and send it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done the following config and its not working.&lt;/P&gt;&lt;P&gt;================================&lt;/P&gt;&lt;P&gt;access-list SPOKE-NAT extended permit ip 172.16.0.0 255.240.0.0 ho 172.25.1.42&lt;/P&gt;&lt;P&gt;nat (OUTSIDE) 2 access-list SPOKE-NAT&lt;BR /&gt;global (INTERNAL) 2 10.100.43.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list P3NAT&amp;nbsp;permit ip ho 172.23.102.92 10.100.43.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (INTERNAL,OUTSIDE) 172.25.1.42 access-list P3NAT&lt;/P&gt;&lt;P&gt;================================&lt;/P&gt;&lt;P&gt;Upon using Packet Tracer , it says "translating&amp;nbsp;to dynamic pool 2 (no matching global)"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519974#M235229</guid>
      <dc:creator>Ramakrishnan R</dc:creator>
      <dc:date>2019-03-12T04:41:09Z</dc:date>
    </item>
    <item>
      <title>Hi, Can you post the complete</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519975#M235232</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post the complete output of the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command and the actual command used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you mean that you want to use a NAT Pool in this case? If so you should have something like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (INTERNAL) 2 10.100.43.1-10.100.43.253&lt;BR /&gt;global (INTERNAL) 2 10.100.43.254&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2014 19:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519975#M235232</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-08-27T19:07:37Z</dc:date>
    </item>
    <item>
      <title>Packet Trace Logs : packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519976#M235234</link>
      <description>&lt;P&gt;Packet Trace Logs : packet-tracer input MPLS-ZONE tcp 172.22.1.1 80 172.25.1.42 80 det&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: CAPTURE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x928ae750, priority=12, domain=capture, deny=false&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=7342021, user_data=0x92afd1f0, cs_id=0x0, l3_type=0x0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x91cc2ba0, priority=1, domain=permit, deny=false&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=511378318, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst mac=0000.0000.0000, mask=0100.0000.0000&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (INTERNAL,OUTSIDE) 172.25.1.42 &amp;nbsp;access-list P3NAT&lt;BR /&gt;&amp;nbsp; match ip INTERNAL host 172.23.102.92 OUTSIDE 10.100.43.0 255.255.255.0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; static translation to 172.25.1.42&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 25&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface INTERNAL&lt;BR /&gt;Untranslate 172.25.1.42/0 to 172.23.102.92/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group OUTSIDE in interface OUTSIDE&lt;BR /&gt;access-list OUTSIDE extended permit ip any any&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x91edba68, priority=12, domain=permit, deny=false&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=28433851, user_data=0x8e9fc000, cs_id=0x0, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x91cc5018, priority=0, domain=inspect-ip-options, deny=true&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=58261256, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x91cbbb48, priority=21, domain=lu, deny=true&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=4473467, user_data=0x0, cs_id=0x0, flags=0x0, protocol=6&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=80, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (OUTSIDE) 2 access-list SPOKE-NAT&lt;BR /&gt;&amp;nbsp; match ip OUTSIDE 172.16.0.0 255.240.0.0 OUTSIDE host 172.25.1.42&lt;BR /&gt;&amp;nbsp; &amp;nbsp; dynamic translation to pool 2 (No matching global)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Forward Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x92cd1e08, priority=2, domain=host, deny=false&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=23362, user_data=0x926a5c18, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src ip=172.16.0.0, mask=255.240.0.0, port=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (INTERNAL,OUTSIDE) 172.25.1.42 &amp;nbsp;access-list P3NAT&lt;BR /&gt;&amp;nbsp; match ip INTERNAL host 172.23.102.92 OUTSIDE 10.100.43.0 255.255.255.0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; static translation to 172.25.1.42&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 25&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Reverse Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x926b2b30, priority=5, domain=host, deny=false&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=41, user_data=0x92b01db0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src ip=172.23.102.92, mask=255.255.255.255, port=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&amp;nbsp;Reverse Flow based lookup yields rule:&lt;BR /&gt;&amp;nbsp;in &amp;nbsp;id=0x929d89d0, priority=0, domain=inspect-ip-options, deny=true&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; hits=2515, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 94023450, packet dispatched to next module&lt;BR /&gt;Module information for forward flow ...&lt;BR /&gt;snp_fp_tracer_drop&lt;BR /&gt;snp_fp_inspect_ip_options&lt;BR /&gt;snp_fp_tcp_normalizer&lt;BR /&gt;snp_fp_translate&lt;BR /&gt;snp_fp_adjacency&lt;BR /&gt;snp_fp_fragment&lt;BR /&gt;snp_ifc_stat&lt;/P&gt;&lt;P&gt;Module information for reverse flow ...&lt;BR /&gt;snp_fp_tracer_drop&lt;BR /&gt;snp_fp_inspect_ip_options&lt;BR /&gt;snp_fp_translate&lt;BR /&gt;snp_fp_tcp_normalizer&lt;BR /&gt;snp_fp_adjacency&lt;BR /&gt;snp_fp_fragment&lt;BR /&gt;snp_ifc_stat&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: OUTSIDE&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: INTERNAL&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2014 07:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519976#M235234</guid>
      <dc:creator>Ramakrishnan R</dc:creator>
      <dc:date>2014-08-28T07:51:55Z</dc:date>
    </item>
    <item>
      <title>Anyone who could help me out</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519977#M235235</link>
      <description>&lt;P&gt;Anyone who could help me out here !!!!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2014 14:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-2-twice-nat-problem/m-p/2519977#M235235</guid>
      <dc:creator>Ramakrishnan R</dc:creator>
      <dc:date>2014-09-04T14:02:07Z</dc:date>
    </item>
  </channel>
</rss>

