<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sorry i´ve digited wrong The in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543212#M237201</link>
    <description>&lt;P&gt;Sorry i´ve digited wrong&amp;nbsp;&lt;IMG alt="blush" height="23" src="https://supportforums.cisco.com/profiles/commons/libraries/ckeditor/plugins/smiley/images/embarrassed_smile.png" title="blush" width="23" /&gt;&lt;/P&gt;&lt;P&gt;The ACL is the follow but dont working yet :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;ip access-list extended OUT-TO-IN&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.11 eq 3389&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 3389&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 3389&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 50&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 50&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jun 2014 17:08:08 GMT</pubDate>
    <dc:creator>Thiago Cella</dc:creator>
    <dc:date>2014-06-25T17:08:08Z</dc:date>
    <item>
      <title>Static NAT problem with ZBF</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543208#M237197</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this scenario, the trafffic from INSIDE to OUTSIDE is working, but from OUTSIDE to INSIDE isnt working. For example, i created the NAT to 3389 , to external access to RDP, but no sucess.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Follow my config, TKS:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;class-map type inspect match-any TRAFFIC&lt;BR /&gt;&amp;nbsp;description TRAFFIC_MATCH&lt;BR /&gt;&amp;nbsp;match protocol icmp&lt;BR /&gt;&amp;nbsp;match protocol tcp&lt;BR /&gt;&amp;nbsp;match protocol udp&lt;BR /&gt;class-map type inspect match-any OUT-TO-IN&lt;BR /&gt;&amp;nbsp;match access-group name OUT-TO-IN&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect OUT-TO-IN&lt;BR /&gt;&amp;nbsp;class type inspect OUT-TO-IN&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect TRAFFIC_CLASS&lt;BR /&gt;&amp;nbsp;class type inspect TRAFFIC&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;!&lt;BR /&gt;zone security INSIDE&lt;BR /&gt;zone security OUTSIDE&lt;BR /&gt;zone-pair security TRAF source INSIDE destination OUTSIDE&lt;BR /&gt;&amp;nbsp;service-policy type inspect TRAFFIC_CLASS&lt;BR /&gt;zone-pair security OUT-TO-IN source OUTSIDE destination INSIDE&lt;BR /&gt;&amp;nbsp;service-policy type inspect OUT-TO-IN&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/0&lt;BR /&gt;&amp;nbsp;ip address 1.1.1.2 255.255.255.248&lt;BR /&gt;&amp;nbsp;ip nat outside&lt;BR /&gt;&amp;nbsp;ip nat enable&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly&lt;BR /&gt;&amp;nbsp;zone-member security OUTSIDE&lt;BR /&gt;&amp;nbsp;duplex auto&lt;BR /&gt;&amp;nbsp;speed auto&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;&amp;nbsp;duplex auto&lt;BR /&gt;&amp;nbsp;speed auto&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1.1&lt;BR /&gt;&amp;nbsp;encapsulation dot1Q 1 native&lt;BR /&gt;&amp;nbsp;ip address 192.168.92.251 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip nat enable&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly&lt;BR /&gt;&amp;nbsp;zone-member security INSIDE&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 1.1.1.1&lt;BR /&gt;no ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip nat inside source list inside_nat0_outbound interface FastEthernet0/0 overload&lt;BR /&gt;ip nat inside source static tcp 192.168.92.89 50 1.1.1.2 50 extendable&lt;BR /&gt;ip nat inside source static tcp 192.168.92.89 3389 1.1.1.2 3389 extendable&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended OUT-TO-IN&lt;BR /&gt;&amp;nbsp;permit tcp any host 192.168.92.11 eq 3389&lt;BR /&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 3389&lt;BR /&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 3389&lt;BR /&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 50&lt;BR /&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 50&lt;BR /&gt;ip access-list extended inside_nat0_outbound&lt;BR /&gt;&amp;nbsp;deny &amp;nbsp; ip 192.168.92.0 0.0.0.255 10.0.70.0 0.0.0.255&lt;BR /&gt;&amp;nbsp;deny &amp;nbsp; ip 192.168.93.0 0.0.0.255 10.0.70.0 0.0.0.255&lt;BR /&gt;&amp;nbsp;deny &amp;nbsp; ip 10.1.10.0 0.0.0.255 10.0.70.0 0.0.0.255&lt;BR /&gt;&amp;nbsp;deny &amp;nbsp; ip 10.2.1.0 0.0.0.255 10.0.20.0 0.0.0.255&lt;BR /&gt;&amp;nbsp;deny &amp;nbsp; ip 10.10.10.0 0.0.0.255 192.168.92.0 0.0.0.255&lt;BR /&gt;&amp;nbsp;deny &amp;nbsp; ip 192.168.92.0 0.0.0.255 10.10.10.0 0.0.0.255&lt;BR /&gt;&amp;nbsp;permit ip 192.168.92.0 0.0.0.255 any&lt;BR /&gt;&amp;nbsp;permit ip 172.31.0.0 0.0.0.255 any&lt;BR /&gt;&amp;nbsp;permit ip 192.168.0.0 0.0.0.255 any&lt;BR /&gt;!&lt;BR /&gt;disable-eadi&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;login&lt;BR /&gt;!&lt;BR /&gt;scheduler allocate 20000 1000&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543208#M237197</guid>
      <dc:creator>Thiago Cella</dc:creator>
      <dc:date>2019-03-12T04:22:55Z</dc:date>
    </item>
    <item>
      <title>The access-list is checked</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543209#M237198</link>
      <description>&lt;P&gt;The access-list is checked prior to un-NATting the address. Try with the outside address of your servers in "&lt;SPAN style="font-size: 14px;"&gt;ip access-list extended OUT-TO-IN&lt;/SPAN&gt;".&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2014 14:51:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543209#M237198</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-06-25T14:51:32Z</dc:date>
    </item>
    <item>
      <title>But the IP is there, look :</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543210#M237199</link>
      <description>&lt;P&gt;But the IP is there, look :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;ip access-list extended OUT-TO-IN&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;SPAN style="font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.11 eq 3389&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;SPAN style="font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 3389&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;SPAN style="font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 3389&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;SPAN style="font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 50&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;SPAN style="font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 50&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2014 16:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543210#M237199</guid>
      <dc:creator>Thiago Cella</dc:creator>
      <dc:date>2014-06-25T16:25:09Z</dc:date>
    </item>
    <item>
      <title>I mean the 1.1.1.x public IP</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543211#M237200</link>
      <description>&lt;P&gt;I mean the 1.1.1.x public IP address that appears on your outside interface and associated zone.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2014 16:25:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543211#M237200</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-06-25T16:25:10Z</dc:date>
    </item>
    <item>
      <title>Sorry i´ve digited wrong The</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543212#M237201</link>
      <description>&lt;P&gt;Sorry i´ve digited wrong&amp;nbsp;&lt;IMG alt="blush" height="23" src="https://supportforums.cisco.com/profiles/commons/libraries/ckeditor/plugins/smiley/images/embarrassed_smile.png" title="blush" width="23" /&gt;&lt;/P&gt;&lt;P&gt;The ACL is the follow but dont working yet :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;ip access-list extended OUT-TO-IN&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.11 eq 3389&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 3389&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 3389&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 192.168.92.89 eq 50&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;permit tcp any host 1.1.1.2 eq 50&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2014 17:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543212#M237201</guid>
      <dc:creator>Thiago Cella</dc:creator>
      <dc:date>2014-06-25T17:08:08Z</dc:date>
    </item>
    <item>
      <title>Friends, I removed the</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543213#M237202</link>
      <description>&lt;P&gt;Friends, I removed the command ip nat enable and works!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;i&lt;/SPAN&gt;&lt;SPAN style="font-size: 14px;"&gt;nterface FastEthernet0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;&amp;nbsp;&lt;SPAN style="color:#FF0000;"&gt;&lt;STRONG&gt;ip nat enable&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;SPAN style="font-size: 14px;"&gt;!&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;SPAN style="font-size: 14px;"&gt;interface FastEthernet0/1.1&lt;/SPAN&gt;&lt;BR style="font-size: 14px;" /&gt;&lt;STRONG&gt;&lt;SPAN style="color:#FF0000;"&gt;&lt;SPAN style="font-size: 14px;"&gt;&amp;nbsp;ip nat enable&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR style="font-size: 14px;" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But i have another question, I created the DMZ ZONE, everthing works, but the DMZ network can ping the IP&amp;nbsp;&lt;SPAN style="font-size: 14px;"&gt;192.168.92.251 ( Interface of the router-Inside Network). But following the config, the DMZ couldnt ping this address, is it correct?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zone security DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.2&lt;BR /&gt;&amp;nbsp;encapsulation dot1Q 2&lt;BR /&gt;&amp;nbsp;ip address 192.168.0.33 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly&lt;BR /&gt;&amp;nbsp;zone-member security DMZ&lt;/P&gt;&lt;P&gt;class-map type inspect match-any DMZ-TO-ALL&lt;BR /&gt;&amp;nbsp;match access-group name dmz_out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map type inspect DMZ-TO-ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp;class type inspect DMZ-TO-ALL&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;zone-pair security DMZ-TO-ALL source DMZ destination OUTSIDE&lt;BR /&gt;&amp;nbsp;service-policy type inspect DMZ-TO-ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip access-list extended lab_out&lt;BR /&gt;&amp;nbsp;deny &amp;nbsp; ip 192.168.0.0 0.0.0.255 192.168.92.0 0.0.0.255&lt;BR /&gt;&amp;nbsp;&amp;nbsp;permit ip 192.168.0.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 11:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-problem-with-zbf/m-p/2543213#M237202</guid>
      <dc:creator>Thiago Cella</dc:creator>
      <dc:date>2014-06-26T11:34:01Z</dc:date>
    </item>
  </channel>
</rss>

