<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NATing &amp;quot;Reverse Path Failure&amp;quot; problem - help required in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nating-quot-reverse-path-failure-quot-problem-help-required/m-p/3923657#M24528</link>
    <description>You need service https https in the below statement.&lt;BR /&gt;&lt;BR /&gt;nat (INSIDE,MY-ISP) source static obj-Web_Server interface service any REMOTE-HTTPS&lt;BR /&gt;&lt;BR /&gt;And make sure you have configured ACL on the interface MY-ISP to allow access in for your web server.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
    <pubDate>Fri, 13 Sep 2019 02:27:06 GMT</pubDate>
    <dc:creator>bhargavdesai</dc:creator>
    <dc:date>2019-09-13T02:27:06Z</dc:date>
    <item>
      <title>NATing "Reverse Path Failure" problem - help required</title>
      <link>https://community.cisco.com/t5/network-security/nating-quot-reverse-path-failure-quot-problem-help-required/m-p/3923579#M24527</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new to ASA's and I have a NATing issue which I'm unable to resolve.&amp;nbsp; I'm trying to allow external access through my ASA to a Web Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've used the Packet Tracer in the ASDM and it's recording the following in the Monitoring log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp src MY-ISP:xx.xx.xx.xx/1065 dst INSIDE:10.10.10.101/443 denied due to NAT reverse path failure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NAT Rule I have added is as follows&lt;/P&gt;&lt;P&gt;nat (INSIDE,MY-ISP) source static obj-Web_Server interface service any REMOTE-HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where&lt;/P&gt;&lt;P&gt;object network obj-WEB_Server&lt;BR /&gt;host 10.10.10.101&lt;/P&gt;&lt;P&gt;object service REMOTE-HTTPS&lt;BR /&gt;service tcp source eq https&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ISP Connection is presented as 192.168.1.17.&amp;nbsp; The ISP forwards all ports from their router to mine.&amp;nbsp; I have a 0.0.0.0 0.0.0.0 via 192.168.1.1 for my ISP connection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what I have read, it seems I need to add a NoNat ACL somewhere, but with the ASDM, I'm not sure as to where this should be added, and in what form.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 21:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nating-quot-reverse-path-failure-quot-problem-help-required/m-p/3923579#M24527</guid>
      <dc:creator>Cormac Champion</dc:creator>
      <dc:date>2019-09-12T21:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: NATing "Reverse Path Failure" problem - help required</title>
      <link>https://community.cisco.com/t5/network-security/nating-quot-reverse-path-failure-quot-problem-help-required/m-p/3923657#M24528</link>
      <description>You need service https https in the below statement.&lt;BR /&gt;&lt;BR /&gt;nat (INSIDE,MY-ISP) source static obj-Web_Server interface service any REMOTE-HTTPS&lt;BR /&gt;&lt;BR /&gt;And make sure you have configured ACL on the interface MY-ISP to allow access in for your web server.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Fri, 13 Sep 2019 02:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nating-quot-reverse-path-failure-quot-problem-help-required/m-p/3923657#M24528</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-13T02:27:06Z</dc:date>
    </item>
  </channel>
</rss>

