<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT excempt for VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863503#M25932</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the way I configure NATs, but I get the same issue.&lt;/P&gt;&lt;P&gt;It is not a configuration problem I suppose..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 27 May 2019 19:42:15 GMT</pubDate>
    <dc:creator>salva</dc:creator>
    <dc:date>2019-05-27T19:42:15Z</dc:date>
    <item>
      <title>NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3861943#M25929</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a network engineer working on a project to deploy and configure a series of ASA 5506-X running 9.9(2) iOS, I have encountered the following important issue:&lt;/P&gt;&lt;P&gt;When I configure a NAT Exempt rule for traffic flowing from one zone to another of the ASA itself, traffic from zone to zone works as expected with no issues.&lt;/P&gt;&lt;P&gt;When I configure a NAT Exempt rule for traffic flowing from one zone of the ASA to a remote network that resides on the other end of an IPSec VPN tunnel, the ASA with no obvious reason unchecks the "NAT Exempt" checkbox option in ASDM&amp;nbsp;and therefore deletes the NAT entry in the Firewall configuration.&lt;/P&gt;&lt;P&gt;If I go configure one NAT rule for each Group's object separately, the issue disappears.&lt;/P&gt;&lt;P&gt;You can easily understand that when the issue occurs the IPSec VPN tunnel goes down or does not work as expected (you can imagine what that means to a production network..)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this some kind of bug (in ASDM or iOS versions), does it has to do with the encrypted traffic or is it some kind of security feature on Cisco devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks everybody, looking forward to any feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Salvatore Comi&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2019 20:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3861943#M25929</guid>
      <dc:creator>salva</dc:creator>
      <dc:date>2019-05-23T20:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863128#M25931</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try to create a nat rule like below and add all your local or remote subnets in the object-group&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (inside,outside) source static Local-Subnet Local-Subnet destination static Remote-Subnet Remote-Subnet&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Hope This Helps&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Abheesh&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2019 07:03:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863128#M25931</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-05-27T07:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863503#M25932</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the way I configure NATs, but I get the same issue.&lt;/P&gt;&lt;P&gt;It is not a configuration problem I suppose..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2019 19:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863503#M25932</guid>
      <dc:creator>salva</dc:creator>
      <dc:date>2019-05-27T19:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863626#M25935</link>
      <description>&lt;BR /&gt;what is error which you are getting while entering the above command for nat..?</description>
      <pubDate>Tue, 28 May 2019 05:37:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863626#M25935</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-05-28T05:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863716#M25937</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I don't get any error when I configure NAT.&lt;/P&gt;&lt;P&gt;But the NAT entries disappear later on. The NAT exempt checkbox gets "unchecked" in ASDM and the NAT statement disappears..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 09:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863716#M25937</guid>
      <dc:creator>salva</dc:creator>
      <dc:date>2019-05-28T09:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863718#M25939</link>
      <description>&lt;P&gt;More precisely:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I configure the NAT rule all is ok at first.&lt;/P&gt;&lt;P&gt;Then a few hours later the client calls and says that the VPN does not work as expected.&lt;/P&gt;&lt;P&gt;When I check the configuration, the NAT rule is not there and I have to configure again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems like an iOS bug, but I am not sure..&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 09:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3863718#M25939</guid>
      <dc:creator>salva</dc:creator>
      <dc:date>2019-05-28T09:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3865200#M25941</link>
      <description>I tried it on mine and it worked fine but I mostly configure it via CLI. Why don't you do this:&lt;BR /&gt;- Login to ASA with ASD&lt;BR /&gt;- Check "preview commands before sending" from preferences and save&lt;BR /&gt;- Create a tunnel and hit apply, at this point you will see all the commands.&lt;BR /&gt;- Copy and paste the commands in notepad, remove that group policy thing (It's of no use)&lt;BR /&gt;- SSH into the ASA&lt;BR /&gt;- Paste all the commands&lt;BR /&gt;- write mem&lt;BR /&gt;- copy running-config startup-config&lt;BR /&gt;&lt;BR /&gt;Let us know how it goes.</description>
      <pubDate>Thu, 30 May 2019 14:52:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3865200#M25941</guid>
      <dc:creator>Abhijeet Kumar</dc:creator>
      <dc:date>2019-05-30T14:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: NAT excempt for VPN</title>
      <link>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3865336#M25942</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Hello Abhijeet,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try this to perform my tests, but if configuring directly through CLI is the only way to make NAT function properly, should I suppose it is an ASDM bug?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 18:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-excempt-for-vpn/m-p/3865336#M25942</guid>
      <dc:creator>salva</dc:creator>
      <dc:date>2019-05-30T18:18:27Z</dc:date>
    </item>
  </channel>
</rss>

