<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SteliosFrom the looks of your in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-static-nat-problem/m-p/2453190#M268034</link>
    <description>&lt;P&gt;Stelios&lt;/P&gt;&lt;P&gt;From the looks of your static statement you are running 8.3 or later code.&lt;/P&gt;&lt;P&gt;So in your acl you need to use the private IP of the server and not the the public IP.&lt;/P&gt;&lt;P&gt;Jon&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Mar 2014 14:21:25 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2014-03-27T14:21:25Z</dc:date>
    <item>
      <title>ASA 5505 - STATIC NAT PROBLEM</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-static-nat-problem/m-p/2453189#M268033</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;As you can see in the attached file i have a web server in dmz which has a real ip of 172.168.100.1 and a public ip&amp;nbsp;192.168.200.1 (let's assume that this is a public ip address for security reasons). All necessary configuration regarding natting and access-lists is in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From inside i can reach the web server and vice versa&lt;/P&gt;&lt;P&gt;From dmz i can reach the internet the weird thing is that if i try from a different internet line to ping 192.168.200.1 (web server's public ip) i can ping it without a problem but when i try to reach the web server via a browser i am receiving the timeout error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i change my access list entry &amp;nbsp;"access-list OUTSIDE-IN &amp;nbsp;extended permit tcp any host 192.168.200.1 eq 80" to the below&lt;/P&gt;&lt;P&gt;&amp;nbsp;"access-list OUTSIDE-IN &amp;nbsp;extended permit ip any any"&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to access the web server.&lt;/P&gt;&lt;P&gt;i've checked the real time log viewer and when i am using the&amp;nbsp;"access-list OUTSIDE-IN &amp;nbsp;extended permit tcp any host 192.168.200.1 eq 80" &amp;nbsp;i receive a deny tcp src outside ...by access-group OUTSIDE-IN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you believe it's blocking the connection?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stelios&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-static-nat-problem/m-p/2453189#M268033</guid>
      <dc:creator>STYLIANOS DEMETRIOU</dc:creator>
      <dc:date>2019-03-12T04:00:03Z</dc:date>
    </item>
    <item>
      <title>SteliosFrom the looks of your</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-static-nat-problem/m-p/2453190#M268034</link>
      <description>&lt;P&gt;Stelios&lt;/P&gt;&lt;P&gt;From the looks of your static statement you are running 8.3 or later code.&lt;/P&gt;&lt;P&gt;So in your acl you need to use the private IP of the server and not the the public IP.&lt;/P&gt;&lt;P&gt;Jon&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 14:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-static-nat-problem/m-p/2453190#M268034</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-27T14:21:25Z</dc:date>
    </item>
    <item>
      <title>Thanks a lot Jon, for</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-static-nat-problem/m-p/2453191#M268035</link>
      <description>&lt;P&gt;Thanks a lot Jon, for assisted me solve this problem.&lt;/P&gt;&lt;P&gt;The weird thing that i can't undestand, is that the icmp was working without a problem using the above mentioned access-list however accesing the web server using www wasn't working.&lt;/P&gt;&lt;P&gt;How you explain that?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2014 10:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-static-nat-problem/m-p/2453191#M268035</guid>
      <dc:creator>STYLIANOS DEMETRIOU</dc:creator>
      <dc:date>2014-03-28T10:14:06Z</dc:date>
    </item>
  </channel>
</rss>

