<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Will Not Work in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-will-not-work/m-p/2445403#M269233</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the packet tracer shows as allowed, I would do a packet capture.&amp;nbsp; This will give us a good idea if the packets is entering and leaving the outside interface, as well as entering and leaving the inside interface.&amp;nbsp; Please post the results here for further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is a link on how to perform a packet capture:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/110117-asa-capture-asdm-config.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/110117-asa-capture-asdm-config.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Feb 2014 08:19:53 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-02-21T08:19:53Z</dc:date>
    <item>
      <title>NAT Will Not Work</title>
      <link>https://community.cisco.com/t5/network-security/nat-will-not-work/m-p/2445401#M269231</link>
      <description>&lt;P&gt;I have the following configured on an ASA running 9.1(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network Webserver&lt;/P&gt;&lt;P&gt; Host&amp;nbsp; 10.10.10.1&lt;/P&gt;&lt;P&gt; nat (DMZ,outside) static 208.2.3.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list knock_knock extended permit tcp any object Webserver eq http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-group &lt;SPAN style="font-size: 10pt;"&gt;knock_knock &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;in interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT.. I still cannot get to the the webserver from the outside(internet). so I captured some logs and found that the NAT and access list mentioned above are actually working (please see the attached screen capture)&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/2/0/181026-DMZ%20Trouble.JPG" alt="DMZ Trouble.JPG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT is definitely working since my independent test from the outside registers as "hits" each time I try to get to the HTTP server. The logs tell me that it Builds and Tears down the attempted connection instantaneously. Since I know that the NAT and the access list on the outside interface are both working components, troubleshooting them would be a waste of time. The Server itself can access the internet(outside) without any issues from behind the DMZ where it lives. I tested it's ability to do so by logging on and browsing the internet (yahoo, CNN etc..) so the basic principles of the server are fine (IP, Gateway Subnet connectivity etc..)&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;BR style="font-family: 'Droid Serif', Georgia, 'Times New Roman', serif; color: #222222; line-height: 20px; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;What would you do at this point? &lt;/P&gt;&lt;P&gt;&lt;BR style="font-family: 'Droid Serif', Georgia, 'Times New Roman', serif; color: #222222; line-height: 20px; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P style="text-align: left;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-will-not-work/m-p/2445401#M269231</guid>
      <dc:creator>chris.mcdermott</dc:creator>
      <dc:date>2019-03-12T03:48:15Z</dc:date>
    </item>
    <item>
      <title>NAT Will Not Work</title>
      <link>https://community.cisco.com/t5/network-security/nat-will-not-work/m-p/2445402#M269232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the output of the following command from the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#packet-tracer input dmz tcp &lt;SOURCE ip=""&gt; http &lt;DESTINATION ip=""&gt; http&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 04:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-will-not-work/m-p/2445402#M269232</guid>
      <dc:creator>vishaw jasrotia</dc:creator>
      <dc:date>2014-02-21T04:51:09Z</dc:date>
    </item>
    <item>
      <title>NAT Will Not Work</title>
      <link>https://community.cisco.com/t5/network-security/nat-will-not-work/m-p/2445403#M269233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the packet tracer shows as allowed, I would do a packet capture.&amp;nbsp; This will give us a good idea if the packets is entering and leaving the outside interface, as well as entering and leaving the inside interface.&amp;nbsp; Please post the results here for further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is a link on how to perform a packet capture:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/110117-asa-capture-asdm-config.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/110117-asa-capture-asdm-config.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 08:19:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-will-not-work/m-p/2445403#M269233</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-21T08:19:53Z</dc:date>
    </item>
  </channel>
</rss>

