<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Issues continue with ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370658#M270872</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible it is a setting on my router that is preventing access to resources behind it? I can't see anything that stands out but I am just learning this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me the ASA is working because it allows me to SSH to the routers, I just can't access resources on the other side of the routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 4779 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;! Last configuration change at 04:01:02 UTC Tue Jan 28 2014 by mtuckness&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname CISCO-2811&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot system flash&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret 4 DWJfYBf6KhkIRmhhIhVGQWjwfuyzfaX4Im8M&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 syslog&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;no ip dhcp use vrf connected&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.1 192.168.1.49&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.10.1 172.16.10.49&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.20.1 172.16.20.49&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool Mitchs_Network&lt;/P&gt;&lt;P&gt; network 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt; dns-server 192.168.1.2 199.195.x.x 205.171.2.65 205.171.3.65 8.8.8.8&lt;/P&gt;&lt;P&gt; default-router 192.168.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool VLAN10&lt;/P&gt;&lt;P&gt; network 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; default-router 172.16.10.1&lt;/P&gt;&lt;P&gt; dns-server 199.195.x.x 205.171.2.65 205.171.3.65 8.8.8.8&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool VLAN20&lt;/P&gt;&lt;P&gt; network 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt; dns-server 199.195.x.x 205.171.2.65 205.171.3.65 8.8.8.8&lt;/P&gt;&lt;P&gt; default-router 172.16.20.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip domain name maladomini.int&lt;/P&gt;&lt;P&gt;ip name-server 192.168.1.2&lt;/P&gt;&lt;P&gt;ip name-server 199.195.xxx.x&lt;/P&gt;&lt;P&gt;ip name-server 205.171.2.65&lt;/P&gt;&lt;P&gt;ip name-server 205.171.3.65&lt;/P&gt;&lt;P&gt;ip name-server 8.8.8.8&lt;/P&gt;&lt;P&gt;no vlan accounting input&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;password encryption aes&lt;/P&gt;&lt;P&gt;crypto pki token default removal timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki trustpoint TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt; enrollment selfsigned&lt;/P&gt;&lt;P&gt; subject-name cn=IOS-Self-Signed-Certificate-1290569776&lt;/P&gt;&lt;P&gt; revocation-check none&lt;/P&gt;&lt;P&gt; rsakeypair TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki certificate chain TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt; certificate self-signed 01&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030&lt;/P&gt;&lt;P&gt;&amp;nbsp; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;/P&gt;&lt;P&gt;&amp;nbsp; 69666963 31323930 35363937 3736301E 170D3134 30313035 30363130&lt;/P&gt;&lt;P&gt;&amp;nbsp; 33395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 32393035&lt;/P&gt;&lt;P&gt;&amp;nbsp; 36393737 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8100B18F F63C5121 00785DE0 854601BA EE77DAA3 21286D8C 6E700C37 237CC1BE&lt;/P&gt;&lt;P&gt;&amp;nbsp; 611023AF FBE04BBE 7B4B3233 E4E129DD A74604E5 62AA39BF 77F98D5D D63944E9&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2345AE37 D93C5753 E425E85A EB22C2C9 CFC5D1A0 F800449B 0419A5C8 A0A101EC&lt;/P&gt;&lt;P&gt;&amp;nbsp; 02928172 7B30A609 71ADA3D4 68F4F484 AF2B3249 0E225DB2 C72C136A E670D761&lt;/P&gt;&lt;P&gt;&amp;nbsp; DDE30203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603&lt;/P&gt;&lt;P&gt;&amp;nbsp; 551D2304 18301680 1461F6DE 8EF50F7B 0E46359F 421EA106 9375F65F 30301D06&lt;/P&gt;&lt;P&gt;&amp;nbsp; 03551D0E 04160414 61F6DE8E F50F7B0E 46359F42 1EA10693 75F65F30 300D0609&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2A864886 F70D0101 05050003 81810049 BA55F695 8525265F ED2D77EE 8706BF10&lt;/P&gt;&lt;P&gt;&amp;nbsp; 63A7E644 202F6663 9EA5551F 47F7FC50 D4021EDD E3DC5A80 39FD161A C337D20D&lt;/P&gt;&lt;P&gt;&amp;nbsp; 71B98875 0F1FE887 649E81D3 F93F7A1B A1E18B99 A77B1A59 84DB4711 867913FD&lt;/P&gt;&lt;P&gt;&amp;nbsp; 044084FB 651ECA6E C6EDF35C E43A2946 8C01781E 26DB9484 C8740A82 4A7CA266&lt;/P&gt;&lt;P&gt;&amp;nbsp; A0655526 CBCB4982 F30D68E9 D70753&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;license udi pid CISCO2811 sn FTX1041A07T&lt;/P&gt;&lt;P&gt;username secret 5 $18dqYMcpTex8gtUfannzox.&lt;/P&gt;&lt;P&gt;username&amp;nbsp; privilege 15 secret 4 DWJfYBf6KhhIhx8ibAAXVGQWjwfuyzfaX4Im8M&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;redundancy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip ssh time-out 60&lt;/P&gt;&lt;P&gt;ip ssh authentication-retries 5&lt;/P&gt;&lt;P&gt;ip ssh version 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; description CONNECTION TO INSIDE INT. OF ASA&lt;/P&gt;&lt;P&gt; ip address 10.10.1.2 255.255.255.252&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.1&lt;/P&gt;&lt;P&gt; description VLAN 10&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 10&lt;/P&gt;&lt;P&gt; ip address 172.16.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.2&lt;/P&gt;&lt;P&gt; description VLAN 20&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 20&lt;/P&gt;&lt;P&gt; ip address 172.16.20.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.3&lt;/P&gt;&lt;P&gt; description Trunk Interface VLAN 1&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 1 native&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dialer0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; network 172.16.0.0&lt;/P&gt;&lt;P&gt; network 192.168.1.0&lt;/P&gt;&lt;P&gt; network 199.195.xxx.0&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 10.10.1.1&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;ip http authentication local&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dns server&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.10.1.1&lt;/P&gt;&lt;P&gt;ip ospf name-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 1 permit any&lt;/P&gt;&lt;P&gt;dialer-list 1 protocol ip permit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tftp-server system:running-config 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; password 7 101D58606050A147A&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 20 in&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; password 7 115A485010D241575&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;scheduler allocate 20000 1000&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Feb 2014 21:54:47 GMT</pubDate>
    <dc:creator>Mitchell Tuckness</dc:creator>
    <dc:date>2014-02-03T21:54:47Z</dc:date>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370636#M270832</link>
      <description>&lt;P&gt;I am still having access issues when using NAT on my ASA 5510. I think it is due to the way I have my ASA setup and the usage of PAT and NAT. I am not sure of the differences in them as of yet, but because I have routers behind my ASA, it seems to me that the issues might relate to the PAT, NAT and the Routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can refer to this link to see my network diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/4145313#4145313" target="_blank"&gt;https://supportforums.cisco.com/message/4145313#4145313&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is, I cannot seem to access any devices behind the routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My initial thought when I started this learning process was to use the ASA as the one point of access to the internet as a firewall. Then behind that I would have my routers and the subnets behind them, including switches and all that stuff. But there is apparently different ways of doing this and the information I get doesn't seem to be consistent, or I should say it is consistent, but doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason, I cannot seem to forward packets from the external interface (internet) on the ASA, to resources behind the routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I create a network object. Assign it a host. Create the NAT statement. Create the access list. and yet the packets still get denied. The error I see on the ASDM is basically always the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jan 27 2014&lt;/TD&gt;&lt;TD&gt;10:36:46&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;98.22.xxx.xxx&lt;/TD&gt;&lt;TD&gt;14979&lt;/TD&gt;&lt;TD&gt;192.168.1.2&lt;/TD&gt;&lt;TD&gt;3389&lt;/TD&gt;&lt;TD&gt;Routing failed to locate next hop for TCP from Outside:98.22.xxx.xxx/14979 to Inside:192.168.1.2/3389&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing I noticed is that no matter what I specify as the port leaving my network here at work, the ASA doesn't see it as that port. RDP, for example, is supposed to use 3389. But as you see from this caption of my ASA log, I initiated an RDP connection from my work computer and when it hit the ASA is is on port 14979 which if I read this correctly is 98.22.xxx.xxx 14979 then converted to 192.168.1.2 port 3389.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a Object Network Group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network RDP-DC1&lt;/P&gt;&lt;P&gt; host 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set NAT within the group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network RDP-DC1&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp 3389 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then created an Access-List:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object RDP-DC1 eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the result is the same as I get when I created the one to allow http traffic on port 8080 to hit an internal address on port 80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know where my NAT issue is, but I am beginning to think it is in the PAT. Maybe I should create only static routes from the ASA to the routers and then setup the routers to allow access as needed? Right now, I believe the routers are allowing any traffic, since I have the access-list permit any any statement. That does mean allow any traffic to any location, including from the 'Outside' source?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the PAT trying to bypass the routers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some outputs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# sh run nat&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network ROUTER-2811&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp ssh 222&lt;/P&gt;&lt;P&gt;object network ROUTER-2821&lt;/P&gt;&lt;P&gt; nat (DMZ,Outside) static interface service tcp ssh 2222&lt;/P&gt;&lt;P&gt;object network WEBCAM-01&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp www 8080&lt;/P&gt;&lt;P&gt;object network ROUTER-3745&lt;/P&gt;&lt;P&gt; nat (VOIP,Outside) static interface service tcp ssh 2223&lt;/P&gt;&lt;P&gt;object network RDP-DC1&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp 3389 3389&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (any,Outside) after-auto source dynamic PAT-SOURCE interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# sh run access-list&lt;/P&gt;&lt;P&gt;access-list USERS standard permit 10.10.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object ROUTER-2811 eq ssh&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object ROUTER-2821 eq ssh&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx interface Outside eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object WEBCAM-01 eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object RDP-DC1 eq 3389&lt;/P&gt;&lt;P&gt;access-list dmz-access-vlan1 extended permit ip 128.162.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit all traffic to DC1&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit ip 128.162.1.0 255.255.255.0 host 192.168.1.2&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit only DNS traffic to DNS server&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit udp 128.162.1.0 255.255.255.0 host 192.168.1.2 eq domain&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit ICMP to all devices in DC&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit icmp 128.162.1.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# sh run object-group&lt;/P&gt;&lt;P&gt;object-group network PAT-SOURCE&lt;/P&gt;&lt;P&gt; network-object 10.10.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 10.10.0.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 10.10.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt; network-object host 98.22.xxx.xxx&lt;/P&gt;&lt;P&gt;object-group network Outside_access_in&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt; protocol-object gre&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/8/1/178182-Network.jpg" alt="Network.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to be missing something in my config preventing nat from working as it should and the work arounds that I do seem to not work properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only statements that do work are the o nes that allow me to SSH into the Routers that are on each interface of the ASA. So I can ssh into the 2811, 2821 fine, but nothing behind them.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370636#M270832</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2019-03-12T03:36:37Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370637#M270834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mitchell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a route on your ASA telling it how to get to 192.168.1.2 ie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 192.168.1.0 255.255.255.0 10.10.1.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition does the router have a route pointing to the ASA eg. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.10.1.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 20:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370637#M270834</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-01-27T20:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370638#M270837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 2811 has:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#sh ip route&lt;/P&gt;&lt;P&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + - replicated route, % - next hop override&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 10.10.1.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0 [1/0] via 10.10.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.0/30 is directly connected, FastEthernet0/0&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.2/32 is directly connected, FastEthernet0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.0.0/16 is variably subnetted, 4 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.0/24 is directly connected, FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.1/32 is directly connected, FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.0/24 is directly connected, FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.1/32 is directly connected, FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0/24 is variably subnetted, 2 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0/24 is directly connected, FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.1/32 is directly connected, FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA has:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# show route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 199.195.xxx.xxx to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.xxx.xxx 255.255.255.240 is directly connected, Outside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.0 255.255.255.252 is directly connected, DMZ&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.0 255.255.255.252 is directly connected, Inside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.2.0 255.255.255.252 is directly connected, VOIP&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 199.195.xxx.xxx, Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh ip address&lt;/P&gt;&lt;P&gt;System IP Addresses:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 CONFIG&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.xxx.xxx 255.255.255.240 CONFIG&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 manual&lt;/P&gt;&lt;P&gt;Ethernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VOIP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.2.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 manual&lt;/P&gt;&lt;P&gt;Current IP Addresses:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 CONFIG&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.xxx.xxx 255.255.255.240 CONFIG&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 manual&lt;/P&gt;&lt;P&gt;Ethernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VOIP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.2.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 manual&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 21:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370638#M270837</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-27T21:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370639#M270838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mitchell &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;One thing I noticed is that no matter what I specify as the port leaving my network here at work, the ASA doesn't see it as that port. RDP, for example, is supposed to use 3389. But as you see from this caption of my ASA log, I initiated an RDP connection from my work computer and when it hit the ASA is is on port 14979 which if I read this correctly is 98.22.xxx.xxx 14979 then converted to 192.168.1.2 port 3389.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I think you are reading it incorrectly. What it is saying is the source of the packet is 98.22.x.x using a random port and the destination is the 192.168.1.2 using RDP ie. it has already translated the destination IP from the interface IP to 192.168.1.2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a route on the ASA for 192.168.1.0/24. From the ASA can you ping 192.168.1.2 ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 22:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370639#M270838</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-01-27T22:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370640#M270841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot ping any addresses behind the routers, including 192.168.1.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# ping 192.168.1.2&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;?????&lt;/P&gt;&lt;P&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 22:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370640#M270841</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-27T22:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370641#M270843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mitchell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason the ASA is not using the route for 192.168.1.0/24 you have added. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post "sh xlate local 192.168.1.2" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 22:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370641#M270843</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-01-27T22:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370642#M270845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA5510(config)# sh xlate local 192.168.1.2&lt;/P&gt;&lt;P&gt;21 in use, 784 most used&lt;/P&gt;&lt;P&gt;Flags: D - DNS, e - extended, I - identity, i - dynamic, r - portmap,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; s - static, T - twice, N - net-to-net&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:192.168.1.2 3389-3389 to Outside:199.195.xxx.xxx 3389-3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 3:19:10 timeout 0:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the one for the WEBCAM that is also not working:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# sh xlate local 192.168.1.5&lt;/P&gt;&lt;P&gt;36 in use, 784 most used&lt;/P&gt;&lt;P&gt;Flags: D - DNS, e - extended, I - identity, i - dynamic, r - portmap,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; s - static, T - twice, N - net-to-net&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:192.168.1.5 80-80 to Outside:199.195.xxx.xxx 8080-8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 0:43:27 timeout 0:00:00&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 22:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370642#M270845</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-27T22:27:36Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370643#M270846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mitchell &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see anything obviously wrong with this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has the correct xlate entry and the correct route for this to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are you accessing it ie. via VPN or not ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 22:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370643#M270846</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-01-27T22:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370644#M270848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From a static IP (not VPN) at work. No VPN tunnel, just from my works PC, which runs on a 192.168.116.0 subnet through a couple of routers and out a firewall with the static IP of 98.22.xxx.xxx and then to my ASA @ home.&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;P&gt;&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Mitchell Tuckness : IP (not VPN)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 00:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370644#M270848</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-28T00:12:51Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370645#M270852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I noticed I had ip source-route enabled on the router, you don't think that could have any impact on this issue? I also read that depending on the license on the ASA it can only do so much?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tured off ip source-route since it seems like most posts say it is not usually enabled. I am at a loss as to why I can't get this to work.&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 03:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370645#M270852</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-28T03:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370646#M270854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No more ideas? &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; I am a /sad sad camper. I hate it when you're (think) doing things right and it doesn't work and your trying to learn and not sure what's up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 16:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370646#M270854</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-28T16:11:30Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370647#M270856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there anything I can run to help diagnose this? Something on the ASA or router? Some config I might run that would help figure it out?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 18:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370647#M270856</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-28T18:56:22Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370648#M270857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mitchell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still can't see what's wrong with this. Can you try removing the NAT statement for the routers outside interface ie. the ssh one and see if you still see the same problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The failed to locate next hop is usually to do with VPN traffic which is why i asked about it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think it is anything on the router as it is the ASA that seems unable to use the route in it's routing table. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 21:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370648#M270857</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-01-28T21:14:41Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370649#M270858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry, which statement should I remove?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 22:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370649#M270858</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-28T22:30:01Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370650#M270859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mitchell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT statement you have for the outside interface of the 2811. It is a long shot but i am wondering if because the next hop in the route also has a NAT statement for the same IP they are somehow conflicting. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 22:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370650#M270859</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-01-28T22:32:34Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370651#M270860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I removed the statement under the network object for the NAT for ssh, no change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network ROUTER-2811&lt;/P&gt;&lt;P&gt;no nat (Inside,Outside) static interface service tcp ssh 222&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume that was the NAT you were talking about?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the route table as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 199.195.xxx.xxx to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.1.0 255.255.255.0 [1/0] via 10.10.0.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.10.0 255.255.255.0 [1/0] via 10.10.0.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.20.0 255.255.255.0 [1/0] via 10.10.0.2, Inside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.xxx.xxx 255.255.255.240 is directly connected, Outside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.0 255.255.255.252 is directly connected, DMZ&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.0 255.255.255.252 is directly connected, Inside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.2.0 255.255.255.252 is directly connected, VOIP&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 199.195.xxx.xxx, Outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 22:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370651#M270860</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-28T22:50:58Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370652#M270862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mitchell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you clear the xlate table for that NAT statement when you removed it ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post full config of ASA ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 23:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370652#M270862</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-01-28T23:00:38Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370653#M270863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shoot, no I didn't and I thought about it, but didn't &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh running-config&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 9.1(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASA5510&lt;/P&gt;&lt;P&gt;domain-name maladomini.int&lt;/P&gt;&lt;P&gt;enable password liSfzvir2g encrypted&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;passwd fzvir2g encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; description LAN Interface&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.1.1 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; description WAN Interface&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 199.195.xxx.xxx 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; description DMZ&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.0.1 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description VOIP&lt;/P&gt;&lt;P&gt; nameif VOIP&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.2.1 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa914-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup Outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 199.195.xxx.xxx&lt;/P&gt;&lt;P&gt; name-server 205.171.2.65&lt;/P&gt;&lt;P&gt; name-server 205.171.3.65&lt;/P&gt;&lt;P&gt; domain-name maladomini.int&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;object network ROUTER-2811&lt;/P&gt;&lt;P&gt; host 10.10.1.2&lt;/P&gt;&lt;P&gt;object network ROUTER-2821&lt;/P&gt;&lt;P&gt; host 10.10.0.2&lt;/P&gt;&lt;P&gt;object network WEBCAM-01&lt;/P&gt;&lt;P&gt; host 192.168.1.5&lt;/P&gt;&lt;P&gt;object network DNS-SERVER&lt;/P&gt;&lt;P&gt; host 192.168.1.2&lt;/P&gt;&lt;P&gt;object network ROUTER-3745&lt;/P&gt;&lt;P&gt; host 10.10.2.2&lt;/P&gt;&lt;P&gt;object network RDP-DC1&lt;/P&gt;&lt;P&gt; host 192.168.1.2&lt;/P&gt;&lt;P&gt;object-group network PAT-SOURCE&lt;/P&gt;&lt;P&gt; network-object 10.10.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 10.10.0.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 10.10.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt; network-object host 98.22.xxx.xxx&lt;/P&gt;&lt;P&gt;object-group network Outside_access_in&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt; protocol-object gre&lt;/P&gt;&lt;P&gt;access-list USERS standard permit 10.10.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object ROUTER-2811 eq ssh&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object ROUTER-2821 eq ssh&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx interface Outside eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object WEBCAM-01 eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.xxx.xxx object RDP-DC1 eq 3389&lt;/P&gt;&lt;P&gt;access-list dmz-access-vlan1 extended permit ip 128.162.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit all traffic to DC1&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit ip 128.162.1.0 255.255.255.0 host 192.168.1.2&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit only DNS traffic to DNS server&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit udp 128.162.1.0 255.255.255.0 host 192.168.1.2 eq domain&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit ICMP to all devices in DC&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit icmp 128.162.1.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Inside 1500&lt;/P&gt;&lt;P&gt;mtu Outside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu VOIP 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp deny any Outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-715.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network ROUTER-2811&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp ssh 222&lt;/P&gt;&lt;P&gt;object network ROUTER-2821&lt;/P&gt;&lt;P&gt; nat (DMZ,Outside) static interface service tcp ssh 2222&lt;/P&gt;&lt;P&gt;object network WEBCAM-01&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp www 8080&lt;/P&gt;&lt;P&gt;object network ROUTER-3745&lt;/P&gt;&lt;P&gt; nat (VOIP,Outside) static interface service tcp ssh 2223&lt;/P&gt;&lt;P&gt;object network RDP-DC1&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp 3389 3389&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (any,Outside) after-auto source dynamic PAT-SOURCE interface&lt;/P&gt;&lt;P&gt;access-group Outside_access_in in interface Outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; network 10.0.0.0&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 199.195.xxx.xxx 1&lt;/P&gt;&lt;P&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/P&gt;&lt;P&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/P&gt;&lt;P&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/P&gt;&lt;P&gt;route Inside 172.16.10.0 255.255.255.0 10.10.1.2 1&lt;/P&gt;&lt;P&gt;route Inside 172.16.20.0 255.255.255.0 10.10.1.2 1&lt;/P&gt;&lt;P&gt;route Inside 192.168.1.0 255.255.255.0 10.10.1.2 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 Inside&lt;/P&gt;&lt;P&gt;http 98.22.xxx.xxx 255.255.255.255 Outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 Inside&lt;/P&gt;&lt;P&gt;ssh 98.22.xxx.xxx 255.255.255.255 Outside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;username&amp;nbsp; encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;password encryption aes&lt;/P&gt;&lt;P&gt;Cryptochecksum:95cd1440463ac3f&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 23:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370653#M270863</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-28T23:07:07Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370654#M270864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please put "ip subnet-zero "command and then try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Naisam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 11:13:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370654#M270864</guid>
      <dc:creator>Naisamuddin pk</dc:creator>
      <dc:date>2014-01-29T11:13:37Z</dc:date>
    </item>
    <item>
      <title>NAT Issues continue with ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370655#M270866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am sorry, I can't seem to find that command to run.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Closest I found was:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh ip address inside&lt;/P&gt;&lt;P&gt;System IP Address:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 CONFIG&lt;/P&gt;&lt;P&gt;Current IP Address:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 CONFIG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh ip address outside&lt;/P&gt;&lt;P&gt;System IP Address:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.xxx.xxx 255.255.255.240 CONFIG&lt;/P&gt;&lt;P&gt;Current IP Address:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.xxx.xxx 255.255.255.240 CONFIG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh ip address DMZ&lt;/P&gt;&lt;P&gt;System IP Address:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 manual&lt;/P&gt;&lt;P&gt;Current IP Address:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 manual&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Naisamuddin pk wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please put "ip subnet-zero "command and then try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Naisam&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 15:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issues-continue-with-asa-5510/m-p/2370655#M270866</guid>
      <dc:creator>Mitchell Tuckness</dc:creator>
      <dc:date>2014-01-29T15:43:12Z</dc:date>
    </item>
  </channel>
</rss>

