<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 9.1 NAT Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351110#M306157</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;happy to help!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Jan 2014 05:44:42 GMT</pubDate>
    <dc:creator>jumora</dc:creator>
    <dc:date>2014-01-08T05:44:42Z</dc:date>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351101#M306142</link>
      <description>&lt;P&gt;Hi all. I'm playing with a cool program called Subsonic - You can stream music from your home server to whatever. The problem I'm having is getting a NAT statement to access the server from inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my current config for the service:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network SubSonic&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.2.32&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,outside) static interface service tcp 4040 4040&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outside_inbound permit tcp any object SubSonic eq 4040&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is working great when I'm out in the world, but when I'm home and connected inside no luck. I'm thinking I need some sort of nat statement for inside to inside, but I'm at a loss really. Any help here would be appricated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ed&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351101#M306142</guid>
      <dc:creator>Ed Willson</dc:creator>
      <dc:date>2019-03-12T03:26:28Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351102#M306144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming your stream server is sitting behind the inside interface and you want to stream music to a host which is sitting behind the inside interface as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More info would be useful like a topology visio.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 you need to enable communication between hosts connected to the same interface&lt;/P&gt;&lt;P&gt;2 if your pc and stream server are behind different interfaces then the interfaces should have the same security level, and you should enable communication between interfaces with same security level. Or create an ACL with the right permit statement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 03:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351102#M306144</guid>
      <dc:creator>Istvan kelemen</dc:creator>
      <dc:date>2014-01-08T03:31:04Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351103#M306146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both devices (Server and AP) are connected to the inside vlan with the ASA doing DHCP. Communication is fine on the LAN side. I can change the server address on my phone to the inside address for the server and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog is showing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jan 07 2014&lt;/TD&gt;&lt;TD&gt;19:36:10&lt;/TD&gt;&lt;TD&gt;110002&lt;/TD&gt;&lt;TD&gt;192.168.2.232&lt;/TD&gt;&lt;TD&gt;33871&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;Failed to locate egress interface for TCP from inside:192.168.2.232/33871 to &lt;EM&gt;OU.TS.ID.E&lt;/EM&gt;/4040&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 03:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351103#M306146</guid>
      <dc:creator>Ed Willson</dc:creator>
      <dc:date>2014-01-08T03:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351104#M306148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you want to access the stream server via outside ip when you are connected to inside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 03:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351104#M306148</guid>
      <dc:creator>Istvan kelemen</dc:creator>
      <dc:date>2014-01-08T03:46:42Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351105#M306149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly - so a mobile device can be mobile without having to change configuration. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 03:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351105#M306149</guid>
      <dc:creator>Ed Willson</dc:creator>
      <dc:date>2014-01-08T03:54:53Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351106#M306150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you access the device with a PC so we can run a sniffer trace on the PC when it works and compare what port and protocol is used. It would be also a good idea to check logs and captures that can be runned on the ASA when you setup the server behind the ASA with NAT, that way we can check when your phone is trying to connect to the server with the phones source address through logs and captures.&lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 04:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351106#M306150</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2014-01-08T04:18:27Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351107#M306152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Well I can tell you its on TCP 4040. When I access on the lan I'm just using &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://192.168.2.238:4040"&gt;http://192.168.2.238:4040&lt;/A&gt;&lt;SPAN&gt;. Nothing special there. Looking at the syslog from my traffic headed to the public address it's getting NATted. That's why I'm thinking I need to hairpin the traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP 4040 from 192.168.2.0/24 headed to &lt;EM&gt;myoutsideIP &lt;/EM&gt;needs to be redirected to 192.168.2.238:4040.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 04:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351107#M306152</guid>
      <dc:creator>Ed Willson</dc:creator>
      <dc:date>2014-01-08T04:29:01Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351108#M306154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All you need to do is configure an object for the external IP address that you have on the ASA and then configure the U turn:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you think that is the case configure the next:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network External_IP&lt;/P&gt;&lt;P&gt; host &lt;SPAN style="font-size: 10pt;"&gt;External_IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,inside) source dynamic any interface destination static &lt;SPAN style="font-size: 10pt;"&gt;External_IP &lt;STRONG style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;SubSonic&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 04:36:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351108#M306154</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2014-01-08T04:36:08Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351109#M306156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You Sir! I was damn close a couple times, but was getting messed up on the nat statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The commands I used:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network SubSonicLAN&lt;/P&gt;&lt;P&gt; host &lt;EM&gt;OUTSIDEIP&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;nat (inside,inside) source dynamic any interface destination static SubSonicLAN SubSonic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That made my night. I was messing with this for hours!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 04:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351109#M306156</guid>
      <dc:creator>Ed Willson</dc:creator>
      <dc:date>2014-01-08T04:57:37Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351110#M306157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;happy to help!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 05:44:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-nat-problem/m-p/2351110#M306157</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2014-01-08T05:44:42Z</dc:date>
    </item>
  </channel>
</rss>

