<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Outside NAT not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405285#M307932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that the traceroute in the original post is done towards IP address 10.5.20.103 and the other &lt;STRONG&gt;"object"&lt;/STRONG&gt; is named so that it suggests that its the &lt;STRONG&gt;"object"&lt;/STRONG&gt; for the original IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding seeing the same IP address on each hop is related to the NAT configuration and the user might be missing ICMP Inspection (error) that would help with the hops between the source host and the actual traced destination host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though the original poster needs to clarify if there is some doubt to which of the destination IP addresses is the actual NAT IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Dec 2013 11:02:08 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-12-03T11:02:08Z</dc:date>
    <item>
      <title>Outside NAT not working</title>
      <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405282#M307925</link>
      <description>&lt;P&gt;I have a server at 10.1.1.51 that is translated to 75.141.84.6 for all outbound connections. For connections to 10.5.20.103 the destination needs to be translated to 10.0.0.103.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network PerrySrv-0-103&lt;/P&gt;&lt;P&gt; host 10.5.20.103&lt;/P&gt;&lt;P&gt;object network Perry-srv-orig-103&lt;/P&gt;&lt;P&gt; host 10.0.0.103&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network Orion-srv-ext&lt;/P&gt;&lt;P&gt; host 75.141.84.6&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt;object network Orion-srv&lt;/P&gt;&lt;P&gt; host 10.1.1.51&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (ITS_inside,ITS-outside) source static Orion-srv Orion-srv-ext destination static PerrySrv-0-103 Perry-srv-orig-103 no-proxy-arp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a traceroute to the 10.0.0.103 from 10.1.1.51 the results are this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tracing route to 10.5.20.103 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp; 10.1.1.153&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp; 10.1.1.205&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp; 10.5.20.103&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp; 10.5.20.103&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp; 10.5.20.103&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 ms&amp;nbsp; 10.5.20.103&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trace complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also RDP's to 10.0.0.103 do not work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405282#M307925</guid>
      <dc:creator>jtowry</dc:creator>
      <dc:date>2019-03-12T03:11:47Z</dc:date>
    </item>
    <item>
      <title>Outside NAT not working</title>
      <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405283#M307928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check if you have the ICMP Inspection enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The old commands you can use on the CLI directly to enable them are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;fixup protocol icmp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;fixup protocol icmp error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also go under your default &lt;STRONG&gt;"policy-map"&lt;/STRONG&gt; configuration and add the following that will achieve the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;inspect icmp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;inspect icmp error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, can you provide us with a &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; output of that traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input ITS_inside tcp 10.1.1.51 12345 10.5.20.103 3389&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 07:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405283#M307928</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-03T07:32:56Z</dc:date>
    </item>
    <item>
      <title>Outside NAT not working</title>
      <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405284#M307930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The format of the twice NAT is as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (real_int,map_int) source static &lt;REAL_OBJ&gt; &lt;MAP_OBJ&gt; destination static &lt;MAP_OBJ&gt; &lt;REAL_OBJ&gt;&lt;/REAL_OBJ&gt;&lt;/MAP_OBJ&gt;&lt;/MAP_OBJ&gt;&lt;/REAL_OBJ&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so from your nat command output above you have the destination objects swapped around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please amend the configuration to the following and test:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (ITS_inside,ITS-outside) source static Orion-srv Orion-srv-ext&amp;nbsp; destination static Perry-srv-orig-103 PerrySrv-0-103 no-proxy-arp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 10:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405284#M307930</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-12-03T10:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Outside NAT not working</title>
      <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405285#M307932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that the traceroute in the original post is done towards IP address 10.5.20.103 and the other &lt;STRONG&gt;"object"&lt;/STRONG&gt; is named so that it suggests that its the &lt;STRONG&gt;"object"&lt;/STRONG&gt; for the original IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding seeing the same IP address on each hop is related to the NAT configuration and the user might be missing ICMP Inspection (error) that would help with the hops between the source host and the actual traced destination host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though the original poster needs to clarify if there is some doubt to which of the destination IP addresses is the actual NAT IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 11:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405285#M307932</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-03T11:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: Outside NAT not working</title>
      <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405286#M307934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I have changed the host I was trying to connect to 10.5.20.194. I can connect via RDP to the server 10.5.20.194 ok now. Why do the tracert replies all show 10.5.20.194 as the address for the hops past the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network Orion-srv&lt;/P&gt;&lt;P&gt; host 10.1.1.51&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network Orion-srv-ext&lt;/P&gt;&lt;P&gt; host 75.141.84.6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network PerryCo-194&lt;/P&gt;&lt;P&gt; host 10.5.20.194&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network PerryCo-194-ext&lt;/P&gt;&lt;P&gt; host 10.0.0.194&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (ITS_inside,ITS-outside) source static Orion-srv Orion-srv-ext destination static PerryCo-194 PerryCo-194-ext no-proxy-arp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS&amp;gt; tracert -d 10.5.20.194&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tracing route to 10.5.20.194 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp; 10.1.1.153&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp; 10.1.1.205&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp; 10.5.20.194&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp; 10.5.20.194&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp; 10.5.20.194&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 ms&amp;nbsp; 10.5.20.194&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RSA-DC-ASA-A/ITS# packet-tracer input ITS_inside tcp 10.1.1.51 12345 10.5.20.194&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (ITS_inside,ITS-outside) source static Orion-srv Orion-srv-ext destination static PerryCo-194 PerryCo-194-ext no-proxy-arp&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface ITS-outside&lt;/P&gt;&lt;P&gt;Untranslate 10.5.20.194/3389 to 10.0.0.194/3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group ITS-inside in interface ITS_inside&lt;/P&gt;&lt;P&gt;access-list ITS-inside extended permit ip any4 any4&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (ITS_inside,ITS-outside) source static Orion-srv Orion-srv-ext destination static PerryCo-194 PerryCo-194-ext no-proxy-arp&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 10.1.1.51/12345 to 75.141.84.6/12345&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FOVER&lt;/P&gt;&lt;P&gt;Subtype: standby-update&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (ITS_inside,ITS-outside) source static Orion-srv Orion-srv-ext destination static PerryCo-194 PerryCo-194-ext no-proxy-arp&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 9&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 10&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 9663156, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: ITS_inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: ITS-outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh local-host 10.1.1.51&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ICMP ITS-outside 10.5.20.194(10.0.0.194):0 ITS_inside&amp;nbsp; 10.1.1.51:11, idle 0:00:00, bytes 192, flags&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 15:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405286#M307934</guid>
      <dc:creator>jtowry</dc:creator>
      <dc:date>2013-12-03T15:21:46Z</dc:date>
    </item>
    <item>
      <title>Outside NAT not working</title>
      <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405287#M307936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you add this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;inspect icmp error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It might be something related to the fact that the replys are coming from router hops between your ASA and the actual destination host since it will be the router in between that is sending the ICMP Error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the ICMP Error message Inspection might be needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 15:31:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405287#M307936</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-03T15:31:21Z</dc:date>
    </item>
    <item>
      <title>Outside NAT not working</title>
      <link>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405288#M307938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, the traceroutes are showing the right information now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 15:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outside-nat-not-working/m-p/2405288#M307938</guid>
      <dc:creator>jtowry</dc:creator>
      <dc:date>2013-12-03T15:45:24Z</dc:date>
    </item>
  </channel>
</rss>

