<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5510 rpf-check drop when translating IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385556#M308657</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is the point, it is already created, the issue is that you were running the packet tracer incorrectly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want we can talk over skype: juanmh84 that is my ID, or when I get to work you can call my number, I get in around 40 min&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Nov 2013 16:18:31 GMT</pubDate>
    <dc:creator>jumora</dc:creator>
    <dc:date>2013-11-21T16:18:31Z</dc:date>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385545#M308640</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently having an ASA setup as a NAT to translate outside IPs to our internal LAN IPs which is all working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However our city council has a printer which sends a job through to an IP address which can no longer be accessed due to the NAT (10.100.1.20) so we need to translate that IP from 10.100 to our internal LAN IP of 172.29.8.20 however we keep getting an error message on the packet test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rpf check dropped acl-drop flow is denied by configured rule vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't currently have access to the ASA to be able to get a show run but i was reading another question on this site and was wondering if it was relevant to my problem &lt;A _jive_internal="true" href="https://community.cisco.com/thread/1003401" target="_blank"&gt;https://supportforums.cisco.com/thread/1003401&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The solution being given by Sankar "&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I believe you need the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;access-list inside_nat0_outbound line 1 deny ip &lt;/STRONG&gt;host 172.26.48.3 host 10.24.14.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Either the above or the host on the outside should talk to the inside host using its private address (172.26.48.3) and not the translated address.&lt;/P&gt;&lt;P&gt; "&lt;/P&gt;&lt;P&gt;MAny thanks for any help.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385545#M308640</guid>
      <dc:creator>Jamie Joh</dc:creator>
      <dc:date>2019-03-12T03:06:47Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385546#M308642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not getting it, maybe you can explain a little better with topology map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If what you have is an outside NAT or PAT then you need to configure a NAT exemption or static policy NAT so that you can map this address with two global address (private IP and global IP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need more detail.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 23:06:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385546#M308642</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-19T23:06:25Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385547#M308644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies if it wasn't very well explained.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are a school that is on a city council network and recently changed providers, however our current internal IP scope clashed with another school so we had to have the ASA installed to work as a NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our admin team use a system where they login to a virtual desktop which used to send a print to the IP of 172.29.8.20 which went directly to our printer however due to moving providers the printer now sends to the IP of 10.100.1.20, the ASA is blocking this coming through (We've tested without the ASA) so we need it to translate that 10.100 IP and give it a route to 172.29 however on the packet trace we are getting the &lt;/P&gt;&lt;P&gt;rpf check dropped acl-drop flow is denied by configured rule vpn on the outside test and an rpf-violation - reverse route verification failed on an inside test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully that explains it better.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 12:05:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385547#M308644</guid>
      <dc:creator>Jamie Joh</dc:creator>
      <dc:date>2013-11-21T12:05:57Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385548#M308647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the packet tracer or run it through CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 14:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385548#M308647</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-21T14:05:51Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385549#M308649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the packet trace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TSTC-FW(config)# packet-tracer input outside tcp 10.100.104.20 9100 172.29.8.2$&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 172.29.8.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.248.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.100.104.0&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.248.0&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 172.29.8.20 eq 9100&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Form Pearson Exam Software&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network TSTC-Printing&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 10.100.104.20 service tcp 9100 9100&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 14:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385549#M308649</guid>
      <dc:creator>Jamie Joh</dc:creator>
      <dc:date>2013-11-21T14:15:32Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385550#M308651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;object network TSTC-Printing&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;nat (inside,outside) static 10.100.104.20 service tcp 9100 9100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet tracer indicated that you are coming from 10.100.104.20 to 172.29.8.20 9100 but it seems that you mapped it on the ASA to object &lt;SPAN style="font-size: 10pt;"&gt;TSTC-Printing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Question here is, are you running the packet tracer correctly or should that NAT not be in place.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Baed on your notes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our admin team use a system where they login to a virtual desktop which used to send a print to the IP of 172.29.8.20 which went directly to our printer however due to moving providers the printer now sends to the IP of 10.100.1.20, the ASA is blocking this coming through (We've tested without the ASA) so we need it to translate that 10.100 IP and give it a route to 172.29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will explain what you are posting on the packet tracer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 10.100.104.20 9100 172.29.8.20 9100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your an IP that resides on the outside that is 10.100.104.20 and you want to connect to 172.29.8.20 on TCP port 9100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it is incorrect but you tell me, are connections really coming into the ASA from 10.100.104.20 to 172.29.8.20????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 14:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385550#M308651</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-21T14:26:01Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385551#M308652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately that NAT was setup by the people who installed the ASA so im not 100% sure on it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically that printer on the virtual desktop prints to the ip of 100.100.104.20 which is one of the assigned IPs given to our ASA (i believe we have 104.1-104.20). I need the ASA to translate that request to a printer that has an internal IP on our network of 172.29.8.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 14:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385551#M308652</guid>
      <dc:creator>Jamie Joh</dc:creator>
      <dc:date>2013-11-21T14:30:21Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385552#M308653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then it seems that you are running the packet tracer incorrectly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try for example any other IP that is not the 10.100.104.20 as source, example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 10.100.104.10 9100 172.29.8.20 9100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know the result and post please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 14:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385552#M308653</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-21T14:39:31Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385553#M308654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just tried with a different IP with the 172.29 being the destination and it came up with the same error. Is the NAT possibly set up incorrectly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 15:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385553#M308654</guid>
      <dc:creator>Jamie Joh</dc:creator>
      <dc:date>2013-11-21T15:00:39Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385554#M308655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry my bad, it´s like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 10.100.104.10 9100 10.100.104.20&lt;SPAN style="font-size: 10pt;"&gt; 9100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 15:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385554#M308655</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-21T15:33:29Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385555#M308656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That trace worked fine, i only have access to the ASDM at the moment so can't copy the log but it passed the RPF and also another set of ip options look up and flow creation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how would i go about creating a NAT so that the print job sent to 10.100.104.20 gets forwarded onto 172.29.8.20? These are print jobs on port 9100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 16:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385555#M308656</guid>
      <dc:creator>Jamie Joh</dc:creator>
      <dc:date>2013-11-21T16:06:10Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385556#M308657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is the point, it is already created, the issue is that you were running the packet tracer incorrectly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want we can talk over skype: juanmh84 that is my ID, or when I get to work you can call my number, I get in around 40 min&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 16:18:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385556#M308657</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-21T16:18:31Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385557#M308660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After talking this over, it seems that your PCs are local to the printer but the login page point to the translated IP of 10.100.104.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; TSTC-Printing_internal&lt;/P&gt;&lt;P&gt; host 172.29.8.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TSTC-Printing_NAT_IP&lt;/P&gt;&lt;P&gt;host 10.100.104.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,inside) source dynamic any interface destination static TSTC-Printing_NAT_IP TSTC-Printing_internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need anything else please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 13:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385557#M308660</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-25T13:32:02Z</dc:date>
    </item>
    <item>
      <title>ASA5510 rpf-check drop when translating IP</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385558#M308663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the traffic is coming from the outside you can configure the same line just define outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside,inside) 1 source dynamic any interface destination static TSTC-Printing_NAT_IP TSTC-Printing_internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 14:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-rpf-check-drop-when-translating-ip/m-p/2385558#M308663</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-25T14:49:50Z</dc:date>
    </item>
  </channel>
</rss>

