<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 NAT help/routing issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386415#M310005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JouniForss,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You just forgot to add the same-security-traffic permit intra-interface command to allow the U turn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 03 Nov 2013 03:02:57 GMT</pubDate>
    <dc:creator>jumora</dc:creator>
    <dc:date>2013-11-03T03:02:57Z</dc:date>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386410#M309997</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a small issue with a small network.&amp;nbsp; I have two servers and a LAN behind a 5505 in one vlan.&amp;nbsp; The servers are natted/port forwarded out using the outside interface's public addressing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One server for ssh&lt;/P&gt;&lt;P&gt;One server for http(s)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's say the servers are 192.168.1.20 and 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.21 is the web server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The LAN uses public dns provided by the ISP.&amp;nbsp; DHCP range is 192.168.1.50-100 and provided by the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the LAN, it cannot route to the webserver due to only having the one inside vlan and one outside vlan.&amp;nbsp; I cannot break the servers off to another vlan due to issues with an outside consultant.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when trying to hit the url of our website, it attempts to hit the outside interface ip of the ASA and cannot due to only having the singular default route out.&amp;nbsp; Is there a way to nat this or route it so that the internal clients can hit the outside interface and see the website without using the internal IP of the webserver?&amp;nbsp; I can provide some config if needed.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386410#M309997</guid>
      <dc:creator>Chad Ciszewski</dc:creator>
      <dc:date>2019-03-12T02:58:13Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386411#M309998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you want the users to be able to connect to the public IP address specifically from the LAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you tell us the software level of your ASA and perhaps share the current NAT configuration with the following commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Software level 8.2 or below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run global&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run nat&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run static&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Software level 8.3 or above&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run nat&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 19:03:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386411#M309998</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-30T19:03:12Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386412#M310000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running 9.1(1) software&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the result of sh run nat for the affected server &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh run nat"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static local_nets local_nat_pool destination static monitoring_network monitoring_network&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network webserverhttp&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp www www &lt;/P&gt;&lt;P&gt;object network webserverhttps&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp https https &lt;/P&gt;&lt;P&gt;object network webservervsftp&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp ftp ftp &lt;/P&gt;&lt;P&gt;object network Infotechssh&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp ssh ssh &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 19:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386412#M310000</guid>
      <dc:creator>Chad Ciszewski</dc:creator>
      <dc:date>2013-10-30T19:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386413#M310003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could try the following configurations. Insert the public IP address to the below configurations that matches your current &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface public IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; subnet 192.168.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network SERVER-SSH&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.20&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network SERVER-WEB&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.21&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network SERVER-PUBLIC&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host &lt;PUBLIC ip=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service WWW&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp destination eq 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service HTTPS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp destination eq 443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service SSH&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp destination eq 22&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,inside) after-auto source dynamic LAN interface destination static SERVER-PUBLIC SERVER-SSH service SSH SSH&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,inside) after-auto source dynamic LAN interface destination static SERVER-PUBLIC SERVER-WEB service WWW WWW&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,inside) after-auto source dynamic LAN interface destination static SERVER-PUBLIC SERVER-WEB service HTTPS HTTPS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should essentially do so that when connections are coming from the network &lt;STRONG&gt;LAN&lt;/STRONG&gt; towards the &lt;STRONG&gt;SERVER-PUBLIC&lt;/STRONG&gt; with the services &lt;STRONG&gt;SSH, WWW&lt;/STRONG&gt; or &lt;STRONG&gt;HTTPS&lt;/STRONG&gt; then the connections will actually be forwarded to the local &lt;STRONG&gt;SERVER-SSH&lt;/STRONG&gt; or &lt;STRONG&gt;SERVER-WEB&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the LAN users address will be mapped to the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface IP address (with the &lt;STRONG&gt;"source dynamic LAN interface"&lt;/STRONG&gt; configuration) so that the servers actually think the connections are coming from the ASA IP. This is essential in this configuration as otherwise the traffic flow wont be correct for the ASA. What I mean is that the ASA would not see the whole "conversation" between the host and server without this type of NAT configuration and would block the connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this works for you &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do remember to mark a reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to ask more if needed though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 19:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386413#M310003</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-30T19:20:21Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386414#M310004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were you able to test this out yet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 08:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386414#M310004</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-31T08:59:51Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386415#M310005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JouniForss,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You just forgot to add the same-security-traffic permit intra-interface command to allow the U turn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Nov 2013 03:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386415#M310005</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-03T03:02:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386416#M310006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;jumora - &lt;/P&gt;&lt;P&gt;Can you provide what the full statement should be?&amp;nbsp; Following JouniForss it looked like packets would be allowed but then the same issue occurred.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 17:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386416#M310006</guid>
      <dc:creator>Chad Ciszewski</dc:creator>
      <dc:date>2013-11-08T17:03:13Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386417#M310007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the command mentioned by Jumora was missing from my examples&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise the configurations I mentioned regarding &lt;STRONG&gt;"nat"&lt;/STRONG&gt; should work unless other NAT configurations prevent that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could use &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; to test the configurations. For example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input inside tcp 192.168.1.100 12345 &lt;PUBLIC ip=""&gt; 80&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output should tell us what happens regarding the configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 17:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386417#M310007</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-08T17:07:13Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386418#M310008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni - &lt;/P&gt;&lt;P&gt;Still getting an error for routing with no route to host.&amp;nbsp; Routes are as follow - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh route"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is PUB GATEWAY to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 is directly connected, inside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; PUB NETWORK 255.255.255.0 is directly connected, outside&lt;BR /&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [10/0] via PUB GATEWAY, outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 17:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386418#M310008</guid>
      <dc:creator>Chad Ciszewski</dc:creator>
      <dc:date>2013-11-08T17:28:15Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 NAT help/routing issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386419#M310009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the output of the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; anyway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you also post the current &lt;STRONG&gt;"nat"&lt;/STRONG&gt; configuration with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run nat&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 17:30:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-help-routing-issue/m-p/2386419#M310009</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-08T17:30:44Z</dc:date>
    </item>
  </channel>
</rss>

