<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT issue routing internet traffic inside. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-issue-routing-internet-traffic-inside/m-p/2282510#M344813</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically there is no translation found for that traffic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 5 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Aug 2013 03:52:27 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-08-13T03:52:27Z</dc:date>
    <item>
      <title>NAT issue routing internet traffic inside.</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue-routing-internet-traffic-inside/m-p/2282509#M344811</link>
      <description>&lt;P&gt;&lt;STRONG&gt;This issue has been resolved by using Nat (inside) 0 0.0.0.0 0.0.0.0 and removing the static nats. 8/14/2013&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;I have been tasked with sending internet traffic 80,443, &amp;amp; ftp through the inside interface of this firewall. Internet traffic was originally routed through the outside interface as in a normal environment but now it needs to be sent through the inside interface. The route statement is in place and static nat is being used to keep the original address when passing through the inside interface. An ACL is in place to allow the traffic from the lower security to higher. Unfortunately the configuration is not working correctly and I don’t have the opportunity to resolve the issue with trial and error. It is an environment that is run through strict change control so I need to get it right during the short change window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the following message in the log&lt;/P&gt;&lt;P&gt;"PIX-3-305005: No translation group found for tcp src Internal_Servers:10.38.166.76/3088 dst inside:74.125.225.232/80"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By using capture statements I can see the traffic pass through the lower security interface but I never see it make it through the inside interface. The PIX is running 6.3 software so there is no packet tracer to help with trouble shooting any assistance would be greatly appreciated. Please the excerpts from the firewall configuration below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX 525 Info.&lt;/P&gt;&lt;P&gt;Cisco PIX Firewall Version 6.3(3)&lt;/P&gt;&lt;P&gt;ip address outside xxx.136.24.86 255.255.255.240&lt;BR /&gt;ip address inside 10.38.166.1 255.255.255.240&lt;BR /&gt;ip address HANCloud 10.55.3.1 255.255.252.0&lt;BR /&gt;ip address Public_Servers 10.38.166.17 255.255.255.240&lt;BR /&gt;ip address Internal_Servers 10.38.166.68 255.255.255.240&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;global (outside) 5 interface&lt;BR /&gt;global (outside) 100 xxx.136.24.94 netmask 255.255.255.255&lt;BR /&gt;global (HANCloud) 10 10.55.4.50&lt;BR /&gt;nat (inside) 10 10.38.57.27 255.255.255.255 0 0&lt;BR /&gt;nat (inside) 10 10.38.68.106 255.255.255.255 0 0&lt;BR /&gt;nat (inside) 10 10.38.68.196 255.255.255.255 0 0&lt;BR /&gt;nat (inside) 10 10.38.68.230 255.255.255.255 0 0&lt;BR /&gt;nat (inside) 10 10.38.128.162 255.255.255.255 0 0&lt;BR /&gt;nat (inside) 10 10.38.248.221 255.255.255.255 0 0&lt;BR /&gt;nat (inside) 10 10.38.54.0 255.255.255.0 0 0&lt;BR /&gt;nat (inside) 10 10.38.156.0 255.255.255.0 0 0&lt;BR /&gt;nat (inside) 100 10.38.166.0 255.255.255.0 0 0&lt;BR /&gt;nat (inside) 5 0.0.0.0 0.0.0.0 0 0&lt;BR /&gt;nat (Public_Servers) 5 0.0.0.0 0.0.0.0 0 0&lt;BR /&gt;nat (Internal_Servers) 5 0.0.0.0 0.0.0.0 0 0&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;static (Internal_Servers,inside) 10.38.166.65 10.38.166.65 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.66 10.38.166.66 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.67 10.38.166.67 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (Internal_Servers,inside) 10.38.166.68 10.38.166.68 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.69 10.38.166.69 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.70 10.38.166.70 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.71 10.38.166.71 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.72 10.38.166.72 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.73 10.38.166.73 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.74 10.38.166.74 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.75 10.38.166.75 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.76 10.38.166.76 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.77 10.38.166.77 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.78 10.38.166.78 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (Internal_Servers,inside) 10.38.166.79 10.38.166.79 netmask 255.255.255.255 0 0 &lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;object-group service Internet_Services tcp&lt;BR /&gt;&amp;nbsp; description Services for Internet Access&lt;BR /&gt;&amp;nbsp; port-object eq www&lt;BR /&gt;&amp;nbsp; port-object eq https&lt;BR /&gt;&amp;nbsp; port-object eq ftp&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;access-list IntServ_to_Inside permit tcp 10.38.166.64 255.255.255.240 any object-group Internet_Services &lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;access-group IntServ_to_Inside in interface Internal_Servers&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;route inside 0.0.0.0 0.0.0.0 10.38.166.4 1&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:24:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue-routing-internet-traffic-inside/m-p/2282509#M344811</guid>
      <dc:creator>Eric Hooten</dc:creator>
      <dc:date>2019-03-12T02:24:52Z</dc:date>
    </item>
    <item>
      <title>NAT issue routing internet traffic inside.</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue-routing-internet-traffic-inside/m-p/2282510#M344813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Eric,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically there is no translation found for that traffic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 5 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 03:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue-routing-internet-traffic-inside/m-p/2282510#M344813</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-13T03:52:27Z</dc:date>
    </item>
  </channel>
</rss>

