<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone-Base-Firewall NAT issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-base-firewall-nat-issue/m-p/2163138#M356591</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone able to help with is?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Feb 2013 11:40:35 GMT</pubDate>
    <dc:creator>irvine_iain</dc:creator>
    <dc:date>2013-02-18T11:40:35Z</dc:date>
    <item>
      <title>Zone-Base-Firewall NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/zone-base-firewall-nat-issue/m-p/2163137#M356590</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having a big issue with Nat on my 3925 router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I have 4 interfaces (Internetl, LAN, DMZ &amp;amp; Wifi (which is isolated except for a vew exceptions) on my router which is setup using zone pairs:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Internet -&amp;gt; LAN, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Internet -&amp;gt; DMZ,&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Internet -&amp;gt; Wi-Fi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;LAN -&amp;gt; Internet, LAN -&amp;gt; DMZ, LAN-&amp;gt; Wi-Fi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;DMZ -&amp;gt; Internet,&amp;nbsp; DMZ -&amp;gt; LAN, DMZ -&amp;gt; Wi-Fi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Wi-Fi -&amp;gt; Internet, Wi-Fi -&amp;gt; LAN, Wi-Fi -&amp;gt; DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;NAT is setup to translate some external IP address to internal IP address both in our LAN and DMZ, basically the image below&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/8/6/128685-NAT-issue.jpg" alt="NAT-issue.jpg" class="jive-image-thumbnail jive-image" onclick="" style="font-size: 10pt;" width="450" /&gt;&lt;/P&gt;&lt;P&gt;and all seem to work however when&lt;SPAN style="font-size: 10pt;"&gt; the issue arise when I use a laptop/device in the Wi-Fi network to access a server in the LAN or DMZ by accessing it external IP address, ie Wifi Laptop IP 172.16.10.10 trying to access 150.148.130.52. The device is unable to access but if an external user trys to access 150.148.130.52 they are able to.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I think the issue is maybe due to the NAT/ZBFW rules maybe trying to access across the Wi-Fi -&amp;gt; DMZ zone pair rules instead of going Wi-Fi -&amp;gt; Internet, then Internet -&amp;gt; DMZ and back. but it just seem to trop the traffic?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Has anyone come accross this issue before? Im sure you most be able to do this as people access there webmail fine on internal and external networks with out the need for DNS translations.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can any one help?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-base-firewall-nat-issue/m-p/2163137#M356590</guid>
      <dc:creator>irvine_iain</dc:creator>
      <dc:date>2019-03-12T01:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Zone-Base-Firewall NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/zone-base-firewall-nat-issue/m-p/2163138#M356591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone able to help with is?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 11:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-base-firewall-nat-issue/m-p/2163138#M356591</guid>
      <dc:creator>irvine_iain</dc:creator>
      <dc:date>2013-02-18T11:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Zone-Base-Firewall NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/zone-base-firewall-nat-issue/m-p/2163139#M356592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please post your config, or at least:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run | sec zone&lt;/P&gt;&lt;P&gt;show run | sec policy-map&lt;/P&gt;&lt;P&gt;show run | sec ip nat&lt;/P&gt;&lt;P&gt;show ip nat translations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i suspect it is NAT issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mashal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 18:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-base-firewall-nat-issue/m-p/2163139#M356592</guid>
      <dc:creator>malshbou</dc:creator>
      <dc:date>2013-02-18T18:24:14Z</dc:date>
    </item>
  </channel>
</rss>

