<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 8.4 static NAT issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185505#M356916</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you do &lt;STRONG&gt;show access-list OUTSIDE-IN&lt;/STRONG&gt; do you see the rules incrementing the hit count?&lt;/P&gt;&lt;P&gt;If you do &lt;STRONG&gt;show arp&lt;/STRONG&gt; from the 887 router do you see an IP and MAC address resolved in the table for the IP in question?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Feb 2013 15:08:55 GMT</pubDate>
    <dc:creator>jj27</dc:creator>
    <dc:date>2013-02-08T15:08:55Z</dc:date>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185504#M356913</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a small lab setup with the ASA connecting to an 887 router (for internet) and a 3550 switch for LAN. I am also trying to setup two routers in the internal network that need to be accessed from the internet for DMVPN. Both routers can access the internet, however as soon as I apply the static NAT statements on the ASA neither can access the internet or can be accessed from the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For testing purposes I have only permitted ICMP and the port numbers for the DMVPN traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT statements:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network dmvpn-hub1&lt;/P&gt;&lt;P&gt; host 192.168.50.5&lt;/P&gt;&lt;P&gt; nat (inside,outside) static x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit gre any object dmvpn-hub1&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit esp any object dmvpn-hub1&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit udp any object dmvpn-hub1 eq isakmp&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit icmp any object dmvpn-hub1&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit udp any object dmvpn-hub1 eq 4500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am curious as to why it causes this issue. Any help would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185504#M356913</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2019-03-12T00:58:03Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185505#M356916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you do &lt;STRONG&gt;show access-list OUTSIDE-IN&lt;/STRONG&gt; do you see the rules incrementing the hit count?&lt;/P&gt;&lt;P&gt;If you do &lt;STRONG&gt;show arp&lt;/STRONG&gt; from the 887 router do you see an IP and MAC address resolved in the table for the IP in question?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 15:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185505#M356916</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2013-02-08T15:08:55Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185506#M356917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The answer is no to both of those questions. The funny thing is when I do a packet-tracer it shows it as passing&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 15:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185506#M356917</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-02-08T15:11:11Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185507#M356918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well if the answer is no to those questions, then there is an issue between the 887 and the ASA.&amp;nbsp;&amp;nbsp; Is it an issue with attempting to use a static IP that is not assigned to your internet line?&amp;nbsp; Doing a packet tracer from the inside to the outside will always work because its simply doing a logical test of the firewall rules and NAT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 15:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185507#M356918</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2013-02-08T15:14:27Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185508#M356919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, I have a public block of IPs. I did see other posts where others had similar issues to mine. Thought it might have been something I missed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 15:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185508#M356919</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-02-08T15:16:24Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185509#M356920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well what you're trying to do is very basic.&amp;nbsp; Is this the first NAT protected device you're attempting to allow connectivity to? It's a stupid question, but is the command &lt;STRONG&gt;access-group OUTSIDE-IN in interface outside&lt;/STRONG&gt; applied?&amp;nbsp; Also, if the public IP block assigned differs from the LAN block on the 887 router you may need to add an IP route for the IP block to the outside interface of the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 15:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185509#M356920</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2013-02-08T15:19:43Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185510#M356921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, indeed it is basic. The ACL is applied and the public block is the same subnet. Also, there is no ACL on the 887 router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 15:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185510#M356921</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-02-08T15:24:50Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185511#M356922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any chance you could share the rest of the ASA configurations (And perhaps even the router too). If need be partially remove public IP addresses and any other sensitive information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 15:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185511#M356922</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-08T15:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.4 static NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185512#M356923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies on this. It turns out that proxy arp was required. Command below:&lt;BR /&gt;&lt;BR /&gt;No sysopt noproxyarp&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Feb 2013 10:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-static-nat-issue/m-p/2185512#M356923</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-02-09T10:40:34Z</dc:date>
    </item>
  </channel>
</rss>

