<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: portmap translation creation failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090839#M392108</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you still getting the error message, or the error message has disappeared now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are you actually having any problem from those host in the error message?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you run packet tracer for the same source and destination as the error message, does it fail or pass? if it fails, can you pls post the output of the packet tracer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Jan 2013 03:14:13 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2013-01-31T03:14:13Z</dc:date>
    <item>
      <title>portmap translation creation failed</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090836#M392094</link>
      <description>&lt;P&gt;After adding a NAT rule on Friday morning, I'm now getting a bunch of "portmap translation creation failed" messages from my ASA 5520.&amp;nbsp; (It's currently running 8.4(3).)&amp;nbsp; The failure errors appear to have nothing to do with the change that was made.&amp;nbsp; Here are the relevant additions to the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Define objects involved&lt;/P&gt;&lt;P&gt;object network BCSNovar&lt;/P&gt;&lt;P&gt;host 172.16.173.191&lt;/P&gt;&lt;P&gt;object network Harris&lt;/P&gt;&lt;P&gt;! public addresses masked to protect the innocent.&lt;/P&gt;&lt;P&gt;range x.x.x.1 x.x.x.254&lt;/P&gt;&lt;P&gt;description Harris Corporation - Novar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Access list to allow the traffic in&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Harris RDP access to BCSNovar server via port 3392&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp object Harris object BCSNovar eq 3392 log alerts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! NAT the inside address to the outside address for the port&lt;/P&gt;&lt;P&gt;object network BCSNovar&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) static interface service tcp 3389 3392&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have very similar rules in place for other vendors to access other machines.&amp;nbsp; The only difference between this new one and those old ones is the use of the objects in the rule instead of the direct IP addresses.&amp;nbsp; This is also the first one that invovles a range instead of a specific address or network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The errors are fairly frequent and usually involved normal web traffic on ports 80/443 or NTP.&amp;nbsp; Here are a few copied from the ASDM interface:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;Jan 28 2013&lt;/TD&gt;&lt;TD&gt;11:26:42&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;72.240.1.140&lt;/TD&gt;&lt;TD&gt;123&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;portmap translation creation failed for udp src Inside:172.16.171.10/65535 dst Outside:72.240.1.140/123&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;Jan 28 2013&lt;/TD&gt;&lt;TD&gt;11:27:44&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;174.132.200.187&lt;/TD&gt;&lt;TD&gt;80&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;portmap translation creation failed for tcp src Inside:172.16.31.119/53767 dst Outside:174.132.200.187/80&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;Jan 28 2013&lt;/TD&gt;&lt;TD&gt;11:29:47&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;74.63.137.149&lt;/TD&gt;&lt;TD&gt;80&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;portmap translation creation failed for tcp src Inside:172.16.30.130/3151 dst Outside:74.63.137.149/80&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea why these are failing.&amp;nbsp; Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090836#M392094</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2019-03-12T00:53:17Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090837#M392099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds to me like there is a co-incidence between the newly configured rules and the error message seen.&lt;/P&gt;&lt;P&gt;Did you perform "clear xlate" after configuring the new rules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the IP Address in the error message as you said, doesn't seem to match the newly configured NAT host, so it might not be related.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without looking at the full configuration, it would be difficult to see what could be the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 01:49:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090837#M392099</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2013-01-29T01:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090838#M392102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did not do a "clear xlate" after configuring the new rules.&amp;nbsp; Should I have?&amp;nbsp; Do you think doing one now would help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached the full config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 15:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090838#M392102</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2013-01-30T15:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090839#M392108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you still getting the error message, or the error message has disappeared now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are you actually having any problem from those host in the error message?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you run packet tracer for the same source and destination as the error message, does it fail or pass? if it fails, can you pls post the output of the packet tracer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 03:14:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090839#M392108</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2013-01-31T03:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090840#M392113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am still getting them.&amp;nbsp; Here are a couple of random failures and the associated packet tracer output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 31 2013 09:32:41: %ASA-3-305006: portmap translation creation failed for udp src Inside:172.16.171.10 (fwdcvod01.buckeyehq.com) /65535 dst Outside:72.240.1.140 (unresolved) /123&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/4/5/127547-packet_trace.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 31 2013 09:44:12: %ASA-3-305006: portmap translation creation failed for tcp src Inside:172.16.30.66 (hpc14520rr.buckeyehq.com) /1242 dst Outside:206.72.206.242 (unresolved) /80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/4/5/127548-packet_trace2.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Both seem to be dropping at the same rule, which is not one that I altered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 14:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090840#M392113</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2013-01-31T14:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090841#M392119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ultimately, it was a 'clear xlate' that fixed the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 11:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed/m-p/2090841#M392119</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2013-10-22T11:24:43Z</dc:date>
    </item>
  </channel>
</rss>

