<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static policy nat problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076114#M392166</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that rule is bidirectional - you do not need to configure any more nat.&lt;/P&gt;&lt;P&gt;Did you try to capture received traffic ? Maybe on the other site when remote server initiating connection traffic is leaving untranslated or translated to different IP than you expect (obj-s-nat-saffron-server) ?&lt;/P&gt;&lt;P&gt;What do you see in logs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Michal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jan 2013 17:11:56 GMT</pubDate>
    <dc:creator>Michal Garcarz</dc:creator>
    <dc:date>2013-01-25T17:11:56Z</dc:date>
    <item>
      <title>Static policy nat problem</title>
      <link>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076113#M392159</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an issue where I am trying to nat the ip address of a server on my inside network "only" when connecting to a server at the other end of a vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come up with the config below, and this works fine outbound, vpn is up and I can initiate connecections to the remote server and it is natted, and if I connect to a public address it translates to the interface as it should.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However if the remote server tries to connect to the inside server on the nat address, it doesn't work.&amp;nbsp; Now at the moment I'm not sure if its because I've misconfigured my end or the 3rd party has misconfigured their end (I've no access to their config).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should the nat config below translate in both directions?&amp;nbsp; or do I need to do anything else?&amp;nbsp;&amp;nbsp; I'd really appreciate confirmation that the below is correct/incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA 5520 Software Version 8.4(4)1&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;inside server:- 192.168.3.81&lt;/P&gt;&lt;P&gt;inside server nat:- 172.20.0.1&lt;/P&gt;&lt;P&gt;remote server:- 10.149.1.31&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-sql06&lt;/P&gt;&lt;P&gt; host 192.168.3.81&lt;/P&gt;&lt;P&gt; description server on insde network&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-s-nat-source-address-for-sql06-to-saffron-server&lt;/P&gt;&lt;P&gt; host 172.20.0.1&lt;/P&gt;&lt;P&gt; description nat address used when connecting to remote Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-s-nat-saffron-server&lt;/P&gt;&lt;P&gt; host 10.149.1.31&lt;/P&gt;&lt;P&gt; description remote server address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static obj-sql06 obj-s-nat-source-address-for-sql06-to-saffron-server destination static obj-s-nat-saffron-server obj-s-nat-saffron-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076113#M392159</guid>
      <dc:creator>the-kamikaze</dc:creator>
      <dc:date>2019-03-12T00:52:28Z</dc:date>
    </item>
    <item>
      <title>Static policy nat problem</title>
      <link>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076114#M392166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that rule is bidirectional - you do not need to configure any more nat.&lt;/P&gt;&lt;P&gt;Did you try to capture received traffic ? Maybe on the other site when remote server initiating connection traffic is leaving untranslated or translated to different IP than you expect (obj-s-nat-saffron-server) ?&lt;/P&gt;&lt;P&gt;What do you see in logs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Michal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jan 2013 17:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076114#M392166</guid>
      <dc:creator>Michal Garcarz</dc:creator>
      <dc:date>2013-01-25T17:11:56Z</dc:date>
    </item>
    <item>
      <title>Static policy nat problem</title>
      <link>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076115#M392171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that, I'll have to do some more investigtation.&amp;nbsp;&amp;nbsp; They aren't doing any nat translation at their end (I hope) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bloke at the other end had to dash off, so we are going to do some more testing monday, I was just worried it was the nat at my end, but if its bidirectional then it shouldn't be, so that sets my mind at rest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully they've just got a rule wrong somewhere, and will be easily fixed, routing should be ok as i get replies when I ping the saffron server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I shall let you know how I get on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jan 2013 17:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076115#M392171</guid>
      <dc:creator>the-kamikaze</dc:creator>
      <dc:date>2013-01-25T17:18:17Z</dc:date>
    </item>
    <item>
      <title>Static policy nat problem</title>
      <link>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076116#M392174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it working.&amp;nbsp;&amp;nbsp; Not quite sure why it wasn't in the first place but removeing the nat config and reinstating it fixed it.&amp;nbsp; The bloke at the other end swears he never changed anything as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 16:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-policy-nat-problem/m-p/2076116#M392174</guid>
      <dc:creator>the-kamikaze</dc:creator>
      <dc:date>2013-01-29T16:48:32Z</dc:date>
    </item>
  </channel>
</rss>

