<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Problems in 8.3 when untranslating NATs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119322#M392831</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for you reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the command in questions and it passed all phases however at the end it provide the following reason for dropping packet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (sp-security-failed) Slowpath security checks failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jan 2013 16:42:41 GMT</pubDate>
    <dc:creator>Mohamed Hamid</dc:creator>
    <dc:date>2013-01-15T16:42:41Z</dc:date>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119320#M392817</link>
      <description>&lt;P&gt;Hi Guys &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following problem &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Background: Upgrated from 8.2 Cisco ASA 5520 to 8.3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have drawn a diagram similar to the below that shows a similar network. I have a server that requires access on a number interfaces on the ASA, in 8.2 I have a number of NAT rules set as the following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/8/1/1/125118-photo%20%281%29.jpg" alt="photo (1).jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NAT in 8.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (il2AHdata,dmzAHdata) 192.168.9.40 10.0.0.40 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (il2AHdata,dmzAHmgmt) 10.1.2.40 10.0.0.40 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (il2AHdata,il2AHmgmt) 10.1.1.40 10.0.0.40 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (il2AHdata,gitHubData) 10.0.2.40 10.0.0.40 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (il2AHdata,gitHubmgmt) 10.1.5.40 10.0.0.40 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the upgrade, it seems the upgrade script has created many objects, although NATing on the interfaces seem to work, it is when inbound traffic coming back that the ASA does not seem to successully travese. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The followng is what has been created in 8.3 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network monitoringsystem-01&lt;/P&gt;&lt;P&gt; nat (il2AHdata,dmzAHmgmt) static 10.1.2.40&lt;/P&gt;&lt;P&gt;object network monitoringsystem-02&lt;/P&gt;&lt;P&gt; nat (il2AHdata,il2AHmgmt) static 10.1.1.40&lt;/P&gt;&lt;P&gt;object network monitoringsystem-03&lt;/P&gt;&lt;P&gt; nat (il2AHdata,gitHubmgmt) static 10.1.5.40&lt;/P&gt;&lt;P&gt;object network monitoringsystem-04&lt;/P&gt;&lt;P&gt; nat (il2AHdata,gitHubData) static 10.0.2.40&lt;/P&gt;&lt;P&gt;object network monitoringsystem&lt;/P&gt;&lt;P&gt; nat (il2AHdata,dmzAHdata) static 192.168.9.40&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the following in my logs and it does not report any blocks on ACL, it seems to be able to NAT out but has issues for incoming&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;|Jan 15 2013|15:38:13|302021|10.1.4.26|0|10.0.0.40|27649|Teardown ICMP connection for faddr &lt;A href="http://10.1.4.26/0" style="color: #1155cc; font-family: arial, sans-serif; background-color: #ffffff;" target="_blank"&gt;10.1.4.26/0&lt;/A&gt; gaddr 10.1.2.40/27649 laddr 10.0.0.40/27649&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 15 2013|15:38:09|302020|10.0.0.40|27649|10.1.4.26|0|Built outbound ICMP connection for faddr &lt;A href="http://10.1.4.26/0" style="color: #1155cc; font-family: arial, sans-serif; background-color: #ffffff;" target="_blank"&gt;10.1.4.26/0&lt;/A&gt; gaddr 10.1.2.40/27649 laddr 10.0.0.40/27649&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your help and guidance is much appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119320#M392817</guid>
      <dc:creator>Mohamed Hamid</dc:creator>
      <dc:date>2019-03-12T00:47:11Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119321#M392824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not quite sure what you are referring to with the Log messages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the IP address under every "object" configured above is the IP 10.0.0.40 the configurations should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There however be NAT rules that override the operation of these configurations but that is impossible to say without seeing more NAT configurations or output of "packet-tracer" command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input &lt;INPUT interface="" /&gt; tcp &lt;SOURCE address=""&gt; &lt;SOURCE port=""&gt; &lt;MAPPED address=""&gt; &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/MAPPED&gt;&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 16:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119321#M392824</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-15T16:34:50Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119322#M392831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for you reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the command in questions and it passed all phases however at the end it provide the following reason for dropping packet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (sp-security-failed) Slowpath security checks failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 16:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119322#M392831</guid>
      <dc:creator>Mohamed Hamid</dc:creator>
      <dc:date>2013-01-15T16:42:41Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119323#M392836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I'm not completely mistaken you might have used the actual IP address of 10.0.0.40 as the destination IP address and not the NAT IP address (that applies to the connection attempt you are trying to simulate)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 16:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119323#M392836</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-15T16:46:34Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119324#M392840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following is what I ran &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.1.2.40 is the NAT address for 10.0.0.40? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this correct?&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;asa-L# packet-tracer input il2AHdata tcp 10.0.0.40 22 10.1.2.40 22&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.1.2.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; dmzAHmgmt&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group il2AHdata_access_in in interface il2AHdata&lt;/P&gt;&lt;P&gt;access-list il2AHdata_access_in extended permit tcp host 10.0.0.40 10.1.2.0 255.255.255.0 eq ssh&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: FOVER&lt;/P&gt;&lt;P&gt;Subtype: standby-update&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: VPN&lt;/P&gt;&lt;P&gt;Subtype: ipsec-tunnel-flow&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network monitoringsystem-01&lt;/P&gt;&lt;P&gt; nat (il2AHdata,dmzAHmgmt) static 10.1.2.40&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate monitoringsystem/22 to dmgmtMonNAT/22&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: il2AHdata&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: dmzAHmgmt&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (sp-security-failed) Slowpath security checks failed&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 16:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119324#M392840</guid>
      <dc:creator>Mohamed Hamid</dc:creator>
      <dc:date>2013-01-15T16:51:01Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119325#M392844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i did this command again this time with the actual destination of the server on our dmz rather than the NAT ip mapped to 10.0.0.40 and it worked fine howe my server still cannot communicate? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems a bit odd &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;asa-L# packet-tracer input il2AHdata tcp 10.0.0.40 22 10.1.4.26 22&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; hostileAHmgmt&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; dmzAHmgmt&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group il2AHdata_access_in in interface il2AHdata&lt;/P&gt;&lt;P&gt;access-list il2AHdata_access_in extended permit tcp host 10.0.0.40 10.1.4.0 255.255.255.0 eq ssh&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: FOVER&lt;/P&gt;&lt;P&gt;Subtype: standby-update&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: VPN&lt;/P&gt;&lt;P&gt;Subtype: ipsec-tunnel-flow&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network monitoringsystem-01&lt;/P&gt;&lt;P&gt; nat (il2AHdata,dmzAHmgmt) static 10.1.2.40&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate monitoringsystem/22 to dmgmtMonNAT/22&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 5481800, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: il2AHdata&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: dmzAHmgmt&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 16:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119325#M392844</guid>
      <dc:creator>Mohamed Hamid</dc:creator>
      <dc:date>2013-01-15T16:55:31Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119326#M392847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first "packet-tracer" doesnt make any sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network monitoringsystem-01&lt;/P&gt;&lt;P&gt; host 10.0.0.40&lt;/P&gt;&lt;P&gt; nat (il2AHdata,dmzAHmgmt) static 10.1.2.40&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa-L# packet-tracer input il2AHdata tcp 10.0.0.40 22 10.1.2.40 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You source the connection from the host you are doing Static NAT for and the destination IP address is the NAT IP address of the same source host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second "packet-tracer" command atleast makes sense from the par that its destination IP address is not alteast a NAT IP address listed in your configurations. (Though I havent seen all of them naturally)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa-L# packet-tracer input il2AHdata tcp 10.0.0.40 22 10.1.4.26 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But where is the network that contains IP address 10.1.4.26 ? dmzAHmgmt?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do the logs say if you actually try some TCP connection between the hosts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 17:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119326#M392847</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-15T17:22:07Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119327#M392850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies please ignore first packet trace. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;But where is the network that contains IP address 10.1.4.26 ? dmzAHmgmt?&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IP address 10.1.4.26 sits on a network that sits off another firewall in our DMZ.&amp;nbsp; I have run a packet trace on that firewall and it seems incoming ICMP requets from the nat 10.1.2.40 however when it tried to return the packet back to 10.1.2.40 it claims that host is unreachable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;What do the logs say if you actually try some TCP connection between the hosts?&lt;/PRE&gt;&lt;P&gt;1) When I run a telnet on port tcp/22 I see the following in the logs from the ASDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;6|Jan 15 2013|17:32:25|302016|10.1.4.26|161|monitoringsystem|53486|Teardown UDP connection 5535929 for dmzAHmgmt:10.1.4.26/161 to il2AHdata:monitoringsystem/53486 duration 0:02:06 bytes 384&lt;/P&gt;&lt;P&gt;6|Jan 15 2013|17:32:14|302021|10.1.4.26|0|monitoringsystem|4038|Teardown ICMP connection for faddr 10.1.4.26/0 gaddr dmgmtMonNAT/4038 laddr monitoringsystem/4038&lt;/P&gt;&lt;P&gt;6|Jan 15 2013|17:32:09|302020|monitoringsystem|4038|10.1.4.26|0|Built outbound ICMP connection for faddr 10.1.4.26/0 gaddr dmgmtMonNAT/4038 laddr monitoringsystem/4038&lt;/P&gt;&lt;P&gt;6|Jan 15 2013|17:31:50|302015|monitoringsystem|50625|10.1.4.26|161|Built outbound UDP connection 5537836 for dmzAHmgmt:10.1.4.26/161 (10.1.4.26/161) to il2AHdata:monitoringsystem/50625 (dmgmtMonNAT/50625)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;6&lt;/TD&gt;
&lt;TD&gt;Jan 15 2013&lt;/TD&gt;
&lt;TD&gt;17:33:37&lt;/TD&gt;
&lt;TD&gt;302013&lt;/TD&gt;
&lt;TD&gt;monitoringsystem&lt;/TD&gt;
&lt;TD&gt;51063&lt;/TD&gt;
&lt;TD&gt;10.1.4.26&lt;/TD&gt;
&lt;TD&gt;22&lt;/TD&gt;
&lt;TD&gt;Built outbound TCP connection 5540186 for dmzAHmgmt:10.1.4.26/22 (10.1.4.26/22) to il2AHdata:monitoringsystem/51063 (dmgmtMonNAT/51063)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 17:35:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119327#M392850</guid>
      <dc:creator>Mohamed Hamid</dc:creator>
      <dc:date>2013-01-15T17:35:12Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119328#M392855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the TCP connection forming normally because of the SYN packet the firewalls sees.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I however dont see any Teardown message for the same TCP connection so I cant say if there is now actually an active TCP connection on the firewall (which would mean the remote host has replied to the SYN) or if you just didnt include the Teardown message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the connection doesnt go through&amp;nbsp; for whatever reason there should be a Teardown message with "SYN Timeout". If on the other hand the TCP connection was formed and was tore down normally it would be a Teardown message with "TCP FINs"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 17:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119328#M392855</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-15T17:40:26Z</dc:date>
    </item>
    <item>
      <title>NAT Problems in 8.3 when untranslating NATs</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119329#M392858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well I dont see any SYN timeouts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just run a ping to another server at the address 10.0.2.10 and the following appears in my log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jan 16 2013&lt;/TD&gt;&lt;TD&gt;09:43:48&lt;/TD&gt;&lt;TD&gt;302020&lt;/TD&gt;&lt;TD&gt;monitoringsystem&lt;/TD&gt;&lt;TD&gt;53816&lt;/TD&gt;&lt;TD&gt;ah1-git-01&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Built outbound ICMP connection for faddr ah1-git-01/0 gaddr gitDataMon/53816 laddr monitoringsystem/53816&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jan 16 2013&lt;/TD&gt;&lt;TD&gt;09:43:52&lt;/TD&gt;&lt;TD&gt;302020&lt;/TD&gt;&lt;TD&gt;monitoringsystem&lt;/TD&gt;&lt;TD&gt;14552&lt;/TD&gt;&lt;TD&gt;ah1-git-01&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Built outbound ICMP connection for faddr ah1-git-01/0 gaddr gitDataMon/14552 laddr monitoringsystem/14552&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jan 16 2013&lt;/TD&gt;&lt;TD&gt;09:43:56&lt;/TD&gt;&lt;TD&gt;302021&lt;/TD&gt;&lt;TD&gt;ah1-git-01&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;monitoringsystem&lt;/TD&gt;&lt;TD&gt;14552&lt;/TD&gt;&lt;TD&gt;Teardown ICMP connection for faddr ah1-git-01/0 gaddr gitDataMon/14552 laddr monitoringsystem/14552&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jan 16 2013&lt;/TD&gt;&lt;TD&gt;09:44:22&lt;/TD&gt;&lt;TD&gt;302020&lt;/TD&gt;&lt;TD&gt;monitoringsystem&lt;/TD&gt;&lt;TD&gt;14591&lt;/TD&gt;&lt;TD&gt;ah1-git-01&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Built outbound ICMP connection for faddr ah1-git-01/0 gaddr gitDataMon/14591 laddr monitoringsystem/14591&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jan 16 2013&lt;/TD&gt;&lt;TD&gt;09:44:26&lt;/TD&gt;&lt;TD&gt;302021&lt;/TD&gt;&lt;TD&gt;ah1-git-01&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;monitoringsystem&lt;/TD&gt;&lt;TD&gt;14591&lt;/TD&gt;&lt;TD&gt;Teardown ICMP connection for faddr ah1-git-01/0 gaddr gitDataMon/14591 laddr monitoringsystem/14591&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am pretty sure its not a firewall rule on the server itself as it worked completely fine in 8.2 I have cheked the firewall logs on server.&amp;nbsp; It seems the returning ping back in is lost somewhere&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2013 09:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems-in-8-3-when-untranslating-nats/m-p/2119329#M392858</guid>
      <dc:creator>Mohamed Hamid</dc:creator>
      <dc:date>2013-01-16T09:49:05Z</dc:date>
    </item>
  </channel>
</rss>

