<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Problem - FWSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118253#M393996</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem in FWSM where the following happens:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I have 2 instances called fW01 and fw02.&lt;/P&gt;&lt;P&gt;- When I create an interface in the same VLAN in the 2 instances, the NAT does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upgraded the FWSM version 2.3 to 4.1 to try to fix this problem, but still does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They would know tell me if it is some configuration problem or is it a bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:37:59 GMT</pubDate>
    <dc:creator>Anderson Ribeiro</dc:creator>
    <dc:date>2019-03-12T00:37:59Z</dc:date>
    <item>
      <title>NAT Problem - FWSM</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118253#M393996</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem in FWSM where the following happens:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I have 2 instances called fW01 and fw02.&lt;/P&gt;&lt;P&gt;- When I create an interface in the same VLAN in the 2 instances, the NAT does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upgraded the FWSM version 2.3 to 4.1 to try to fix this problem, but still does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They would know tell me if it is some configuration problem or is it a bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118253#M393996</guid>
      <dc:creator>Anderson Ribeiro</dc:creator>
      <dc:date>2019-03-12T00:37:59Z</dc:date>
    </item>
    <item>
      <title>NAT Problem - FWSM</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118254#M394007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share some configurations for us to go through?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly I've gotten a bit rusty on the FWSM side and mostly used new ASAs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the version of the configuration before and after the change you are trying to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the situation the following&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You have a single FWSM running in multiple context mode&lt;/LI&gt;&lt;LI&gt;You have 2 Security Contexts on that FWSM&lt;/LI&gt;&lt;LI&gt;You are trying to add a single created Vlan interface to both Security Contexts?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 11:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118254#M394007</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-17T11:16:04Z</dc:date>
    </item>
    <item>
      <title>NAT Problem - FWSM</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118255#M394018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You have a single FWSM running in multiple context mode - &lt;STRONG&gt;YES&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;You have 2 Security Contexts on that FWSM - &lt;STRONG&gt;YES&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;You are trying to add a single created Vlan interface to both Security Contexts? - &lt;STRONG&gt;YES&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow below the configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;FW01&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; interface Vlan12&lt;/P&gt;&lt;P&gt; nameif NET-LAN&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list NET-LAN extended permit ip 10.10.10.0 255.255.255.0 10.30.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list NET-LAN-INTERNET extended permit ip 10.10.10.0 255.255.255.0 10.30.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (NET-LAN) 10 access-list NET-LAN-INTERNET&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;global (DMZ-PUBLIC-ROB) 10 10.30.0.10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;____________________________________________________________________________________________&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;FW02&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan12&lt;/P&gt;&lt;P&gt; nameif NET-LAN&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list NET-LAN extended permit ip 10.10.10.0 255.255.255.0 10.31.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list NET-LAN-INTERNET extended permit ip 10.10.10.0 255.255.255.0 10.31.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (NET-LAN) 10 access-list NET-LAN-INTERNET&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;global (DMZ-PUBLIC-CAR) 10 10.31.0.10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;_____________________________________________________________________________________________&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case the NAT doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 12:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118255#M394018</guid>
      <dc:creator>Anderson Ribeiro</dc:creator>
      <dc:date>2012-12-17T12:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem - FWSM</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118256#M394034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not quite sure if I'm getting the whole picture of the network but the Policy NAT configuration doesnt seem that complex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems you have the following setup&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The mentioned 2 Security Context are connected by Vlan12 to the same NET-LAN&lt;/LI&gt;&lt;LI&gt;The mentioned 2 Secuirty Context have different DMZ networks behind them&lt;/LI&gt;&lt;LI&gt;In both cases you want to Policy NAT the traffic coming from the NET-LAN to the DMZ in question so that the given NAT address belongs to the same network as the actual destination host?&lt;/LI&gt;&lt;LI&gt;On the NET-LAN side you probably have static routes pointing towards each context for the DMZ networks.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is the case can you specify how you confirm that the NAT is not working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you taking the "show xlate" output for the connections? Can you get some log messages of the connection attempts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only NAT rule that should override the Policy NAT (to my understanding) is either a more specific Policy NAT rule or NAT0/NAT Exempt rule. Going between the old NAT and new NAT does get me confused sometimes so I'm not 100% sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 13:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-fwsm/m-p/2118256#M394034</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-17T13:59:43Z</dc:date>
    </item>
  </channel>
</rss>

