<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic problem with no nat after upgrade version in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077357#M395206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Fine, but what did you change exactly? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Nov 2012 12:13:25 GMT</pubDate>
    <dc:creator>Peter Koltl</dc:creator>
    <dc:date>2012-11-26T12:13:25Z</dc:date>
    <item>
      <title>problem with no nat after upgrade version</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077354#M395203</link>
      <description>&lt;P&gt;Hello Guys...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im having problems with nat after upgrade....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source = 10.11.7.14&lt;/P&gt;&lt;P&gt;destination = 10.0.32.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the next hop for 10.0.32/24 is 10.0.5.1, by inside interface. My firewall Pings this 10.0.5.1. When I change the router to doesnt pass by firewall, the connection works from source to destination, works!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In log, im receiving this message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Nov 23 2012&lt;/TD&gt;&lt;TD&gt;15:24:54&lt;/TD&gt;&lt;TD&gt;302303&lt;/TD&gt;&lt;TD&gt;spbwts02_0303&lt;/TD&gt;&lt;TD&gt;55517&lt;/TD&gt;&lt;TD&gt;10.0.32.10&lt;/TD&gt;&lt;TD&gt;80&lt;/TD&gt;&lt;TD&gt;Built TCP state-bypass connection 249015 from dmz:spbwts02_0303/55517 (spbwts02_0303/55517) to inside:10.0.32.10/80 (10.0.32.10 /80)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Nov 23 2012&lt;/TD&gt;&lt;TD&gt;15:27:29&lt;/TD&gt;&lt;TD&gt;302304&lt;/TD&gt;&lt;TD&gt;spbwts02_0303&lt;/TD&gt;&lt;TD&gt;51123&lt;/TD&gt;&lt;TD&gt;10.0.32.10&lt;/TD&gt;&lt;TD&gt;80&lt;/TD&gt;&lt;TD&gt;Teardown TCP state-bypass connection 242785 from dmz:spbwts02_0303/51123 to inside:10.0.32.10/80 duration 1:00:10 bytes 0 Connection timeout&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 8.2 I had this NAT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ interface:&lt;/P&gt;&lt;P&gt;Exempt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.32.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.11.7.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (outbound)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a bypass for those networks and services. I guess I dont need bypass because the packet comes from dmz and goes to inside, right? Anyway, I removed bypass and nothing happen!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And now, in 8.4(5) I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; obj-10.11.7.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; obj-10.0.32.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; original&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; original&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can be my problem?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077354#M395203</guid>
      <dc:creator>Diego Maciel Gomes</dc:creator>
      <dc:date>2019-03-12T00:27:22Z</dc:date>
    </item>
    <item>
      <title>problem with no nat after upgrade version</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077355#M395204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may have encountered the change of NAT behavior from 8.4(2). Check the "Lookup route table to locate egress interface" checkbox in your identity NAT rule. (This is the route-lookup option in CLI.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paste your config if that does not help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Nov 2012 20:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077355#M395204</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2012-11-25T20:24:17Z</dc:date>
    </item>
    <item>
      <title>problem with no nat after upgrade version</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077356#M395205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Peter!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed the route for that network and worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I needed to keep the bypass. I didnt understand why, because the traffic comes from DMZ and goes to INSIDE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 11:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077356#M395205</guid>
      <dc:creator>Diego Maciel Gomes</dc:creator>
      <dc:date>2012-11-26T11:18:12Z</dc:date>
    </item>
    <item>
      <title>problem with no nat after upgrade version</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077357#M395206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Fine, but what did you change exactly? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 12:13:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077357#M395206</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2012-11-26T12:13:25Z</dc:date>
    </item>
    <item>
      <title>problem with no nat after upgrade version</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077358#M395207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;route, look:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.0.32.0 255.255.255.0 10.11.5.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now and working:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.0.32.0 255.255.255.0 10.11.2.3 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont have an interface in the 10.11.5.0 network. I guess when someone configured the route, put this 10.11.5.1 as gateway, but I dont know how it was working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I changed to 10.11.2.3 and OK. My firewall has an interface in 10.11.2.0 newtork.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the bypass is a mistery to me yet!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 12:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-no-nat-after-upgrade-version/m-p/2077358#M395207</guid>
      <dc:creator>Diego Maciel Gomes</dc:creator>
      <dc:date>2012-11-26T12:29:11Z</dc:date>
    </item>
  </channel>
</rss>

