<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Akash,  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/regarding-asa/m-p/2795850#M415638</link>
    <description>&lt;P&gt;Hi Akash,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Looks like you have a bunch of NATs configured that &amp;nbsp;might be overlapping this entry and casuing that error. Try adding the "route-lookup" keyword at the end of the NAts that contain the same subnet or have the "any" statement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps&lt;/P&gt;
&lt;P&gt;-Randy-&lt;/P&gt;</description>
    <pubDate>Sat, 05 Dec 2015 00:45:41 GMT</pubDate>
    <dc:creator>rvarelac</dc:creator>
    <dc:date>2015-12-05T00:45:41Z</dc:date>
    <item>
      <title>Regarding ASA</title>
      <link>https://community.cisco.com/t5/network-security/regarding-asa/m-p/2795849#M415637</link>
      <description>&lt;P&gt;I am having a issue to undertand the NATTING in ASA, below is the issue which i am having as of now.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;getting drop:- can you please go through it and let me know what can be the issue&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input outside tcp 166.77.235.144 2020 166.77.174.123 123&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 166.77.35.2 using egress ifc&amp;nbsp; inside&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group acl-outside in interface outside&lt;BR /&gt;access-list acl-outside extended permit ip host 166.77.235.144 host 166.77.174.123&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: CONN-SETTINGS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map RT881625&lt;BR /&gt;&amp;nbsp;match access-list rt881625-conns-acl&lt;BR /&gt;policy-map RT881625-conns&lt;BR /&gt;&amp;nbsp;class RT881625&lt;BR /&gt;&amp;nbsp; set connection conn-max 0 embryonic-conn-max 0 random-sequence-number enable&lt;BR /&gt;service-policy RT881625-conns interface inside&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network natobj-166.77.0.0-16&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;====================&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source dynamic natobj-via-axciom natobj-axciom-natpool destination static natobj-axiom-nets natobj-axiom-nets&lt;BR /&gt;nat (dmz-dot12,outside) source static natobj-src-166.77.12.0-22 natobj-src-166.77.12.0-22 destination static natobj-dst-a2m natobj-dst-a2m&lt;BR /&gt;nat (dmz-dot12,outside) source dynamic natobj-src-166.77.12.0-22 natobj-global-nat destination static natobj-dst-hosting natobj-dst-hosting&lt;BR /&gt;nat (dmz-dot9,outside) source dynamic natobj-src-166.77.9.0-24 natobj-global-nat destination static natobj-dst-hosting natobj-dst-hosting&lt;BR /&gt;nat (outside,outside) source dynamic natobj-vpn-pool-uturn pat-pool natobj-default-natpool destination static natobj-dst-nets-uturn natobj-dst-nets-uturn&lt;BR /&gt;nat (outside,outside) source static servicenow-natobj-src-nets-uturn servicenow-natobj-src-nets-uturn destination static servicenow-natobj-dst-nets-uturn servicenow-natobj-dst-nets-uturn&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static wordpress-129.228.35.64 wordpress-129.228.35.64&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static 129.228.0.0 129.228.0.0&lt;BR /&gt;nat (inside,outside) source static any any destination static redspace-172.18.0.80 redspace-172.18.0.80&lt;BR /&gt;nat (inside,outside) source dynamic natobj-src-oneoffs pat-pool natobj-global-oneoffs&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool natobj-global-oneoffs destination static natobj-dst-oneoffs natobj-dst-oneoffs&lt;BR /&gt;nat (outside,outside) source static VPN_Hairpin VPN_Hairpin destination static VPN_Hairpin VPN_Hairpin&lt;BR /&gt;nat (inside,outside) source static natobj-src-tacacs natobj-src-tacacs destination static natobj-dst-tacas-devices natobj-dst-tacas-devices&lt;BR /&gt;nat (inside,outside) source static singapore-dr-us singapore-dr-us destination static singapore-dr-asia singapore-dr-asia&lt;BR /&gt;nat (dmz-dot12,outside) source static natobj-src-a2m natobj-src-a2m destination static natobj-dst-a2m natobj-dst-a2m route-lookup&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-vpn-lan-to-lan-new natobj-dst-vpn-lan-to-lan-new&lt;BR /&gt;nat (dmz-dot8,outside) source static natobj-src-larsentoubro-local natobj-src-larsentoubro-local destination static natobj-dst-larsentoubro-remote natobj-dst-larsentoubro-remote&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-vpn-lan-to-lan natobj-dst-vpn-lan-to-lan&lt;BR /&gt;nat (inside,outside) source static natobj-src-network-tools natobj-src-network-tools destination static natobj-dst-network-devices natobj-dst-network-devices&lt;BR /&gt;nat (inside,outside) source static pp-cl1-10-6-0-0 pp-cl1-10-6-0-0 destination static pp-bet-172-20-20-0 pp-bet-172-20-20-0&lt;BR /&gt;nat (inside,dmz-paramount) source static obj-1515-52fl-printers obj-1515-52fl-printers destination static obj-ppc-192-168-148-0 obj-ppc-192-168-148-0&lt;BR /&gt;nat (inside,outside) source static obj-10-0-0-0-24 obj-10-0-0-0-24 destination static obj-no-nat-bet obj-no-nat-bet&lt;BR /&gt;nat (inside,dmz-paramount) source static obj-no-nat-to-ppc obj-no-nat-to-ppc destination static obj-ppc-no-nat obj-ppc-no-nat&lt;BR /&gt;nat (inside,outside) source static natobj-172.16.0.0-12 166.77.6.4 destination static SterlingASA SterlingASA&lt;BR /&gt;nat (inside,dmz-paramount) source dynamic any interface&lt;BR /&gt;nat (inside,outside) source static natobj-166.77.0.0-16 166.77.6.4 destination static SterlingASA SterlingASA&lt;BR /&gt;nat (inside,outside) source static xbox-166.77.216.203 xbox-166.77.216.203&lt;BR /&gt;nat (inside,outside) source static xbox-216-184 xbox-public-6-218&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool nielsen-vpn-local destination static nielsen-vpn-remote nielsen-vpn-remote&lt;BR /&gt;nat (inside,dmz-paramount) source static natobj-src-viacom-no-nat natobj-src-viacom-no-nat destination static natobj-dst-paramount-no-nat natobj-dst-paramount-no-nat&lt;BR /&gt;nat (inside,outside) source static natobj-src-166.77.200.105 natobj-src-166.77.200.105 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (inside,outside) source static 166.77.200.57 166.77.200.57 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (inside,dmz-dot5) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot7) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot9) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot11) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,dmz-dot12) source static RFC-1918-Addresses RFC-1918-Addresses destination static DMZ-Networks DMZ-Networks&lt;BR /&gt;nat (inside,outside) source static 166.77.186.224 166.77.186.224 destination static 69.195.244.238 69.195.244.238&lt;BR /&gt;nat (inside,outside) source static natobj-src-166.77.200.105 natobj-src-166.77.200.105 destination static 69.195.244.238 69.195.244.238&lt;BR /&gt;nat (inside,outside) source static 166.77.199.147 166.77.199.147 destination static 172.20.90.0 172.20.90.0&lt;BR /&gt;nat (inside,outside) source static 166.77.199.223 166.77.199.223 destination static 172.20.90.0 172.20.90.0&lt;BR /&gt;nat (inside,outside) source static NATPOOL-166.77.35.128 NATPOOL-166.77.35.128 destination static 69.195.244.235 69.195.244.235&lt;BR /&gt;nat (dmz-lb-dmz,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-larsentoubro-remote natobj-dst-larsentoubro-remote&lt;BR /&gt;nat (inside,outside) source static 10.40.122.20 10.40.122.20 destination static SterlingDECRU SterlingDECRU&lt;BR /&gt;nat (inside,outside) source static 10.40.122.21 10.40.122.21 destination static SterlingDECRU SterlingDECRU&lt;BR /&gt;nat (inside,outside) source dynamic any pat-pool natobj-global-bluejeans destination static GLB-bluejeans-nets GLB-bluejeans-nets&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_172.18.251.0_24 NETWORK_OBJ_172.18.251.0_24 no-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source static natobj-src-local-nets natobj-src-local-nets destination static natobj-dst-aws-servers natobj-dst-aws-servers&lt;BR /&gt;nat (inside,outside) source static Jenkins_Server Jenkins_Server destination static DMQA_Network DMQA_Network&lt;BR /&gt;nat (outside,outside) source static redspace-172.18.0.80 default-natpool-1 destination static 129.228.31.145 129.228.31.145&lt;BR /&gt;nat (inside,outside) source static VPN-Wireless_Pools-DMQA VPN-Wireless_Pools-DMQA destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.13 obj_166.77.185.13 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.14 obj_166.77.185.14 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.15 obj_166.77.185.15 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.123 obj_166.77.185.123 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.185.124 obj_166.77.185.124 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static obj_166.77.206.28 obj_166.77.206.28 destination static DMQA_Router DMQA_Router&lt;BR /&gt;nat (inside,outside) source static natobj-src-sap natobj-src-sap&lt;BR /&gt;nat (inside,outside) source static natobj-src-sap natobj-src-sap destination static natobj-src-sap natobj-src-sap&lt;BR /&gt;nat (inside,outside) source static obj_imailrelay-server obj_imailrelay-server destination static DMQA_Router DMQA_Router&lt;BR /&gt;!&lt;BR /&gt;object network natobj-172.18.3.0-25&lt;BR /&gt;&amp;nbsp;nat (dmz-corpvpn,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-10.10.4.0-24&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-192.21.120.0-23&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic pat-pool natobj-default-natpool&lt;BR /&gt;object network natobj-166.77.0.0-16&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:37:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-asa/m-p/2795849#M415637</guid>
      <dc:creator>akash.deep</dc:creator>
      <dc:date>2020-02-21T13:37:52Z</dc:date>
    </item>
    <item>
      <title>Hi Akash, </title>
      <link>https://community.cisco.com/t5/network-security/regarding-asa/m-p/2795850#M415638</link>
      <description>&lt;P&gt;Hi Akash,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Looks like you have a bunch of NATs configured that &amp;nbsp;might be overlapping this entry and casuing that error. Try adding the "route-lookup" keyword at the end of the NAts that contain the same subnet or have the "any" statement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps&lt;/P&gt;
&lt;P&gt;-Randy-&lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2015 00:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-asa/m-p/2795850#M415638</guid>
      <dc:creator>rvarelac</dc:creator>
      <dc:date>2015-12-05T00:45:41Z</dc:date>
    </item>
  </channel>
</rss>

