<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problems with NAT ASA 8.4(2) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050568#M439002</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here the output...&lt;/P&gt;&lt;P&gt;the first Output is what you provides &lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.226.31.14 8 0&amp;nbsp; 10.226.31.10&lt;/P&gt;&lt;P&gt;the second is &lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.226.224.25 8 0&amp;nbsp; 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13# packet-tracer input inside icmp 10.226.31.14 8 0 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.226.16.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.240.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group inside_access_in_3 in interface inside&lt;/P&gt;&lt;P&gt;access-list inside_access_in_3 extended permit ip any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 139046, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13# packet-tracer input inside icmp 10.226.224.25 8 0 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.226.16.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.240.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group inside_access_in_3 in interface inside&lt;/P&gt;&lt;P&gt;access-list inside_access_in_3 extended permit ip any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 139111, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Aug 2012 05:54:16 GMT</pubDate>
    <dc:creator>zlbbehring</dc:creator>
    <dc:date>2012-08-24T05:54:16Z</dc:date>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050562#M438996</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;I have a ASA5520 with 4 Portchannel interfaces and ASA Version 8.4.(2). There are many vlan interfaces but in the DMZ I have one Server who has a Static NAT to all other interfaces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;original (security 50) DMZ&amp;nbsp; 10.226.224.25 &lt;/P&gt;&lt;P&gt;translatet&amp;nbsp; (security 100) inside 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the CLI for this is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat(DMZ,inside) source static 10.226.224.25 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Rules&lt;/P&gt;&lt;P&gt;any any - ICMP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me why the first ping works and the others doesn´t work ??? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;Erkan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:45:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050562#M438996</guid>
      <dc:creator>zlbbehring</dc:creator>
      <dc:date>2019-03-11T23:45:42Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050563#M438997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have access rule to only allow ICMP thats why only ping is working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nitesh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 12:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050563#M438997</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2012-08-23T12:13:39Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050564#M438998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, you didn´t understand what I mean. The first ping has a reply and all other pings didn´t reply for this NAT entry...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 12:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050564#M438998</guid>
      <dc:creator>zlbbehring</dc:creator>
      <dc:date>2012-08-23T12:58:53Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050565#M438999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;can you remove that NAT command and try to do the nat the 8.4 static way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please find the commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-10.226.224.25 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; host 10.226.224.25 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat (DMZ,inside) static10.226.31.10&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 13:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050565#M438999</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2012-08-23T13:36:07Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050566#M439000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have test it but it doesn´t work....its the same failure...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 05:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050566#M439000</guid>
      <dc:creator>zlbbehring</dc:creator>
      <dc:date>2012-08-24T05:37:18Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050567#M439001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Erkran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide the following output complete&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.226.31.14 8 0&amp;nbsp; 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 05:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050567#M439001</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-24T05:42:29Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050568#M439002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here the output...&lt;/P&gt;&lt;P&gt;the first Output is what you provides &lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.226.31.14 8 0&amp;nbsp; 10.226.31.10&lt;/P&gt;&lt;P&gt;the second is &lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.226.224.25 8 0&amp;nbsp; 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13# packet-tracer input inside icmp 10.226.31.14 8 0 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.226.16.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.240.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group inside_access_in_3 in interface inside&lt;/P&gt;&lt;P&gt;access-list inside_access_in_3 extended permit ip any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 139046, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13# packet-tracer input inside icmp 10.226.224.25 8 0 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.226.16.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.240.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group inside_access_in_3 in interface inside&lt;/P&gt;&lt;P&gt;access-list inside_access_in_3 extended permit ip any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 139111, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MBRASA13#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 05:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050568#M439002</guid>
      <dc:creator>zlbbehring</dc:creator>
      <dc:date>2012-08-24T05:54:16Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050569#M439003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet tracer one looks good &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now why are you doing this :&lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.226.224.25 8 0 10.226.31.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean the host on the DMZ 10.226.31.10 is being translated to the inside to the IP address of 10.226.224.25 so I do not understand what are you sending traffic from the own global IP to itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tell me what are you trying to acomplish with this nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 06:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050569#M439003</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-24T06:03:42Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050570#M439004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the packet tracer looks good...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;okay now I understand what you have test...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes the 10.226.31.10 is the translated IP and the 10.226.224.25 is the original...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attched a drawing from our topologie&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/1/4/99413-aaa.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 06:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050570#M439004</guid>
      <dc:creator>zlbbehring</dc:creator>
      <dc:date>2012-08-24T06:22:47Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050571#M439005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Erkan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So just to make sure we are on the same page you are looking to make inside users access that DMZ server on the &lt;/P&gt;&lt;P&gt;10.226.31.10 &lt;/P&gt;&lt;P&gt;Right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 06:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050571#M439005</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-24T06:33:08Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050572#M439006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes right, every User from Inside use this 10.226.31.10 to access to the DMZ Server MBLX74&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 06:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050572#M439006</guid>
      <dc:creator>zlbbehring</dc:creator>
      <dc:date>2012-08-24T06:36:33Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050573#M439007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julio is it possible that I have a problem with Portchannel and security Levels ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All Vlans are connected via portchannel to this Firewall...I have 4 x 1 GB Ports connected to a redundant Nexus 5000 (2 Ports respectively) and inside have the security 100, DMZ have 50, and all other Vlans have 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 07:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050573#M439007</guid>
      <dc:creator>zlbbehring</dc:creator>
      <dc:date>2012-08-24T07:39:23Z</dc:date>
    </item>
    <item>
      <title>Problems with NAT ASA 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050574#M439008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Erkan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result of the packet tracer shows that there is no nat taking place, please paste the running-config&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 16:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-with-nat-asa-8-4-2/m-p/2050574#M439008</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-24T16:09:32Z</dc:date>
    </item>
  </channel>
</rss>

