<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multi-global twice nat &amp;gt;8.3 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995013#M440746</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA Version 8.4(2)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name orange.fr&lt;/P&gt;&lt;P&gt;enable password Yn8Esq3NcXIHL35v encrypted&lt;/P&gt;&lt;P&gt;passwd Yn8Esq3NcXIHL35v encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description Lien vers reseau Interne Client&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description Lien pppoe vers Wanadoo-Orange&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.99.16 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 8.8.8.8&lt;/P&gt;&lt;P&gt; name-server 8.8.4.4&lt;/P&gt;&lt;P&gt; domain-name orange.fr&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network Reseau-Interne&lt;/P&gt;&lt;P&gt; subnet 192.168.99.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network rdp-test&lt;/P&gt;&lt;P&gt; host 192.168.0.3&lt;/P&gt;&lt;P&gt;object network rdp-test1&lt;/P&gt;&lt;P&gt; host 192.168.0.4&lt;/P&gt;&lt;P&gt;object network Ext-9817&lt;/P&gt;&lt;P&gt; host 192.168.98.17&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit tcp any object rdp-test eq 3389&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit tcp any object rdp-test1 eq 3389&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit udp any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm debugging&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network rdp-test&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 192.168.99.17&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network rdp-test1&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 192.168.98.17&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source dynamic any interface&lt;/P&gt;&lt;P&gt;access-group ACL_INT in interface inside&lt;/P&gt;&lt;P&gt;access-group ACL_OUT in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.99.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.99.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 192.168.99.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Jun 2012 14:13:49 GMT</pubDate>
    <dc:creator>jerome.bordeau</dc:creator>
    <dc:date>2012-06-18T14:13:49Z</dc:date>
    <item>
      <title>Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995005#M440738</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I try to convert a CISCO ASA 8.2 version to 8.4 BUT, I have a small or "little" problem :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Cisco ASA 8.2.x, i have a possibility to create multi-line global with different subnet.&lt;/P&gt;&lt;P&gt;Example : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (outside) 2 217.1.x.65-217.x.x.66 netmask 255.255.255.240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (outside) 1 interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&amp;lt;--&amp;nbsp; Ip interface is other subnet : 217.3.x.3&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (outside) 2 217.1.x.67 netmask 255.255.255.240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (dmz2) 2 192.168.4.0 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the method or solution to translate multi-global in 8.4 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In same idea : with static translation in 8.4 : i try to use different server in inside's zone, but not in same network on outside. In 8.2 Firmware, it's very easy to use that, but in 8.3-8.4 version, i don't have some idea to manipulate ...&lt;SPAN __jive_emoticon_name="cry" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Vlan1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; description Lien vers reseau Interne Client&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; nameif inside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; ip address 192.168.0.1 255.255.255.0 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Vlan2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; nameif outside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; security-level 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; ip address 192.168.99.16 255.255.255.0 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;object network rdp-test&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; host 192.168.0.3&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; nat (inside,outside) static 192.168.99.17&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;object network rdp-test1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; host 192.168.0.4&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; nat (inside,inside) static 192.168.98.17&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not a filter problem, it's probably a problem between nat and arp .... but where ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please, help me !!!&lt;/P&gt;&lt;P&gt;Have a nice day&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JB&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:20:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995005#M440738</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2019-03-11T23:20:25Z</dc:date>
    </item>
    <item>
      <title>Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995006#M440739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the direct conversion:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (outside) 1 interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj_inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (outside) 2 217.1.x.65-217.x.x.66 netmask 255.255.255.240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (outside) 2 217.1.x.67 netmask 255.255.255.240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (dmz2) 2 192.168.4.0 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj-&lt;EM&gt;217.1.x.65-217.x.x.66&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; range &lt;EM&gt;217.1.x.65 217.x.x.66&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj-&lt;EM&gt;217.1.x.67&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; host 217.1.x.67&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network 217.1.x.6x-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; network-object object obj-&lt;EM&gt;217.1.x.65-217.x.x.66&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; network-object object obj-&lt;EM&gt;217.1.x.67&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj-192.168.4.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; subnet 192.168.4.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; nat (dmz,outside) dynamic 217.1.x.6x-group&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 13:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995006#M440739</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-18T13:14:40Z</dc:date>
    </item>
    <item>
      <title>Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995007#M440740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank Jenifer, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For First part, perfect ! thanks a lot, but for 2nd request : Have you a idea ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;interface Vlan1&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;description Lien vers reseau Interne Client&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;nameif inside&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;ip address 192.168.0.1 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;interface Vlan2&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;nameif outside&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;security-level 0&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;ip address 192.168.99.16 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;object network rdp-test&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;host 192.168.0.3&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;nat (inside,outside) static 192.168.99.17&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;object network rdp-test1&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;host 192.168.0.4&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;nat (inside,inside) static 192.168.98.17&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i try this lines, the second translation doesn't work... Have a you a idea to create static with different subnet on outside ?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 13:22:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995007#M440740</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T13:22:14Z</dc:date>
    </item>
    <item>
      <title>Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995008#M440741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what did you have configured before on version 8.2 and below?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, do you have typo:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;object network rdp-test1&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;host 192.168.0.4&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;nat (inside,&lt;STRONG&gt;inside&lt;/STRONG&gt;) static 192.168.98.17&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;shouldn't it be "nat (inside,outside) static &lt;/EM&gt;&lt;EM style="border-collapse: collapse; list-style: none outside none;"&gt;192.168.98.17" ??&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 13:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995008#M440741</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-18T13:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995009#M440742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For test only,&lt;/P&gt;&lt;P&gt;I would like use on Outside zone, 2 ip on differents subnets (in my example, 192.168.99.x and 192.168.98.x).&lt;/P&gt;&lt;P&gt;I test with rdp server in Inside zone on ip 192.168.0.3 with nat 192.168.99.17, it's all right for this nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a error from me : nat (inside, OUTSIDE) static 192.168.98.17 (keyboard error from me...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But with ip inside 192.168.0.4, i would like from outside, to connect on rdp server in inside by ip outside 192.168.98.17 &lt;/P&gt;&lt;P&gt;If i used wizard to test configuration, everything looks good... but in test, ... problem...&lt;/P&gt;&lt;P&gt;In 8.2 version, the static command in different ip running correctly but with twice nat, i don't see the good syntax...&lt;/P&gt;&lt;P&gt;Thank you very much for your help and excuse me poor english &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 13:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995009#M440742</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T13:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995010#M440743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;and what does your access-list say on the outside interface?&lt;/P&gt;&lt;P&gt;access-list from version 8.3 onwards need to refer to the real IP, not NATed IP anymore, so access-list should say:&lt;/P&gt;&lt;P&gt;access-list &lt;ACL-NAME&gt; permit tcp any host 192.168.0.4 eq 3389&lt;/ACL-NAME&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995010#M440743</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-18T14:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995011#M440744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have this rule exactly&amp;nbsp; :&lt;/P&gt;&lt;P&gt;access-list &lt;ACL-NAME&gt; permit tcp any host 192.168.0.4 eq 3389 , my rule filter is allright BUT, this translation nat (inside,outside) don't work correctly !! try if you want ? The most mistake : the access-list (for this rules) counter increase !!! but nothing after... If i try on first translation, access list counter increase too, and i have rdp connection.&amp;nbsp; &lt;/ACL-NAME&gt;&lt;/P&gt;&lt;P&gt;I test with asa5505 and 3 pc to test this, for 3 hours, i don't have find a solution.... ?? very strange&lt;/P&gt;&lt;P&gt;Would you like all configuration ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description Lien vers reseau Interne Client&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description Lien pppoe vers Wanadoo-Orange&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.99.16 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 8.8.8.8&lt;/P&gt;&lt;P&gt; name-server 8.8.4.4&lt;/P&gt;&lt;P&gt; domain-name orange.fr&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network Reseau-Interne&lt;/P&gt;&lt;P&gt; subnet 192.168.99.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network rdp-test&lt;/P&gt;&lt;P&gt; host 192.168.0.3&lt;/P&gt;&lt;P&gt;object network rdp-test1&lt;/P&gt;&lt;P&gt; host 192.168.0.4&lt;/P&gt;&lt;P&gt;object network Ext-9817&lt;/P&gt;&lt;P&gt; host 192.168.98.17&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit tcp any object rdp-test eq 3389&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit tcp any object rdp-test1 eq 3389&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit udp any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm debugging&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network rdp-test&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 192.168.99.17&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network rdp-test1&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 192.168.98.17&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source dynamic any interface&lt;/P&gt;&lt;P&gt;access-group ACL_INT in interface inside&lt;/P&gt;&lt;P&gt;access-group ACL_OUT in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.99.1 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:10:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995011#M440744</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T14:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995012#M440745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes pls, all config would be great.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995012#M440745</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-18T14:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995013#M440746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA Version 8.4(2)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name orange.fr&lt;/P&gt;&lt;P&gt;enable password Yn8Esq3NcXIHL35v encrypted&lt;/P&gt;&lt;P&gt;passwd Yn8Esq3NcXIHL35v encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description Lien vers reseau Interne Client&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description Lien pppoe vers Wanadoo-Orange&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.99.16 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 8.8.8.8&lt;/P&gt;&lt;P&gt; name-server 8.8.4.4&lt;/P&gt;&lt;P&gt; domain-name orange.fr&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network Reseau-Interne&lt;/P&gt;&lt;P&gt; subnet 192.168.99.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network rdp-test&lt;/P&gt;&lt;P&gt; host 192.168.0.3&lt;/P&gt;&lt;P&gt;object network rdp-test1&lt;/P&gt;&lt;P&gt; host 192.168.0.4&lt;/P&gt;&lt;P&gt;object network Ext-9817&lt;/P&gt;&lt;P&gt; host 192.168.98.17&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit tcp any object rdp-test eq 3389&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit tcp any object rdp-test1 eq 3389&lt;/P&gt;&lt;P&gt;access-list ACL_OUT extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list ACL_INT extended permit udp any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm debugging&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network rdp-test&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 192.168.99.17&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network rdp-test1&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 192.168.98.17&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source dynamic any interface&lt;/P&gt;&lt;P&gt;access-group ACL_INT in interface inside&lt;/P&gt;&lt;P&gt;access-group ACL_OUT in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.99.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.99.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 192.168.99.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995013#M440746</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T14:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995014#M440747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your help, it's very nice ! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995014#M440747</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T14:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995015#M440748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please remove the following 2 lines:&lt;/P&gt;&lt;P&gt;nat (outside,inside) source static any any destination static Ext-9817 rdp-test1&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static rdp-test1 Ext-9817 unidirectional inactive&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then "clear xlate"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i believe that you have route for the 192.168.98.x pointing towards the ASA outside interface IP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995015#M440748</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-18T14:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995016#M440749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for me, this 2 lines are a test. I remove this 2 lines, and clear xlate, clear arp, but without success...&lt;/P&gt;&lt;P&gt;My network map :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.99.16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.99.1&amp;nbsp; (router)&amp;nbsp; ------------+---------------------ASA-------------------Pc 192.168.0.3 (rdp) &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +-----Pc&amp;nbsp; 192.168.0.4 (rdp1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; other PC 192.168.98.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; to test from outside rdp1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995016#M440749</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T14:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995017#M440750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, don't think it works like that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your router, configure a route for 192.168.98.0/24 to point to the ASA 192.168.99.16.&lt;/P&gt;&lt;P&gt;Configure a PC in the 192.168.99.x subnet with the router being the default gateway and test to access 192.168.98.17&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 14:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995017#M440750</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-18T14:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995018#M440751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why ?&lt;/P&gt;&lt;P&gt;My opinion is a problem with ARP - Static on ASA.&lt;/P&gt;&lt;P&gt;In 8.2 version, this network map running correctly. &lt;/P&gt;&lt;P&gt;When i improve log level (debugging) on CISCO ASA, i see the request from my PC 192.168.98.2 try to join rdp server. I see SYN connection (but without sync + ack and ack...). I same time, when i try to ping from 192.168.98.2 to 192.168.98.17, i see "echo request" from CISCO ASA and "echo reply" !!! but on PC, icmp don't reply...&lt;/P&gt;&lt;P&gt;Have you a possibility to check this configuration on your side ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to add route on router but i'm septic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 15:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995018#M440751</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T15:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995019#M440752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I finish the test to add new route....&lt;/P&gt;&lt;P&gt;And amazing... it's allright !!! it's ok !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alert-interval 300&lt;/P&gt;&lt;P&gt;access-list ACL_OUT; 3 elements; name hash: 0x21ec8810&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 1 extended permit tcp any object rdp-test eq 3389 (hitcnt=0) 0x63af37f1&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list ACL_OUT line 1 extended permit tcp any host 192.168.0.3 eq 3389 (hitcnt=0) 0x63af37f1&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 2 extended permit tcp any object rdp-test1 eq 3389 (hitcnt=0) 0xc1209d8a&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; access-list ACL_OUT line 2 extended permit tcp any host 192.168.0.4 eq 3389 (hitcnt=1) 0xc1209d8a&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;access-list ACL_OUT line 3 extended permit icmp any any (hitcnt=0) 0x7ea87995&lt;/P&gt;&lt;P&gt;access-list ACL_INT; 3 elements; name hash: 0x88ae4fa9&lt;/P&gt;&lt;P&gt;access-list ACL_INT line 1 extended permit icmp any any (hitcnt=1) 0x01029607&lt;/P&gt;&lt;P&gt;access-list ACL_INT line 2 extended permit tcp any any (hitcnt=2) 0xe6887ad7&lt;/P&gt;&lt;P&gt;access-list ACL_INT line 3 extended permit udp any any (hitcnt=2) 0xba134485&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;/P&gt;&lt;P&gt;1 (inside) to (outside) source static rdp-test 192.168.99.17&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2 (inside) to (outside) source static rdp-test1 192.168.98.17&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 5, untranslate_hits = 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manual NAT Policies (Section 3)&lt;/P&gt;&lt;P&gt;1 (inside) to (outside) source dynamic any interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help Jenifer.&lt;/P&gt;&lt;P&gt;But can you explain me if i put my PC 192.168.98.3 on outside, (and i don't add a route), why this don't running ? The PC and NAT translation are in same network, in this case, i don't want a route.&lt;/P&gt;&lt;P&gt;What do you think ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 15:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995019#M440752</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T15:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995020#M440753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a change in the behaviour on how ASA response to ARP, but it doesn't start until version 8.4.3, and you are running 8.4.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But here is the change for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-24549"&gt;https://supportforums.cisco.com/docs/DOC-24549&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 15:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995020#M440753</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-18T15:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-global twice nat &gt;8.3</title>
      <link>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995021#M440754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank a lot for this informations.&lt;/P&gt;&lt;P&gt;It's very shame that this function running correctly on 8.2 version and now, in 8.3, 8.4, this fonction have need to add a route in gateway.&lt;/P&gt;&lt;P&gt;Have a nice day&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 15:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multi-global-twice-nat-gt-8-3/m-p/1995021#M440754</guid>
      <dc:creator>jerome.bordeau</dc:creator>
      <dc:date>2012-06-18T15:22:44Z</dc:date>
    </item>
  </channel>
</rss>

