<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic new to ASA 8.4 issue with asymmetric nat rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887841#M457073</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Surely someone out there can assist me with this. I see plenty of other asymmetric NAT posts receiving plenty of replies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Come on gurus, show us your stuff. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Apr 2012 23:21:17 GMT</pubDate>
    <dc:creator>James Smith</dc:creator>
    <dc:date>2012-04-17T23:21:17Z</dc:date>
    <item>
      <title>new to ASA 8.4 issue with asymmetric nat rules</title>
      <link>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887840#M457070</link>
      <description>&lt;P&gt;G'day All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am have just completed my first ASA install using 8.4 software, I was ok with 8.2 and prior for NAT, but I am running into an issue with the 8.4 setup. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 5585 that is running multiple contexts, one of the contexts connects to a cisco wlc on it's inside interface. Wireless users are able to associate to the wlan fine, but their dhcp server is upstream on the outside of the asa. My issue is when clients attempt to grab a dhcp address, the dhcp offer is being dropped by the firewall due to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Courier;"&gt;%ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for udp src outside:192.168.200.84/67 dst inside:192.168.79.14/67 denied due to NAT reverse path failure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The dhcp server is upstream and is 192.168.200.84 and 192.168.79.14 is the wlan interface on the wlc. Can someone please have a look over my config and advise where I am going wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the complete config for the context, keep in mind that this is only in test at the moment and is presently completely private, there is no public access presently. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;asa/test# sh run&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;: Saved&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;:&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;ASA Version 8.4(1) &amp;lt;context&amp;gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;hostname test&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;enable password *********** encrypted&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;passwd ********** encrypted&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;names&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;interface outside_test&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;nameif outside&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;security-level 0&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;ip address 192.168.207.91 255.255.255.248 &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;interface inside_test&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;nameif inside&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;security-level 100&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;ip address 192.168.79.125 255.255.255.128 &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;interface radtest&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;nameif radtest&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;security-level 50&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;ip address 10.1.0.251 255.255.255.248 &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;object network test-inside &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;subnet 192.168.79.0 255.255.255.128&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;object-group network radtest&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;network-object 10.1.0.181 255.255.255.255&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;network-object 10.1.0.213 255.255.255.255&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;object-group network out-rad&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;network-object 192.168.15.68 255.255.255.255&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;network-object 192.168.15.69 255.255.255.255&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;object-group service radius_ports udp&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;port-object range radius radius-acct&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;port-object range 1812 1813&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;access-list outside-in extended permit ip any any &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;access-list radtes-tin extended permit ip any any &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;access-list inside-in extended permit ip any any &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;pager lines 24&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;logging enable&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;logging buffered debuggin&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;mtu outside 1500&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;mtu inside 1500&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;mtu apnet 1500&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;no asdm history enable&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;arp timeout 14400&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;object network test-inside&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;object network radtest&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;nat(radtest,outside) dynamic interface&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;access-group outside-in in interface outside&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;access-group inside-in in interface inside&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;access-group radtest-in in interface radtest&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;route outside 0.0.0.0 0.0.0.0 192.168.207.89 1&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;route apnet 10.1.0.181 255.255.255.255 10.1.0.249 1&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;route apnet 10.1.0.213 255.255.255.255 10.1.0.249 1&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;no snmp-server location&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;no snmp-server contact&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;telnet timeout 5&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;ssh timeout 5&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;class-map inspection_default&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;match default-inspection-traffic&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;parameters&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;policy-map global_policy&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;class inspection_default&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect h323 h22&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;!&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;service-policy global_policy global&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;Cryptochecksum:98edfeccab777266691c489212987947&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;Thanks for any assistance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica;"&gt;JS&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887840#M457070</guid>
      <dc:creator>James Smith</dc:creator>
      <dc:date>2019-03-11T22:53:27Z</dc:date>
    </item>
    <item>
      <title>new to ASA 8.4 issue with asymmetric nat rules</title>
      <link>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887841#M457073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Surely someone out there can assist me with this. I see plenty of other asymmetric NAT posts receiving plenty of replies. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Come on gurus, show us your stuff. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 23:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887841#M457073</guid>
      <dc:creator>James Smith</dc:creator>
      <dc:date>2012-04-17T23:21:17Z</dc:date>
    </item>
    <item>
      <title>new to ASA 8.4 issue with asymmetric nat rules</title>
      <link>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887842#M457077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this article describes what you are seeing &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-12569"&gt;https://supportforums.cisco.com/docs/DOC-12569&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2012 06:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887842#M457077</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2012-04-18T06:13:57Z</dc:date>
    </item>
    <item>
      <title>new to ASA 8.4 issue with asymmetric nat rules</title>
      <link>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887843#M457083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I addition to this, I think the problem that you are having is that your DHCP server is directing traffic for your WLC (&lt;/P&gt;&lt;P&gt;192.168.79.14) to your ASA, well at least that is what your output shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for udp src outside:192.168.200.84/67 dst inside:192.168.79.14/67 denied due to NAT reverse path failure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So although you are directing traffic to&amp;nbsp; 192.168.79.14&amp;nbsp;&amp;nbsp; that IP address will never be presented out the outside interface, because it is hidden behind dynamic NAT:&amp;nbsp; &lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so how is your DHCP server sending offers to the real IP address of the WLC, rather then the NAT-ed IP address (&lt;/P&gt;&lt;P&gt;192.168.207.91)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2012 07:04:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887843#M457083</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2012-04-18T07:04:55Z</dc:date>
    </item>
    <item>
      <title>new to ASA 8.4 issue with asymmetric nat rules</title>
      <link>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887844#M457089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;G'day All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turns out I had a number of configuration issues, I got these resolved with the help of the members that replied. Much appreciated for the assistance and my new found working understanding on NAT in 8.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 06:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-to-asa-8-4-issue-with-asymmetric-nat-rules/m-p/1887844#M457089</guid>
      <dc:creator>James Smith</dc:creator>
      <dc:date>2012-05-16T06:23:49Z</dc:date>
    </item>
  </channel>
</rss>

