<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA NAT help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat-help/m-p/1900135#M457752</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me to understand!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an internet link from ISP whic is terminated in a router(say Fa 0/0). ISP have provided me a public ip pool for our use. we have configured one of the ip from this pool in other interface of the router(say Fa 0/1) and&amp;nbsp; ASA outside also in the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP---(Fa 0/0) RTR (Fa 0/1)---ASA----10.50.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we ping any inside ip with source as Fa 0/0 from router i am getting a reply. But when i ping the same with source as Fa 0/1 i am getting the below log in asa firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No translation group found for icmp src outside:x.x.x.x dst inside:10.50.x.x (type 8, code 0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But ping is success when we add static NAT command for 10.50.x.x to translate as 10.50.x.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.50.x.x 10.50.x.x netmask 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why i didnt get same log when i ping with source as Fa 0/0&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:46:49 GMT</pubDate>
    <dc:creator>uthayaman elangovan</dc:creator>
    <dc:date>2019-03-11T22:46:49Z</dc:date>
    <item>
      <title>ASA NAT help</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-help/m-p/1900135#M457752</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me to understand!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an internet link from ISP whic is terminated in a router(say Fa 0/0). ISP have provided me a public ip pool for our use. we have configured one of the ip from this pool in other interface of the router(say Fa 0/1) and&amp;nbsp; ASA outside also in the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP---(Fa 0/0) RTR (Fa 0/1)---ASA----10.50.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we ping any inside ip with source as Fa 0/0 from router i am getting a reply. But when i ping the same with source as Fa 0/1 i am getting the below log in asa firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No translation group found for icmp src outside:x.x.x.x dst inside:10.50.x.x (type 8, code 0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But ping is success when we add static NAT command for 10.50.x.x to translate as 10.50.x.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.50.x.x 10.50.x.x netmask 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why i didnt get same log when i ping with source as Fa 0/0&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-help/m-p/1900135#M457752</guid>
      <dc:creator>uthayaman elangovan</dc:creator>
      <dc:date>2019-03-11T22:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT help</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-help/m-p/1900136#M457753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont understand why you would need to ping your local LAN private address range IP addresses from public network? You can't use the local private IP addresses to connect to Internet anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also having no configuration attached I can't really say what the situation is on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log message itself says theres no translation configured for the traffic. So I guess you have some rule for the ISP link network (Fa0/0 -&amp;gt; ISP) but not for the address pool (Fa0/1 -&amp;gt; ASA)? Still doesnt make sense why you would need to ping inside hosts from outside with their original IP address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd imagine the syslog id of the message that you mentioned was the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;H3&gt; 305005 &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;A name="wp4770947"&gt;&lt;/A&gt;&lt;A name="wpxref25062"&gt;&lt;/A&gt;&lt;A name="wpxref20353"&gt;&lt;/A&gt;&lt;A name="wpxref24101"&gt;&lt;/A&gt;&lt;A name="wpmkr4770945"&gt;&lt;/A&gt;&lt;A name="wpmkr4770946"&gt;&lt;/A&gt;Error Message&amp;nbsp;&amp;nbsp;&amp;nbsp; %ASA-3-305005: No translation group found for &lt;EM&gt;protocol&lt;/EM&gt; src 
&lt;EM&gt;interface_name&lt;/EM&gt;&lt;EM style="font-style: italic;"&gt;: &lt;/EM&gt;source_address&lt;EM style="font-style: italic;"&gt;/&lt;/EM&gt;source_port dst &lt;EM&gt;interface_name&lt;/EM&gt;&lt;EM style="font-style: italic;"&gt;: 
&lt;/EM&gt;dest_address/&lt;EM&gt;dest_port
&lt;/EM&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt; &lt;A name="wp4770949"&gt;&lt;/A&gt;&lt;A name="wpmkr4770948"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Explanation&amp;nbsp;&amp;nbsp;&amp;nbsp; A packet does not match any of the outbound nat command rules. If NAT is not&amp;nbsp; configured for the specified source and destination systems, the message will be generated&amp;nbsp; frequently. &lt;/P&gt;
&lt;P&gt; &lt;A name="wp4770950"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Recommended Action&amp;nbsp;&amp;nbsp;&amp;nbsp; This message indicates a configuration error. If dynamic NAT is desired for the&amp;nbsp; source host, ensure that the &lt;STRONG&gt;nat&lt;/STRONG&gt; command matches the source IP address. If static NAT is desired for&amp;nbsp; the source host, ensure that the local IP address of the &lt;STRONG&gt;static&lt;/STRONG&gt; command matches. If no NAT is desired&amp;nbsp; for the source host, check the ACL bound to the NAT 0 ACL. &lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you copy/paste here all your basic ASA configurations while ofcourse changing the public IP addresses/passwords etc. if needed from the output. It would be easy to see then how the translations/traffic works on your ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 14:22:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-help/m-p/1900136#M457753</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-03-26T14:22:17Z</dc:date>
    </item>
  </channel>
</rss>

