<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I can not to connect to nated address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901158#M458464</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I corrected mistake which was found by Joseph, but it still not working&lt;/P&gt;&lt;P&gt;SO i did packet-tracer...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pna-tdc1# packet-tracer input intranet tcp 10.161.11.130 1025 10.164.32.15 80&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (service491,intranet) 10.164.32.15 10.173.1.242 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip service491 host 10.173.1.242 intranet any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.164.32.15&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 2&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface service491&lt;BR /&gt;Untranslate 10.164.32.15/0 to 10.173.1.242/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;access-group intranet-in in interface intranet&lt;BR /&gt;access-list intranet-in extended deny ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: intranet&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: service491&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;pna-tdc1#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Mar 2012 20:26:35 GMT</pubDate>
    <dc:creator>pslavkovsky</dc:creator>
    <dc:date>2012-03-06T20:26:35Z</dc:date>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901151#M458448</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;I have server with real address 10.173.1.242, i created static nat to address 10.164.32.15, but I can not to connect to address 10.164.32.15 from IP 10.161.111.130, here is config of ASA:&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.0(5)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;nameif intranet&lt;/P&gt;&lt;P&gt;security-level 30&lt;/P&gt;&lt;P&gt;ip address 10.164.241.1 255.255.255.0 standby 10.164.241.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;nameif cdi&lt;/P&gt;&lt;P&gt;security-level 80&lt;/P&gt;&lt;P&gt;ip address 10.173.241.1 255.255.255.0 standby 10.173.241.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.491&lt;/P&gt;&lt;P&gt;&amp;nbsp; vlan 491&lt;/P&gt;&lt;P&gt;nameif service491&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 10.173.1.241 255.255.255.0 standby 10.173.1.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.492&lt;/P&gt;&lt;P&gt;vlan 492&lt;/P&gt;&lt;P&gt;nameif service492&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 10.173.2.241 255.255.255.0 standby 10.173.2.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.493&lt;/P&gt;&lt;P&gt;vlan 493&lt;/P&gt;&lt;P&gt;nameif service493&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 10.173.3.241 255.255.255.0 standby 10.173.3.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.500&lt;/P&gt;&lt;P&gt;&amp;nbsp; vlan 500&lt;/P&gt;&lt;P&gt;nameif service500&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 10.173.0.241 255.255.255.0 standby 10.173.0.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2.550&lt;/P&gt;&lt;P&gt;vlan 550&lt;/P&gt;&lt;P&gt;nameif service550&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;description LAN Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa805-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;domain-name t-dc.sk&lt;/P&gt;&lt;P&gt;access-list cdi-in extended permit icmp any any log debugging&lt;/P&gt;&lt;P&gt;access-list cdi-in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list intranet-in extended permit ip 10.161.111.0 255.255.255.0 host 10.0.0.0 log debugging&lt;/P&gt;&lt;P&gt;access-list intranet-in extended permit ip 10.164.32.0 255.255.255.0 host 10.0.0.0 log debugging&lt;/P&gt;&lt;P&gt;access-list intranet-in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list service491-in extended permit icmp any any log debugging&lt;/P&gt;&lt;P&gt;access-list service491-in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list service492-in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list service493-in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list service500-in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list service550-in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list cap extended permit ip any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging asdm debugging&lt;/P&gt;&lt;P&gt;logging host service491 10.173.1.242&lt;/P&gt;&lt;P&gt;mtu intranet 1500&lt;/P&gt;&lt;P&gt;mtu cdi 1500&lt;/P&gt;&lt;P&gt;mtu service491 1500&lt;/P&gt;&lt;P&gt;mtu service492 1500&lt;/P&gt;&lt;P&gt;mtu service493 1500&lt;/P&gt;&lt;P&gt;mtu service500 1500&lt;/P&gt;&lt;P&gt;mtu service550 1500&lt;/P&gt;&lt;P&gt;mtu mngmt 1500&lt;/P&gt;&lt;P&gt;ip local pool pool1 10.31.250.129-10.31.250.255 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip failover 172.16.10.1 255.255.255.252 standby 172.16.10.2&lt;/P&gt;&lt;P&gt;no monitor-interface intranet&lt;/P&gt;&lt;P&gt;no monitor-interface cdi&lt;/P&gt;&lt;P&gt;no monitor-interface mngmt&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any intranet&lt;/P&gt;&lt;P&gt;icmp permit any cdi&lt;/P&gt;&lt;P&gt;icmp permit any service491&lt;/P&gt;&lt;P&gt;icmp permit any service492&lt;/P&gt;&lt;P&gt;icmp permit any service493&lt;/P&gt;&lt;P&gt;icmp permit any service500&lt;/P&gt;&lt;P&gt;icmp permit any service550&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-647.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;static (service491,intranet) 10.164.32.15 10.173.1.242 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group intranet-in in interface intranet&lt;/P&gt;&lt;P&gt;access-group cdi-in in interface cdi&lt;/P&gt;&lt;P&gt;access-group service491-in in interface service491&lt;/P&gt;&lt;P&gt;access-group service492-in in interface service492&lt;/P&gt;&lt;P&gt;access-group service493-in in interface service493&lt;/P&gt;&lt;P&gt;access-group service500-in in interface service500&lt;/P&gt;&lt;P&gt;access-group service550-in in interface service550&lt;/P&gt;&lt;P&gt;route intranet 0.0.0.0 0.0.0.0 10.164.241.5 1&lt;/P&gt;&lt;P&gt;route cdi 10.97.0.0 255.255.0.0 10.173.241.5 1&lt;/P&gt;&lt;P&gt;route cdi 10.168.0.0 255.255.0.0 10.173.241.5 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto ca trustpoint localtrust&lt;/P&gt;&lt;P&gt;enrollment self&lt;/P&gt;&lt;P&gt;fqdn sslvpn.t-dc.sk&lt;/P&gt;&lt;P&gt;keypair sslvpnkeypair&lt;/P&gt;&lt;P&gt;crl configure&lt;/P&gt;&lt;P&gt;crypto ca certificate chain localtrust&lt;/P&gt;&lt;P&gt;certificate c116474f&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 308201e7 30820150 a0030201 020204c1 16474f30 0d06092a 864886f7 0d010104&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; bce 90a3424e&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; f9f040e2 95c69b91 779b8a&lt;/P&gt;&lt;P&gt;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;no crypto isakmp nat-traversal&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;ssl trust-point localtrust intranet&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;enable intranet&lt;/P&gt;&lt;P&gt;svc image disk0:/anyconnect-win-2.5.3055-k9.pkg 1&lt;/P&gt;&lt;P&gt;svc enable&lt;/P&gt;&lt;P&gt;group-policy GrpPolicy-ssl1 internal&lt;/P&gt;&lt;P&gt;group-policy GrpPolicy-ssl1 attributes&lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol svc&lt;/P&gt;&lt;P&gt;tunnel-group ssl1 type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group ssl1 general-attributes&lt;/P&gt;&lt;P&gt;address-pool pool1&lt;/P&gt;&lt;P&gt;default-group-policy GrpPolicy-ssl1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:be82cd121bde8e5de3981453caa201f0&lt;/P&gt;&lt;P&gt;: end&lt;SPAN id="mce_marker"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901151#M458448</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2019-03-11T22:38:47Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901152#M458450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you seeing any deny's in the log files?&amp;nbsp; This kind of smells like someting is being denyed from the access lists.&amp;nbsp; Also, where does the 10.161.111.X network reside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 17:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901152#M458450</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2012-03-06T17:15:24Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901153#M458451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi, &lt;/P&gt;&lt;P&gt;I see no denys in logg.&lt;/P&gt;&lt;P&gt;10.161.111. is on intranet interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 17:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901153#M458451</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T17:18:19Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901154#M458454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried running a packet capture while trying to connect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 17:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901154#M458454</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2012-03-06T17:31:23Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901155#M458457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; yes, I tried capture on intranet interfacem but I did not see any packet.&lt;/P&gt;&lt;P&gt;But I have no problem to connect intranet interface of ASA via ASDM&lt;/P&gt;&lt;P&gt;Peter &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 17:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901155#M458457</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T17:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901156#M458459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;access-list intranet-in extended permit ip 10.161.111.0 255.255.255.0 host 10.0.0.0 log debugging&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;access-list intranet-in extended permit ip 10.164.32.0 255.255.255.0 host 10.0.0.0 log debugging&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;access-list intranet-in extended deny ip any any&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're permitting access to 10.0.0.0 but you're using the 'host' keyword. This is causing a 255.255.255.255 mask which isn't going to allow what you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try adding this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list intranet-in extended permit ip 10.161.111.0 255.255.255.0 host 10.164.32.15&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 19:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901156#M458459</guid>
      <dc:creator>johuggin</dc:creator>
      <dc:date>2012-03-06T19:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901157#M458462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joseph advise should do it... If by any chance that does not make it please add the following and provide us the output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input intranet tcp 10.161.11.1130 1025 10.164.32.15 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 20:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901157#M458462</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-03-06T20:09:19Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901158#M458464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I corrected mistake which was found by Joseph, but it still not working&lt;/P&gt;&lt;P&gt;SO i did packet-tracer...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pna-tdc1# packet-tracer input intranet tcp 10.161.11.130 1025 10.164.32.15 80&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (service491,intranet) 10.164.32.15 10.173.1.242 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip service491 host 10.173.1.242 intranet any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.164.32.15&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 2&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface service491&lt;BR /&gt;Untranslate 10.164.32.15/0 to 10.173.1.242/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;access-group intranet-in in interface intranet&lt;BR /&gt;access-list intranet-in extended deny ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: intranet&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: service491&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;pna-tdc1#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 20:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901158#M458464</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T20:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901159#M458465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;Please remove this line and check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list intranet-in extended deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Coz, in phase 4 it is showing &lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more quest where is the IP &lt;/P&gt;&lt;P&gt;10.164.32.15 belongs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 20:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901159#M458465</guid>
      <dc:creator>Sajan Thomas</dc:creator>
      <dc:date>2012-03-06T20:40:36Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901160#M458466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have no account on server so I can not to ping from server.&lt;/P&gt;&lt;P&gt;I removed &lt;/P&gt;&lt;P&gt;access-list intranet-in extended deny ip any any&lt;/P&gt;&lt;P&gt;but it is stiil the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you think about phase3&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (service491,intranet) 10.164.32.15 10.173.1.242 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip service491 host 10.173.1.242 intranet any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.164.32.15&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 2&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface service491&lt;BR /&gt;&lt;STRONG&gt;Untranslate 10.164.32.15/0 to 10.173.1.242/0 using netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 20:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901160#M458466</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T20:48:59Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901161#M458468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i corrected "packet-tracer..." there was mistake,&amp;nbsp; 10.161.11.130 instead 10.161.111.130&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pna-tdc1# packet-tracer input intranet tcp 10.161.111.130 1025 10.164.32.15 22&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (service491,intranet) 10.164.32.15 10.173.1.242 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip service491 host 10.173.1.242 intranet any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.164.32.15&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 4&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface service491&lt;BR /&gt;Untranslate 10.164.32.15/0 to 10.173.1.242/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group intranet-in in interface intranet&lt;BR /&gt;access-list intranet-in extended permit ip 10.161.111.0 255.255.255.0 10.0.0.0 255.0.0.0 log debugging&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (service491,intranet) 10.164.32.15 10.173.1.242 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip service491 host 10.173.1.242 intranet any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.164.32.15&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 4&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (service491,intranet) 10.164.32.15 10.173.1.242 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip service491 host 10.173.1.242 intranet any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.164.32.15&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 4&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 2956, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: output and adjacency&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.173.1.242 using egress ifc service491&lt;BR /&gt;adjacency Active&lt;BR /&gt;next-hop mac address 0014.4fed.bb6c hits 41&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: intranet&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: service491&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;pna-tdc1#&lt;BR /&gt;pna-tdc1#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 21:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901161#M458468</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T21:11:48Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901162#M458470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; router which is in front of ASA has this in arp cache:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router#sh arp | i&amp;nbsp; 10.164.32.15&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 10.164.32.15&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; Incomplete&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ARPA&lt;/P&gt;&lt;P&gt;router#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 21:21:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901162#M458470</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T21:21:56Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901163#M458471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; it looks that router can not to reslove 10.164.32.15 to MAC address via arp request. What do you think?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 21:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901163#M458471</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T21:26:21Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901164#M458474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct, that seems to be the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now on the packet-tracer we can see that everything is properly configured on the ASA site ( the NAT, ACLs,inspections, etc) is properly configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a route from the router to that ip via the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 21:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901164#M458474</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-03-06T21:37:20Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901165#M458476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;router#sh ip route | i 10.164.32.0&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.164.32.0/24 is directly connected, GigabitEthernet0/0.2&lt;/P&gt;&lt;P&gt;router#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 21:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901165#M458476</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T21:40:41Z</dc:date>
    </item>
    <item>
      <title>I can not to connect to nated address</title>
      <link>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901166#M458477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; it is resolved. thank you all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 22:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-can-not-to-connect-to-nated-address/m-p/1901166#M458477</guid>
      <dc:creator>pslavkovsky</dc:creator>
      <dc:date>2012-03-06T22:29:01Z</dc:date>
    </item>
  </channel>
</rss>

