<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static Nat on ASA 5510 IOS version 8.2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859356#M459071</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's allowing the packets in and out that's working fine but my issue is, for reverse DNS on the mail server, traffic originating from internal ip x.x.x.20 on 25 is showing as if it's coming from the Firewall external IP which is x.x.x.253 instead of x.x.x.150. I want traffic coming from the internal IP x.x.x.20 to be natted and goes out via it's nated public IP x.x.x.150 and not the firewall external IP x.x.x.253&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Feb 2012 08:29:19 GMT</pubDate>
    <dc:creator>chigumbab</dc:creator>
    <dc:date>2012-02-21T08:29:19Z</dc:date>
    <item>
      <title>Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859350#M459062</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have a question. I have a ASA5510 with IOS version 8.2 . I have my firewall and behind it also have a mail server eg 192.168.1.x. When i send email from inside network it doesn't show as if it's coming grom the out side nated public IP of my server but IP of firewall. What am i missing my example nat statements are . Nat-control is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 196.68.99.x 192.168.1.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list inbound extended permit tcp any host 196.68.99.x eq 225&lt;/P&gt;&lt;P&gt;accesslist outbound extended permit host 192.168.1.x host 196.68.99.x&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859350#M459062</guid>
      <dc:creator>chigumbab</dc:creator>
      <dc:date>2019-03-11T22:32:54Z</dc:date>
    </item>
    <item>
      <title>Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859351#M459063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need 'accesslist outbound extended permit host 192.168.1.x host 196.68.99.x'. Remove this and clear the existing translate for the internal IP (clear xlate local 192.168.1.x) and see if that fix the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 02:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859351#M459063</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2012-02-21T02:44:41Z</dc:date>
    </item>
    <item>
      <title>Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859352#M459064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the reply. I tried that but it didn't work. What else do you suggest i try?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 06:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859352#M459064</guid>
      <dc:creator>chigumbab</dc:creator>
      <dc:date>2012-02-21T06:52:37Z</dc:date>
    </item>
    <item>
      <title>Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859353#M459065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you provide me the output of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 4.2.2.2 23456 196.68.99.x 80&amp;nbsp; detailed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and also can you provide the running config from the ASA, you can hide the ip's if you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 07:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859353#M459065</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-02-21T07:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859354#M459067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are you man. We meet again. Thank you so much for your help last time. Please find attached the partial configs. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 08:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859354#M459067</guid>
      <dc:creator>chigumbab</dc:creator>
      <dc:date>2012-02-21T08:06:48Z</dc:date>
    </item>
    <item>
      <title>Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859355#M459069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Chigumbab,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its nice to see you after a while as well &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the packet tracer and it is allowing all the packets, are all the ports not working or only some specific??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you take captures on the asa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cap permit tcp host xx.xx.xx.150 any&lt;/P&gt;&lt;P&gt;access-list cap permit tcp any host xx.xx.xx.150&lt;/P&gt;&lt;P&gt;access-list cap permit tcp any host xx.xx.xx.20&lt;/P&gt;&lt;P&gt;access-list cap permit tcp host xx.xx.xx.20 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capin access-list cap interface inside&lt;/P&gt;&lt;P&gt;capture capo access-list cap interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then generate some traffic and collect the output of "show cap capin" and "show cap capo"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be interesting to see where the packets are being dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 08:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859355#M459069</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-02-21T08:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859356#M459071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's allowing the packets in and out that's working fine but my issue is, for reverse DNS on the mail server, traffic originating from internal ip x.x.x.20 on 25 is showing as if it's coming from the Firewall external IP which is x.x.x.253 instead of x.x.x.150. I want traffic coming from the internal IP x.x.x.20 to be natted and goes out via it's nated public IP x.x.x.150 and not the firewall external IP x.x.x.253&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 08:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859356#M459071</guid>
      <dc:creator>chigumbab</dc:creator>
      <dc:date>2012-02-21T08:29:19Z</dc:date>
    </item>
    <item>
      <title>Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859357#M459073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chigumbab,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nope that would not work, because you have just done port forwarding and allowed only specfic ports on the xx.xx.xx.150 ip address, so the DNS traffic would definitely be natted to the outside interface, because of the nat-global statements that you have, just as a workaround add the statement at the end of all the statics :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp x.x.x.150 smtp x.x.x.20 smtp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp x.x.x.150 587 x.x.x.20 587 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp x.x.x.150 pop3 x.x.x.20 pop3 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp x.x.x.150 3389 x.x.x.20 3389 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp x.x.x.150 1433 x.x.x.20 1433 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp x.x.x.150 3306 x.x.x.20 3306 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.x.150 x.x.x.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and now if the server goes to the internet, it should show the IP x.x.x.150&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't worry it would not allow any other ports to be opened as you have restricted the incoming ports through the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 08:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859357#M459073</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-02-21T08:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859358#M459075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Varun, you are the man!!!!!!! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 09:06:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859358#M459075</guid>
      <dc:creator>chigumbab</dc:creator>
      <dc:date>2012-02-21T09:06:25Z</dc:date>
    </item>
    <item>
      <title>Static Nat on ASA 5510 IOS version 8.2</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859359#M459077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey thats great!!!! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; hope to see you soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 09:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-on-asa-5510-ios-version-8-2/m-p/1859359#M459077</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-02-21T09:08:05Z</dc:date>
    </item>
  </channel>
</rss>

