<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static PAT issue with 8.4 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849811#M459129</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Lee,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear everything is working now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just in case the one option I gave you should be like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;nat (inside,outside) 1 source static LD-App01 interface service https&amp;nbsp;&amp;nbsp; https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Feb 2012 17:24:58 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-02-20T17:24:58Z</dc:date>
    <item>
      <title>Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849803#M459121</link>
      <description>&lt;P&gt;I have a simple small network setup here, and trying to setup a simple Static PAT on HTTPS, for some reason the NAT rule is dropping the packet.&amp;nbsp; Here is the setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal Subnet: 172.31.0.0/24&lt;/P&gt;&lt;P&gt;External Internet DHCP&lt;/P&gt;&lt;P&gt;Host object: 172.31.0.13&lt;/P&gt;&lt;P&gt;There is also a SSL anyconnect VPN setup but is using port 444.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any-01&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network LD-App01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp https https&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,any) after-auto source static obj-172.31.0.0 obj-172.31.0.0 destination static Personal-VPN Personal-VPN no-proxy-arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-172.31.0.0&lt;/P&gt;&lt;P&gt; subnet 172.31.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network Personal-VPN&lt;/P&gt;&lt;P&gt; subnet 172.31.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj_any-01&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network LD-App01&lt;/P&gt;&lt;P&gt; host 172.31.0.13&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 172.31.0.0 255.255.255.0 object Personal-VPN&lt;/P&gt;&lt;P&gt;access-list Personal-VPN-ACL standard permit 172.31.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object LD-App01 eq https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the packet trace&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 172.31.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object LD-App01 eq https&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: HOST-LIMIT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network LD-App01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp https https&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Help...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849803#M459121</guid>
      <dc:creator>Lee Breinich</dc:creator>
      <dc:date>2019-03-11T22:32:09Z</dc:date>
    </item>
    <item>
      <title>Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849804#M459122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Lee,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuaration looks good to me, I would make the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network outside_interface_ip&lt;/P&gt;&lt;P&gt;host x.x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object service https&lt;/P&gt;&lt;P&gt;service tcp source eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network LD-App01&lt;/P&gt;&lt;P&gt;no&amp;nbsp; nat (inside,outside) static interface service tcp https https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) 1 source static LD-App01 outside_interface_ip service https&amp;nbsp;&amp;nbsp; https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Give it a try and let me know regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 21:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849804#M459122</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-19T21:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849805#M459123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried your recomendation but ran into a error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created the object outside_int_ip with the outside ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then tried to create the nat as you have listed but got the following error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside)1 source static LD-App01 outside_int_ip service https https&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;LD-FW01(config-network-object)# nat (inside,outside) 1 source static LD-App01 $&lt;/P&gt;&lt;P&gt;ERROR: Address 75.188.84.144 overlaps with outside interface address.&lt;/P&gt;&lt;P&gt;ERROR: NAT Policy is not downloaded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849805#M459123</guid>
      <dc:creator>Lee Breinich</dc:creator>
      <dc:date>2012-02-19T22:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849806#M459124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Lee,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should not have failed!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You placed the object right, not the Ip?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849806#M459124</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-19T22:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849807#M459125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the current object list and the nat command with the failure message.&amp;nbsp; I'm also running the current 8.4(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LD-FW01# show run ob&lt;/P&gt;&lt;P&gt;object network obj-172.31.0.0&lt;/P&gt;&lt;P&gt; subnet 172.31.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network Personal-VPN&lt;/P&gt;&lt;P&gt; subnet 172.31.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj_any-01&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network LD-App01&lt;/P&gt;&lt;P&gt; host 172.31.0.13&lt;/P&gt;&lt;P&gt; description Spiceworks&lt;/P&gt;&lt;P&gt;object service https&lt;/P&gt;&lt;P&gt; service tcp source eq https&lt;/P&gt;&lt;P&gt;object network outside_int_ip&lt;/P&gt;&lt;P&gt; host 76.188.84.144&lt;/P&gt;&lt;P&gt;LD-FW01# con t&lt;/P&gt;&lt;P&gt;LD-FW01(config)# object network LD-App01&lt;/P&gt;&lt;P&gt;LD-FW01(config-network-object)# nat (inside,outside) 1 source static LD-App01 $&lt;/P&gt;&lt;P&gt;ERROR: Address 75.188.84.144 overlaps with outside interface address.&lt;/P&gt;&lt;P&gt;ERROR: NAT Policy is not downloaded&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849807#M459125</guid>
      <dc:creator>Lee Breinich</dc:creator>
      <dc:date>2012-02-19T22:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849808#M459126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to do it outside the object network that is the problem!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So just by being on config te add the nat command&amp;nbsp; I gave you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849808#M459126</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-19T22:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849809#M459127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;still getting the same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LD-FW01(config)# nat (inside,outside) 1 source static LD-App01 outside_int_ip $&lt;/P&gt;&lt;P&gt;ERROR: Address 75.188.84.144 overlaps with outside interface address.&lt;/P&gt;&lt;P&gt;ERROR: NAT Policy is not downloaded&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Feb 2012 22:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849809#M459127</guid>
      <dc:creator>Lee Breinich</dc:creator>
      <dc:date>2012-02-19T22:36:00Z</dc:date>
    </item>
    <item>
      <title>Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849810#M459128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For Julio and anyone else who may read this.&amp;nbsp; The origional config I posted worked just fine though for some reason the NAT in the packet trace still shows as being dropped.&amp;nbsp; The actual issue is that the server I was Natting to closed the 443 (https) port for some reason.&amp;nbsp; As soon as I fixed the port issue on the server, I was able to NAT correctly through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 13:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849810#M459128</guid>
      <dc:creator>Lee Breinich</dc:creator>
      <dc:date>2012-02-20T13:54:43Z</dc:date>
    </item>
    <item>
      <title>Static PAT issue with 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849811#M459129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Lee,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear everything is working now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just in case the one option I gave you should be like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;nat (inside,outside) 1 source static LD-App01 interface service https&amp;nbsp;&amp;nbsp; https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 17:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-issue-with-8-4/m-p/1849811#M459129</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-20T17:24:58Z</dc:date>
    </item>
  </channel>
</rss>

