<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static Port Address Translation 8.4 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869170#M490149</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes correct ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when these server initiate a connection by what IP they will go out.??/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 24 Dec 2011 19:21:11 GMT</pubDate>
    <dc:creator>estelamathew</dc:creator>
    <dc:date>2011-12-24T19:21:11Z</dc:date>
    <item>
      <title>Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869166#M490145</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the static Port Address Translation is bidirectional in 8.4 ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured static port address translation for the 2 server with same Public IP for the port 80 and 23. The strange thing is when they initiate a connection to the outside world they are allowed access to the internet as they are not included in the Dynamic Port address translation pool.&lt;/P&gt;&lt;P&gt;object network inside network.&lt;/P&gt;&lt;P&gt;subnet 192.168.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869166#M490145</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2019-03-11T22:06:23Z</dc:date>
    </item>
    <item>
      <title>Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869167#M490146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Please post your configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 16:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869167#M490146</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-12-24T16:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869168#M490147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ciscoasa(config-network-object)# sh running-config &lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.20.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.10.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;object network all&lt;/P&gt;&lt;P&gt; subnet 192.168.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network static&lt;/P&gt;&lt;P&gt; host 2.2.2.2&lt;/P&gt;&lt;P&gt;object network PAT&lt;/P&gt;&lt;P&gt; host 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 2.2.2.2 eq telnet &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 10.10.10.1 eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffered notifications&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;no failover&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network all&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic 192.168.20.5&lt;/P&gt;&lt;P&gt;object network static&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 3.3.3.3 service tcp telnet telnet &lt;/P&gt;&lt;P&gt;object network PAT&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 3.3.3.3 service tcp 8080 www &lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.20.2 1&lt;/P&gt;&lt;P&gt;route inside 2.2.2.0 255.255.255.0 192.168.10.2&lt;/P&gt;&lt;P&gt;route inside 10.10.10.0 255.255.255.0 192.168.10.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 19:00:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869168#M490147</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-24T19:00:14Z</dc:date>
    </item>
    <item>
      <title>Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869169#M490148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are doing port-forwarding, this kind of nat is just for inbound connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static will always be bi-directional, port-forwarding will be for communications innitiated on the lower security level interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 19:13:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869169#M490148</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-24T19:13:10Z</dc:date>
    </item>
    <item>
      <title>Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869170#M490149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes correct ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when these server initiate a connection by what IP they will go out.??/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 19:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869170#M490149</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-24T19:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869171#M490150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will use the PAT ip address : 192.168.20.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 19:37:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869171#M490150</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-24T19:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869172#M490151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my concern, this is what not happening just see the logs below. I just initiate a connection from these servers and it is successful though their addresses are not included in PAT pool, still they are going out, how come??????????????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh conn&lt;/P&gt;&lt;P&gt;1 in use, 10 most used&lt;/P&gt;&lt;P&gt;TCP outside 1.1.1.1:23 inside 10.10.10.1:14811, idle 0:00:12, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh xlate &lt;/P&gt;&lt;P&gt;2 in use, 4 most used&lt;/P&gt;&lt;P&gt;Flags: D - DNS, i - dynamic, r - portmap, s - static, I - identity, T - twice&lt;/P&gt;&lt;P&gt;TCP PAT from inside:2.2.2.2 23-23 to outside:3.3.3.3 23-23&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 0:41:35 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from inside:10.10.10.1 8080-8080 to outside:3.3.3.3 80-80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 0:02:29 timeout 0:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh local-host &lt;/P&gt;&lt;P&gt;Interface management: 0 active, 0 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;Interface inside: 1 active, 2 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;local host: &amp;lt;10.10.10.1&amp;gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 0/unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside 1.1.1.1:23 inside 10.10.10.1:14811, idle 0:01:01, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;Interface outside: 1 active, 5 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;local host: &amp;lt;1.1.1.1&amp;gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 0/unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside 1.1.1.1:23 inside 10.10.10.1:14811, idle 0:01:01, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 19:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869172#M490151</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-24T19:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869173#M490152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see what you are saying,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide the following packet-tracer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp 192.168.10.5 1025 4.2.2.2 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 20:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869173#M490152</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-24T20:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869174#M490153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;U need the captured packets, from inside to outside, if i m not wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did'nt understood the below line, i dont have the following IP's in my network, i hope it is an example.&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp 192.168.10.5 1025 4.2.2.2 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 20:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869174#M490153</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-24T20:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869175#M490154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will show us all the nat rules, acl, routes that the traffic for that host is hitting, of course is an example. you can use any host on that network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Dec 2011 20:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869175#M490154</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-24T20:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869176#M490155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dears&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet tracer for the Static port redirection server IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh conn &lt;/P&gt;&lt;P&gt;1 in use, 1 most used&lt;/P&gt;&lt;P&gt;TCP outside 1.1.1.1:23 inside 2.2.2.2:28826, idle 0:00:09, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh xlate&lt;/P&gt;&lt;P&gt;2 in use, 3 most used&lt;/P&gt;&lt;P&gt;Flags: D - DNS, i - dynamic, r - portmap, s - static, I - identity, T - twice&lt;/P&gt;&lt;P&gt;TCP PAT from inside:2.2.2.2 23-23 to outside:3.3.3.3 23-23&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 2:11:34 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from inside:10.10.10.1 8080-8080 to outside:3.3.3.3 80-80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 2:11:34 timeout 0:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh local-host &lt;/P&gt;&lt;P&gt;Interface management: 0 active, 0 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;Interface inside: 1 active, 2 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;local host: &amp;lt;2.2.2.2&amp;gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 0/unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside 1.1.1.1:23 inside 2.2.2.2:28826, idle 0:00:21, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;Interface outside: 1 active, 1 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;local host: &amp;lt;1.1.1.1&amp;gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 0/unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside 1.1.1.1:23 inside 2.2.2.2:28826, idle 0:00:21, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# packet-tracer input inside tcp 2.2.2.2 28826 1.1.1.1 23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found flow with id 15, using existing flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#####################################################################################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh conn &lt;/P&gt;&lt;P&gt;1 in use, 1 most used&lt;/P&gt;&lt;P&gt;TCP outside 1.1.1.1:23 inside 10.10.10.1:31862, idle 0:00:18, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh xlate &lt;/P&gt;&lt;P&gt;2 in use, 3 most used&lt;/P&gt;&lt;P&gt;Flags: D - DNS, i - dynamic, r - portmap, s - static, I - identity, T - twice&lt;/P&gt;&lt;P&gt;TCP PAT from inside:2.2.2.2 23-23 to outside:3.3.3.3 23-23&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 2:15:10 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from inside:10.10.10.1 8080-8080 to outside:3.3.3.3 80-80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 2:15:10 timeout 0:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh local-host &lt;/P&gt;&lt;P&gt;Interface management: 0 active, 0 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;Interface inside: 1 active, 2 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;local host: &amp;lt;10.10.10.1&amp;gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 0/unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside 1.1.1.1:23 inside 10.10.10.1:31862, idle 0:00:36, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;Interface outside: 1 active, 1 maximum active, 0 denied&lt;/P&gt;&lt;P&gt;local host: &amp;lt;1.1.1.1&amp;gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP flow count/limit = 1/unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP embryonic count to host = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP intercept watermark = unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flow count/limit = 0/unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Conn:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP outside 1.1.1.1:23 inside 10.10.10.1:31862, idle 0:00:36, bytes 149, flags UIO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# packet-tracer input inside tcp 10.10.10.1 31862 1.1.1.1 23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found flow with id 17, using existing flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 06:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869176#M490155</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-25T06:55:20Z</dc:date>
    </item>
    <item>
      <title>Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869177#M490159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Post full trace all phase.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 07:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869177#M490159</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-12-25T07:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869178#M490161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are using an exisiting flow for the packet tracer that is not what I am looking for.....&lt;/P&gt;&lt;P&gt;I want you to do the following packet tracer please!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp 10.10.10.1 1025 1.1.1.1 23&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 07:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869178#M490161</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-25T07:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869179#M490165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The source port what i m using is 23 and the destination is also 23 , Is it OK or i m wrong.Please correct if this is not enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In such case when i don't know the source port what i shld use. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# packet-tracer input inside tcp 2.2.2.2 23 1.1.1.1 23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network static&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 3.3.3.3 service tcp telnet telnet &lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 2.2.2.2/23 to 3.3.3.3/23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 2368, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 08:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869179#M490165</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-25T08:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869180#M490167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to use a random port, but for this monitoring purposes its okay, I saw what I was looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That traffic is hitting the static rule, seems like on ASA version 8.3 and prior the static port-forwarding will be taken biderectional.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you looking for just inbound connections or it is okay if its bi-derectional?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 18:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869180#M490167</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-25T18:22:46Z</dc:date>
    </item>
    <item>
      <title>Static Port Address Translation 8.4</title>
      <link>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869181#M490169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tx Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose if i m looking only inbound then what i have to do??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2011 19:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-port-address-translation-8-4/m-p/1869181#M490169</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-12-25T19:25:42Z</dc:date>
    </item>
  </channel>
</rss>

