<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 8.3+ NAT/ACL problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745532#M495389</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for your answer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 2.2.2.2 is above 2.2.2.3 (2.2.2.2 is NAT Rule, 2.2.2.3 is Network Object NAT Rule)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For security reasons I can't post the entire conf.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could we use translated address in ACL, like in pre-8.3 releases ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Oct 2011 10:01:17 GMT</pubDate>
    <dc:creator>Kooopobol</dc:creator>
    <dc:date>2011-10-18T10:01:17Z</dc:date>
    <item>
      <title>ASA 8.3+ NAT/ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745530#M495387</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the 8.3 release, addresses used in ACL have to be untranslated ones.&lt;/P&gt;&lt;P&gt;But it is not compatible with our configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I explain :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2 static NAT rules :&lt;/P&gt;&lt;P&gt;- (Static Policy) MyHost is converted to 2.2.2.2 when the destination is X&lt;/P&gt;&lt;P&gt;- (Static) MyHost is converted to 2.2.2.3 for all others destinations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 8.2.2 we had an ACL which authorized ICMP from X to 2.2.2.2 (X for source and 2.2.2.2 for destination in Access Rule)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, in 8.4.2, we have to use MyHost instead of 2.2.2.2. (X for source and MyHost for destination in Access Rule)&lt;/P&gt;&lt;P&gt;The problem is that &lt;STRONG&gt;MyHost automatically corresponds to 2.2.2.3, not 2.2.2.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the ICMP is authorized from X to 2.2.2.3, not 2.2.2.2...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any trick to bypass this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745530#M495387</guid>
      <dc:creator>Kooopobol</dc:creator>
      <dc:date>2019-03-11T21:39:11Z</dc:date>
    </item>
    <item>
      <title>ASA 8.3+ NAT/ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745531#M495388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the config, we can have a look at it and will suggest you the right configuration for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure that the nat rule for 2.2.2.2 is above the nat rule for 2.2.2.3 in the nat order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 08:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745531#M495388</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-18T08:33:40Z</dc:date>
    </item>
    <item>
      <title>ASA 8.3+ NAT/ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745532#M495389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for your answer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 2.2.2.2 is above 2.2.2.3 (2.2.2.2 is NAT Rule, 2.2.2.3 is Network Object NAT Rule)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For security reasons I can't post the entire conf.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could we use translated address in ACL, like in pre-8.3 releases ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 10:01:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745532#M495389</guid>
      <dc:creator>Kooopobol</dc:creator>
      <dc:date>2011-10-18T10:01:17Z</dc:date>
    </item>
    <item>
      <title>ASA 8.3+ NAT/ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745533#M495390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No in Post 8.3 configuration you only need to use real ip's rather than trranslated ip's. Could you just explauin me the complete traffic flow, like bnehind whihc interface is the soutrce from where you are pinging and behind whihc interface is the destination. If need be, I'll suggest you the natting for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 10:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745533#M495390</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-18T10:13:15Z</dc:date>
    </item>
    <item>
      <title>ASA 8.3+ NAT/ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745534#M495391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are two interfaces : Inside and outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MyHost is a Network Object corresponding to 192.168.1.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two static NAT Rules :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- One which translates MyHost to 2.2.2.2 when the destination of the packet is X [ from inside to outside] &lt;/P&gt;&lt;P&gt;- One which translates MyHost to 2.2.2.3 no matter the destination [from inside to outside] &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.2.2.2 rule is above 2.2.2.3 one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the Access Rules :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On interface outside (inbounds connections) :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Permit ICMP from X to 2.2.2.2&lt;/P&gt;&lt;P&gt;Permit SSH from X to 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like I said in 8.4.2 we have to use MyHost instead of 2.2.2.2 in Access Rules, but MyHost automatically corresponds to 2.2.2.3 translated address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2011 07:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745534#M495391</guid>
      <dc:creator>Kooopobol</dc:creator>
      <dc:date>2011-10-19T07:59:13Z</dc:date>
    </item>
    <item>
      <title>ASA 8.3+ NAT/ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745535#M495392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Armand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this nat statement in teh same order:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (outside,inside) source static X X destination static obj-2.2.2.2 MyHost &lt;/P&gt;&lt;P&gt;nat (outside,inside) source static any any destination static obj-2.2.2.3 MyHost&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear local-host 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2011 18:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-nat-acl-problem/m-p/1745535#M495392</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-19T18:10:20Z</dc:date>
    </item>
  </channel>
</rss>

