<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Problem in PIX 525 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685943#M497414</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 525 configured with 3 interfaces (inside,outside,DMZ). This PIX is connected to a cisco core 4100R switch. I want to let a specific VLAN with a subnet (10.2.0.0) to remote desktop and ping the DMZ web and mail servers. However, after i created a dynamic NAT and access-list, users in this VLAN still not ping or RDP to the servers. Please check the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 192.168.1.11&lt;/P&gt;&lt;P&gt;global (dmz) 1 10.11.0.130-10.11.0.135 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.2.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit ip 10.2.0.0 255.255.0.0 10.11.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit icmp 10.2.0.0 255.255.0.0 10.11.0.0 255.255.0.0 echo&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit icmp 10.2.0.0 255.255.0.0 10.11.0.0 255.255.0.0 echo-reply&lt;/P&gt;&lt;P&gt;access-group outgoing in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ : 10.11.0.0/24&lt;/P&gt;&lt;P&gt;inside VLAN: 10.2.0.0/16&lt;/P&gt;&lt;P&gt;Web server: 10.11.0.13&lt;/P&gt;&lt;P&gt;Mail server: 10.11.0.12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please correct me if i am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:11:14 GMT</pubDate>
    <dc:creator>turbo_engine26</dc:creator>
    <dc:date>2020-02-21T09:11:14Z</dc:date>
    <item>
      <title>NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685943#M497414</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 525 configured with 3 interfaces (inside,outside,DMZ). This PIX is connected to a cisco core 4100R switch. I want to let a specific VLAN with a subnet (10.2.0.0) to remote desktop and ping the DMZ web and mail servers. However, after i created a dynamic NAT and access-list, users in this VLAN still not ping or RDP to the servers. Please check the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 192.168.1.11&lt;/P&gt;&lt;P&gt;global (dmz) 1 10.11.0.130-10.11.0.135 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.2.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit ip 10.2.0.0 255.255.0.0 10.11.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit icmp 10.2.0.0 255.255.0.0 10.11.0.0 255.255.0.0 echo&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit icmp 10.2.0.0 255.255.0.0 10.11.0.0 255.255.0.0 echo-reply&lt;/P&gt;&lt;P&gt;access-group outgoing in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ : 10.11.0.0/24&lt;/P&gt;&lt;P&gt;inside VLAN: 10.2.0.0/16&lt;/P&gt;&lt;P&gt;Web server: 10.11.0.13&lt;/P&gt;&lt;P&gt;Mail server: 10.11.0.12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please correct me if i am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:11:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685943#M497414</guid>
      <dc:creator>turbo_engine26</dc:creator>
      <dc:date>2020-02-21T09:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685944#M497415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration seems ok to me...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe, you can:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- try the command "clear xlate" which clears the translation table on your PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- make sure that you can RDP and ping your servers, EVEN if you are in the DMZ (try with a host in the DMZ)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Check PIX logs and verify that no packets are dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- No nat from the inside to the DMZ:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 10.2.0.0 10.2.0.0 netmask 255.255.0.0 0 0 and check if it works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe other people will have accurate suggestions...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to give us update about your case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2006 06:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685944#M497415</guid>
      <dc:creator>huynhkhay</dc:creator>
      <dc:date>2006-09-21T06:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685945#M497416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of code is this PIX running?   Your config looks ok with regards to traffic going from the inside to DMZ.  Depending on the version traffic may be treated differently.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2006 16:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685945#M497416</guid>
      <dc:creator>todh</dc:creator>
      <dc:date>2006-09-21T16:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685946#M497418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps this is because you are using a /16 mask in the ACLs, but in your global you are using a /24 mask....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2006 20:25:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685946#M497418</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2006-09-21T20:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685947#M497420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello walker,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, the mask in the access-list is not a real subnet mask but it's a wild card mask to identify between hosts and subnets and that's it. In global commands, the mask is the real subnet mask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My PIX is running OS 7.0(1) and i am really wondering why it's not working since my config is okay. And yes, i can RDP and ping the servers from a host in the DMZ too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2006 17:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685947#M497420</guid>
      <dc:creator>turbo_engine26</dc:creator>
      <dc:date>2006-09-22T17:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685948#M497422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;are there other ACL entries in your access-list thats applied to the inside interface?? assuming a security level of 100, all traffic to other interfaces should be allowed...w/o an ACL.&lt;/P&gt;&lt;P&gt;you probably dont need to nat when going from the inside to the dmz interface...as one other person suggested, just static nat  the 10.2.0.0 subnet to itself, or do it with a nat 0 command (which is what i use to get to my dmz).  i assume your pix knows how to get back to the 10.2.0.0 subnet?  (a ping from the pix to a 10.2.x.x host can confirm this).  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Sep 2006 03:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685948#M497422</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2006-09-24T03:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685949#M497424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to open the echo reply path from the dmz to the inside network, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming extended permit icmp 10.11.0.0 255.255.0.0 10.11.0.0 255.255.0.0 echo-reply &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group incoming in interface dmz &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;check if the routing ok or not, (route inside)...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the remote desktop, you can also check whether the service is running on the server or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps, please rate if it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Sep 2006 07:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685949#M497424</guid>
      <dc:creator>oabduo983</dc:creator>
      <dc:date>2006-09-24T07:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685950#M497425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello can you do a show conn detail when you are attempting to access the Terminal Server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;post the output plz ( hide real IP addresses if public )&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Sep 2006 13:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685950#M497425</guid>
      <dc:creator>fausto-oliveira</dc:creator>
      <dc:date>2006-09-24T13:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685951#M497427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello oabduo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes,i already opened the icmp echo reply path from dmz to inside and nothing new.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit icmp 10.11.0.0 255.255.0.0 10.2.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But thanks for your suggestion anyways &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope more suggestions are on my way soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turbo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Sep 2006 20:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685951#M497427</guid>
      <dc:creator>turbo_engine26</dc:creator>
      <dc:date>2006-09-24T20:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685952#M497429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Turbo, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice the destination which I have included in my extended access-list, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit icmp 10.11.0.0 255.255.0.0 10.11.0.0 255.255.0.0 echo-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is because when you access from a low security zone to a high security zone you need to access the translated IP not the actual IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please include that access-list... if confused include the following instead, just for testing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget the access-group command...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Sep 2006 06:55:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685952#M497429</guid>
      <dc:creator>oabduo983</dc:creator>
      <dc:date>2006-09-25T06:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685953#M497432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ..  you cold try this assuming security for the inside interface is higher that the security for the DMZ. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you enable the default policy map for providing application inspection. Make sure inspect icmp is present&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global-policy&lt;/P&gt;&lt;P&gt; class global-class&lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;  inspect icmp error &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect mgcp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect pptp &lt;/P&gt;&lt;P&gt;  inspect ctiqbe &lt;/P&gt;&lt;P&gt;  inspect snmp &lt;/P&gt;&lt;P&gt;  inspect http &lt;/P&gt;&lt;P&gt;  inspect icmp &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect ils &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect dns &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global-policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit icmp 10.2.0.0 255.255.0.0 10.11.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list outgoing extended permit tcp 10.2.0.0 255.255.0.0 10.11.0.0 255.255.255.0 eq 3389&lt;/P&gt;&lt;P&gt;access-group outgoing in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Inside_Out_nonat extended permit ip 10.2.0.0 255.255.0.0 10.11.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list Inside_Out_nonat &lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I hope it helps  ..  please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2006 04:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685953#M497432</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-09-26T04:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Problem in PIX 525</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685954#M497434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please allow me to explain once again. I want to RDP and ping the DMZ servers by their same ip addresses. i.e RDP/Ping to 10.11.0.12 (mail srv) and RDP/Ping to 10.11.0.13 (web srv). I used all the kind of NATs in the world but it still not working for sorry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the best way to RDP/Ping with the same servers addresses is the NAT exemption..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check this out!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Exempt extended permit ip 10.11.0.0 255.255.0.0 10.2.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;nat (dmz) 0 access-list Exempt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But,the problem still exist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turbo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Oct 2006 13:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-in-pix-525/m-p/685954#M497434</guid>
      <dc:creator>turbo_engine26</dc:creator>
      <dc:date>2006-10-02T13:19:49Z</dc:date>
    </item>
  </channel>
</rss>

