<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: portmap translation creation failed for tcp src inside:192.1 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745564#M529899</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I today was having the same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Who doing hairpining NAT on a tcp port, to and from the same interface. Why is it that you need global (dmz4) 101 interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Jun 2013 21:12:09 GMT</pubDate>
    <dc:creator>John Peterson</dc:creator>
    <dc:date>2013-06-12T21:12:09Z</dc:date>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.91.35/32483 dst dmz4:10.10.7.21/443</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745553#M529884</link>
      <description>&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;﻿Hello all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having an issue where clients at remote sites can not access website in our dmz.&amp;nbsp; Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745553#M529884</guid>
      <dc:creator>Matthew Michaluk</dc:creator>
      <dc:date>2019-03-11T21:30:18Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745554#M529885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Matthew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which interface do the clients use to get to the DMZ (looks like the inside interface from your post ?) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the clients use VPN or is it just normal traffic ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a NAT statement setup for the client traffic to the DMZ ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 21:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745554#M529885</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-09-26T21:20:13Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745555#M529886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normal traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz4) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 21:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745555#M529886</guid>
      <dc:creator>Matthew Michaluk</dc:creator>
      <dc:date>2011-09-26T21:32:11Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745556#M529887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls. share the output of "sh run nat" and "sh run global"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 00:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745556#M529887</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-09-27T00:01:02Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745557#M529888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; sh run nat&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (dmz4) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (dmz3) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt; sh run global&lt;/P&gt;&lt;P&gt;global (outside) 101 207.40.1.252 netmask 255.255.255.255&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 14:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745557#M529888</guid>
      <dc:creator>Matthew Michaluk</dc:creator>
      <dc:date>2011-09-27T14:12:11Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745558#M529889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Oct 2011 16:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745558#M529889</guid>
      <dc:creator>Matthew Michaluk</dc:creator>
      <dc:date>2011-10-13T16:33:29Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745559#M529890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might need to add this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (dmz4) 101 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There no translation for the inside host when&amp;nbsp; they go the dmz4 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Oct 2011 16:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745559#M529890</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-13T16:37:06Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745560#M529891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was having the same problem after changing dynamic nat pools around and found the below tip &lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml"&gt;here&lt;/A&gt; (at the bottom under troubleshooting). I ran &lt;STRONG&gt;clear xlate &lt;/STRONG&gt;and my problem was solved immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;&lt;A name="trans-failed"&gt;Translation Creation Failed&lt;/A&gt;&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a connection cannot be created between the client and the WWW&amp;nbsp; server, it might be due to a NAT misconfiguration. Check the security&amp;nbsp; appliance logs for messages which indicate that a protocol failed to&amp;nbsp; create a translation through the security appliance. If such messages&amp;nbsp; appear, verify that NAT has been configured for the desired traffic and&amp;nbsp; that no addresses are incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;PRE&gt;%ASA-3-305006: portmap translation creation failed for tcp src 
inside:192.168.100.2/11000 dst inside:192.168.100.10/80&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clear the xlate entries, and then remove and reapply the NAT statements in order to resolve this error.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2011 18:37:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745560#M529891</guid>
      <dc:creator>fitzerpn1</dc:creator>
      <dc:date>2011-11-16T18:37:48Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745561#M529893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Varun said you will need to add the following:&lt;/P&gt;&lt;P&gt;global (dmz4) 101 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do a packet-tracer too see if now we are hitting the correct nat statement when the packet goes from the dmz to the inside (syn-ack).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp 192.168.100.2 1025 10.10.7.21 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do a clear local-host&amp;nbsp; 10.10.7.21 and clear xlate local 10.10.7.21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2011 18:53:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745561#M529893</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-11-16T18:53:21Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745562#M529895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; You need to add an NO NAT from your inside interface to your DMZ to get this to work. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 21:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745562#M529895</guid>
      <dc:creator>smayfield</dc:creator>
      <dc:date>2012-02-29T21:15:37Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside:192.168.9</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745563#M529897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; So for example you have this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.1.0/24Inside(FW)or (RA VPN) ---------VPN------------(FW )10.1.1.0/24Inside------192.168.10.0/24 DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSIDE_NO_NAT extended permit ip 192.168.1.0 255.255.255.0 192.168.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list INSIDE_NO_NAT &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 21:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745563#M529897</guid>
      <dc:creator>smayfield</dc:creator>
      <dc:date>2012-02-29T21:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed for tcp src inside:192.1</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745564#M529899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I today was having the same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Who doing hairpining NAT on a tcp port, to and from the same interface. Why is it that you need global (dmz4) 101 interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 21:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745564#M529899</guid>
      <dc:creator>John Peterson</dc:creator>
      <dc:date>2013-06-12T21:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed for tcp src inside:192.1</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745565#M529900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is&amp;nbsp; a document that will help u with the U-turn understanding:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-34107"&gt;https://supportforums.cisco.com/docs/DOC-34107&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if u Understand the reason afterwards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 23:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside-192-168/m-p/1745565#M529900</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-12T23:20:56Z</dc:date>
    </item>
  </channel>
</rss>

