<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static NAT for outside access not working... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777350#M530326</link>
    <description>&lt;P&gt;Hello all. I've got an ASA 5510 that has been working like a charm for some time now. Until now we've not had to nat any resources to the outside. I created network objects for an internal host and an external host. The internal host has to respond to requests on tcp/2001.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The internal host has no problem accessing the internet, but when I attempt to access the internal host from the outside, I get the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; Sep 20 2011&amp;nbsp;&amp;nbsp;&amp;nbsp; 16:20:33&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fw_outside_ip&amp;nbsp;&amp;nbsp;&amp;nbsp; 62678&amp;nbsp;&amp;nbsp;&amp;nbsp; outside_host&amp;nbsp;&amp;nbsp;&amp;nbsp; 2001&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny tcp src outside:outside_host_ip/62678 dst inside_host:inside_host_ip/2001 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to use the packet tracer to simulate the outside traffic, I get the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5&amp;nbsp;&amp;nbsp;&amp;nbsp; Sep 20 2011&amp;nbsp;&amp;nbsp;&amp;nbsp; 16:17:41&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_host&amp;nbsp;&amp;nbsp;&amp;nbsp; 2001&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp src outside:outside_host/1065 dst inside_int:inside_host/2001 denied due to NAT reverse path failure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got over my NAT statement and access rule and can't find anything wrong with either. If someone could take a look I'd appreciate it...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the pertinent NAT and access rule...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside_int,outside) tcp interface 2001 inside_host 2001 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp host outside_host host inside_host eq 2001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:27:40 GMT</pubDate>
    <dc:creator>remitprosupport</dc:creator>
    <dc:date>2019-03-11T21:27:40Z</dc:date>
    <item>
      <title>Static NAT for outside access not working...</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777350#M530326</link>
      <description>&lt;P&gt;Hello all. I've got an ASA 5510 that has been working like a charm for some time now. Until now we've not had to nat any resources to the outside. I created network objects for an internal host and an external host. The internal host has to respond to requests on tcp/2001.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The internal host has no problem accessing the internet, but when I attempt to access the internal host from the outside, I get the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; Sep 20 2011&amp;nbsp;&amp;nbsp;&amp;nbsp; 16:20:33&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fw_outside_ip&amp;nbsp;&amp;nbsp;&amp;nbsp; 62678&amp;nbsp;&amp;nbsp;&amp;nbsp; outside_host&amp;nbsp;&amp;nbsp;&amp;nbsp; 2001&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny tcp src outside:outside_host_ip/62678 dst inside_host:inside_host_ip/2001 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to use the packet tracer to simulate the outside traffic, I get the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5&amp;nbsp;&amp;nbsp;&amp;nbsp; Sep 20 2011&amp;nbsp;&amp;nbsp;&amp;nbsp; 16:17:41&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_host&amp;nbsp;&amp;nbsp;&amp;nbsp; 2001&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp src outside:outside_host/1065 dst inside_int:inside_host/2001 denied due to NAT reverse path failure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got over my NAT statement and access rule and can't find anything wrong with either. If someone could take a look I'd appreciate it...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the pertinent NAT and access rule...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside_int,outside) tcp interface 2001 inside_host 2001 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp host outside_host host inside_host eq 2001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777350#M530326</guid>
      <dc:creator>remitprosupport</dc:creator>
      <dc:date>2019-03-11T21:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT for outside access not working...</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777351#M530328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I can see you are running a version older than 8.3, So in this case you will need to point the Public Ip ( The natted one ) address on the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if the Ip adddress of the interface is 31.31.31.31 the ACL should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp host outside_host&amp;nbsp; host 31.31.31.31 eq 2001&lt;/P&gt;&lt;P&gt;Access-group&amp;nbsp; outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this is going to solve your problem, Please let me know if you need anything else&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Sep 2011 21:52:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777351#M530328</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-09-20T21:52:40Z</dc:date>
    </item>
    <item>
      <title>Static NAT for outside access not working...</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777352#M530330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Julio. I tried changing the destination IP address in the ACL from my inside host to that of the external IP address of the firewall in the ACL and I still get the same denial message. Do you have any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 00:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777352#M530330</guid>
      <dc:creator>remitprosupport</dc:creator>
      <dc:date>2011-09-21T00:48:08Z</dc:date>
    </item>
    <item>
      <title>Static NAT for outside access not working...</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777353#M530333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that you can post the configuration, and the source Ip address and the destination Ip address of this traffic in order to take a deeper look into this issue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 00:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777353#M530333</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-09-21T00:51:09Z</dc:date>
    </item>
    <item>
      <title>Static NAT for outside access not working...</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777354#M530336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your reply. Because this was&amp;nbsp; time-sensitive, I opened a TAC with Cisco and they were able to resolve&amp;nbsp; the issue. As you pointed out, the access rule on the outside interface&amp;nbsp; needed to allow access to the outside interface itself. I was adding the&amp;nbsp; outside interface's IP address through ASDM, which did not work. The&amp;nbsp; Cisco tech added the outside IP address through the CLI, which then&amp;nbsp; showed up in ASDM as the interface by name (outside) instead of IP. I'm&amp;nbsp; not sure yet if specifying it by name in ASDM when adding the rule would&amp;nbsp; have had the same effect, but I'll have to test that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your help is greatly appreciated...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 15:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777354#M530336</guid>
      <dc:creator>remitprosupport</dc:creator>
      <dc:date>2011-09-21T15:07:49Z</dc:date>
    </item>
    <item>
      <title>Static NAT for outside access not working...</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777355#M530338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am glad that now everything is working, as I assumed the problem was the Access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other question I will be more than glad to help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great Day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 16:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-for-outside-access-not-working/m-p/1777355#M530338</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-09-21T16:05:53Z</dc:date>
    </item>
  </channel>
</rss>

