<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM static NAT gets Stuck Intermittently in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668927#M557587</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have &lt;SPAN class="Apple-style-span" style="word-spacing: 0px; font: medium 'Times New Roman'; text-transform: none; color: #000000; text-indent: 0px; white-space: normal; letter-spacing: normal; border-collapse: separate; orphans: 2; widows: 2; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;wherein we have configured static NAT. It has been observed that static nat gets stuck, and the host becomes unreachable via &lt;BR /&gt;both ingress/egress&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i issue a clear xlate local x.x.x.x, this clears things up and &lt;BR /&gt;connectivity is restored.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CONFIG DETAILS AS FOLLOWS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;FWSM# show run | i LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt; nameif LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;object-group network LBS_Firewall_dest&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;object-group service LBS_ACCESS_PORTS_TCP tcp---------(SOME PORT RANGE)&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;object-group service LBS_ACCESS_PORTS_UDP udp---------(SOME PORT RANGE)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-list INTERNET_IN extended permit tcp any object-group LBS_ACCESS_DEST object-group LBS_ACCESS_PORTS_TCP &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-list INTERNET_IN extended permit udp any object-group LBS_ACCESS_DEST object-group LBS_ACCESS_PORTS_UDP &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-list LBS extended permit ip any any &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;mtu LBS 1500&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;monitor-interface LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;icmp permit any LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;static (LBS,INTERNET) A.A.A.A B.B.B.B netmask 255.255.255.255 &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-group LBS in interface LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;route LBS B.B.B.128 255.255.255.128 C.C.C.C 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;server with private IP B.B.B.B becomes unreachable intermittently, although xlate entry is happening with 1_to_1 mapping.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Please suggest.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Fiya.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="word-wrap: break-word;"&gt;FWSM Version 4.0(8)&lt;/PRE&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:22:33 GMT</pubDate>
    <dc:creator>ansarihuma</dc:creator>
    <dc:date>2019-03-11T20:22:33Z</dc:date>
    <item>
      <title>FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668927#M557587</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have &lt;SPAN class="Apple-style-span" style="word-spacing: 0px; font: medium 'Times New Roman'; text-transform: none; color: #000000; text-indent: 0px; white-space: normal; letter-spacing: normal; border-collapse: separate; orphans: 2; widows: 2; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;wherein we have configured static NAT. It has been observed that static nat gets stuck, and the host becomes unreachable via &lt;BR /&gt;both ingress/egress&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i issue a clear xlate local x.x.x.x, this clears things up and &lt;BR /&gt;connectivity is restored.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CONFIG DETAILS AS FOLLOWS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;FWSM# show run | i LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt; nameif LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;object-group network LBS_Firewall_dest&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;object-group service LBS_ACCESS_PORTS_TCP tcp---------(SOME PORT RANGE)&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;object-group service LBS_ACCESS_PORTS_UDP udp---------(SOME PORT RANGE)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-list INTERNET_IN extended permit tcp any object-group LBS_ACCESS_DEST object-group LBS_ACCESS_PORTS_TCP &lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-list INTERNET_IN extended permit udp any object-group LBS_ACCESS_DEST object-group LBS_ACCESS_PORTS_UDP &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-list LBS extended permit ip any any &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;mtu LBS 1500&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;monitor-interface LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;icmp permit any LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;static (LBS,INTERNET) A.A.A.A B.B.B.B netmask 255.255.255.255 &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;access-group LBS in interface LBS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #0000ff; font-family: Calibri;"&gt;route LBS B.B.B.128 255.255.255.128 C.C.C.C 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;server with private IP B.B.B.B becomes unreachable intermittently, although xlate entry is happening with 1_to_1 mapping.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Please suggest.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Fiya.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="word-wrap: break-word;"&gt;FWSM Version 4.0(8)&lt;/PRE&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:22:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668927#M557587</guid>
      <dc:creator>ansarihuma</dc:creator>
      <dc:date>2019-03-11T20:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668928#M557588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most likely, the xlate is actually being built to the wrong interface. This can happen if traffic incorrectly is received on a different interface than is expected. If the traffic is allowed by ACL and RPF checking is disabled, the FWSM will black-hole traffic to the incorrect interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround is to enable RPF checking (ip verify reverse-path interface &lt;INT&gt;) or lock down your ACLs to only permit traffic sourced from the correct subnets.&lt;/INT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Apr 2011 13:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668928#M557588</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-04-18T13:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668929#M557591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brendan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for kind reply..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RPF have not been enabled on this vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is the connection table:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;A.A.A.A---NATTED DESTINATION PUBLIC IP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;B.B.B.B---NATTED DESTINATION PRIVATE IP.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;P.Q.R.S-- SOURCE COMING FROM INTERNET.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**********************************CONNECTION TABLE AT NORMAL SCENARIO*****************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh conn | i B.B.B.B&lt;/P&gt;&lt;P&gt;TCP INTERNET P.Q.R.S:1298 LBS B.B.B.B:80 idle 0:00:00 Bytes 2782 FLAGS - UOI&lt;/P&gt;&lt;P&gt;TCP INTERNET P.Q.R.S:1299 LBS B.B.B.B:80 idle 0:00:00 Bytes 2736 FLAGS - UOI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;********CONNECTION TABLE AT OUTAGE SCENARIO**********SHOWS SWITCH MSFC WITH PUBLIC IP AS DESTINATION**********&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh conn | i B.B.B.B&lt;/P&gt;&lt;P&gt;TCP INTERNET P.Q.R.S:1298 MSFC A.A.A.A:80 idle 0:00:00 Bytes 2782 FLAGS - BS&lt;/P&gt;&lt;P&gt;TCP INTERNET P.Q.R.S:1299 MSFC A.A.A.A:80 idle 0:00:00 Bytes 2736 FLAGS - BS&lt;/P&gt;&lt;P&gt;TCP INTERNET P.Q.R.S:554 LBS B.B.B.B:23170 idle 0:00:00 Bytes 48718 FLAGS - BS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: MSFC is the vlan mapped in FWSM to have communication between switch (MSFC) &amp;amp; FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Albeit, we are able to ping the server IP even during outage time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;************************************SH XLATE AT BOTH SCENARIO***************************************&lt;/P&gt;&lt;P&gt;FWSM# sh xlate | i B.B.B.B&lt;/P&gt;&lt;P&gt;Global A.A.A.A Local B.B.B.B&lt;/P&gt;&lt;P&gt;FWSM#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pl. suggest..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Huma.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2011 07:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668929#M557591</guid>
      <dc:creator>ansarihuma</dc:creator>
      <dc:date>2011-04-19T07:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668930#M557593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have enable RPF but still issue is persisting &amp;amp; connection table seems perfect with normal connection flags..&lt;/P&gt;&lt;P&gt;Please suggest ASAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Huma.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2011 06:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668930#M557593</guid>
      <dc:creator>ansarihuma</dc:creator>
      <dc:date>2011-04-20T06:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668931#M557597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the conn output. Did you check the xlates as well? The bad xlates are what black holes the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, do you have rpf checks enabled on all interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2011 06:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668931#M557597</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-04-20T06:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668932#M557599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I meant to ask for the 'show xlate detail'. The normal 'show xlate' output does not reference the actual interface names. The 'show xlate detail' output should show that the xlate is built to an incorrect interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2011 06:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668932#M557599</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-04-20T06:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668933#M557600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brquinn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The sh xlate detail seems like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***********DURING ISSUE**************&lt;/P&gt;&lt;P&gt;FWSM# sh xlate detail | i B.B.B.B&lt;/P&gt;&lt;P&gt;NAT from LBS:B.B.B.B to ASA:B.B.B.B flags Ii&lt;/P&gt;&lt;P&gt;NAT from LBS:B.B.B.B to INTERNET:A.A.A.A flags si&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**********DURING NORMAL*************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh xlate detail | i B.B.B.B&lt;/P&gt;&lt;P&gt;NAT from LBS:B.B.B.B to INTERNET:A.A.A.A flags si&lt;/P&gt;&lt;P&gt;NAT from LBS:B.B.B.B to ASA:B.B.B.B flags Ii&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt IDENTITY NAT should not create a issue as such. &lt;/P&gt;&lt;P&gt;The only i can find in both scenario is the sequence of IDENTITY NAT happening, i.e. during normal scenario IDENTITY NAT is on first priority and during normal STATIC NAT is on priority.&lt;/P&gt;&lt;P&gt;Even rest of the other interface works absolutely fine with such IDENTITY NAT on priority.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Huma.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Apr 2011 07:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668933#M557600</guid>
      <dc:creator>ansarihuma</dc:creator>
      <dc:date>2011-04-25T07:00:56Z</dc:date>
    </item>
    <item>
      <title>FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668934#M557601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having the exact same issue...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 14:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668934#M557601</guid>
      <dc:creator>a.henning</dc:creator>
      <dc:date>2012-08-22T14:29:01Z</dc:date>
    </item>
    <item>
      <title>FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668935#M557602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;Looks like you'll need to enable Cisco's xlate bypass feature in your FWSM. Please click on this URL for further details &lt;A _jive_internal="true" href="https://community.cisco.com/thread/2164524"&gt;https://supportforums.cisco.com/thread/2164524&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 18:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668935#M557602</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-22T18:16:30Z</dc:date>
    </item>
    <item>
      <title>FWSM static NAT gets Stuck Intermittently</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668936#M557605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the tip Ramraj!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For anyone else having this intermittent NAT issue here are a couple options to improve and/or solve the issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;NAT/PAT entries that worked for years start to display intermittent issues. &lt;/P&gt;&lt;P&gt;show xlate | in ^Global 209.165.200.224&lt;/P&gt;&lt;P&gt;NAT from OUTSIDE:209.165.200.224 to OUTSIDE:209.165.200.224&lt;/P&gt;&lt;P&gt;NAT from DMZ:10.1.1.224 to OUTSIDE:209.165.200.224&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first entry is created dynamically and is the problem, the second entry is correct based on the configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on the interpretation, this might be:&lt;/P&gt;&lt;P style="margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11px; text-indent: -0.25in;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;CSCso46878&lt;/P&gt;&lt;P&gt;&lt;A name="wp169532" style="color: #000000; font-size: 12px;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 1px 0em 6px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11px;"&gt;An extra xlate (between the wrong interfaces) gets created when using static policy NAT and the &lt;STRONG&gt;no nat-control&lt;/STRONG&gt;command. This seems to occur when the policy NAT access list overlaps with a network on another interface.&lt;/P&gt;&lt;P&gt;&lt;A name="wp169701" style="color: #000000; font-size: 12px;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 1px 0em 6px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11px;"&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;: If applicable, use static NAT without an access list, and filter with an &lt;STRONG&gt;access-group&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a temporary measure the clear xlate global 209.165.200.224 resolves the problem until the dynamic entry is created again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actions that improved but did not solve the issue in order of significance:&lt;/P&gt;&lt;P&gt;Convert and consolidate multiple PAT entries into 1-to-1 NAT&lt;/P&gt;&lt;P&gt;Reduce xlate timeout&lt;/P&gt;&lt;P&gt;Removed ACL's in NAT statements as per CSCso4687 work around suggestion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution in this particular case:&lt;/P&gt;&lt;P&gt;Upgrade code from 3.1(4) to 3.2(23). Required for xlate-bypass&lt;/P&gt;&lt;P&gt;Enable xlate-bypass&lt;/P&gt;&lt;P&gt;Changed OUTSIDE interface mask to not overlap with OUTSIDE NAT addresses&lt;/P&gt;&lt;P&gt;Moved devices on OUTSIDE segment to dedicated NONAT-DMZ zone with public address space.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Sep 2012 22:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-static-nat-gets-stuck-intermittently/m-p/1668936#M557605</guid>
      <dc:creator>a.henning</dc:creator>
      <dc:date>2012-09-08T22:13:33Z</dc:date>
    </item>
  </channel>
</rss>

