<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT problem, cannot interoperability with internal and DMZ zone in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681985#M561081</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;since the traffic is originated from the internet, coming inbound towards the DMZ server, the access-list needs to be created on the outside interface on the inbound direction.&lt;/P&gt;&lt;P&gt;So guessing that outside_access_in is your outside ACL, then please add the permit for those traffic onto the ACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Jun 2011 07:27:23 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-06-08T07:27:23Z</dc:date>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681978#M561067</link>
      <description>&lt;P&gt;Hi forumers'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Want to ask about conceptual network design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as we seen from the topology, router C881 will do the NAT for the traffic from public internet to internal network that reside privately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First hop will reach ASA firewall. Ethernet 0/1 is main for internal server farm. The sub-interface of Ehternet 0/1.301 and Ehternet 0/1.302 used for DMZ zone, with 2 different publich IP range. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem statement:&lt;/P&gt;&lt;P&gt;1. If i apply ip nat on the C881 router, i can't reach the server reside at DMZ zone. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. apart of design requirement, there's no NAT at ASA....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea how i can resolve such network design?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noel&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:43:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681978#M561067</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2019-03-11T20:43:22Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681979#M561070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the version of your ASA?&lt;/P&gt;&lt;P&gt;Since the traffic is from lower security level towards higher security level, you would also need to apply access-list on ASA outside interface to allow the traffic to go through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further to that, on the router, you would also need to configure route for those server farm subnets to be routed towards the ASA outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 06:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681979#M561070</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-08T06:09:42Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681980#M561073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my ASA running on 8.4. and the server reside at DMZ IS is using public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would this cause the conflict? thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 06:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681980#M561073</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2011-06-08T06:17:43Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681981#M561077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, it shouldn't cause any conflicts.&lt;/P&gt;&lt;P&gt;Are you doing public to public address NATing on the router? I assume different sets of public address that you are doing the NATing on?&lt;/P&gt;&lt;P&gt;and route for those DMZ public subnet on the router towards ASA outside interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 06:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681981#M561077</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-08T06:22:06Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681982#M561078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's no public to public NATTING, NATTING only happen on public to server reside at server farm. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For DMZ, since it's public IP, the router only doing route to the DMZ zone. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it work in this case? thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 06:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681982#M561078</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2011-06-08T06:34:03Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681983#M561079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the router can just do route to the ASA towards the DMZ subnet. No problem at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, from your initial post, I thought you are doing NAT as well, as you mention "&lt;/P&gt;&lt;P&gt;If i apply ip nat on the C881 router, i can't reach the server reside at DMZ zone.".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But yeah, just route on the router will work if the DMZ is already configured with public subnet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 06:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681983#M561079</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-08T06:44:33Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681984#M561080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennnifer, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok, so now the resolution i jsut need to stick with your previous statement:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Since&amp;nbsp; the traffic is from lower security level towards higher security&amp;nbsp;&amp;nbsp; level, you would also need to apply access-list on ASA outside interface&amp;nbsp;&amp;nbsp; to allow the traffic to go through"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;something not clear, i shoudl create the rule at outside_access_in or IPS-A-DMZ_access_in ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 07:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681984#M561080</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2011-06-08T07:24:05Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681985#M561081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;since the traffic is originated from the internet, coming inbound towards the DMZ server, the access-list needs to be created on the outside interface on the inbound direction.&lt;/P&gt;&lt;P&gt;So guessing that outside_access_in is your outside ACL, then please add the permit for those traffic onto the ACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 07:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681985#M561081</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-08T07:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem, cannot interoperability with internal and DMZ z</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681986#M561082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i try create a rule that any--&amp;gt;IPS-A-DMZ on the&amp;nbsp; outside_access_in, it seems that cannot go thru. i try remotely telnet&amp;nbsp; but cannot go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i check on the log it showing this message: as attach&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anything i miss again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 08:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681986#M561082</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2011-06-08T08:22:04Z</dc:date>
    </item>
    <item>
      <title>NAT problem, cannot interoperability with internal and DMZ zone</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681987#M561083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The logs seems to suggest that the TCP SYN is being sent, however, there is no complete TCP 3 way handshake, therefore the TCP connection is getting Reset.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please check if the DMZ server is listening on port 25, and also has the correct default gateway back towards the ASA DMZ interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A copy of the ASA configuration might help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 00:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681987#M561083</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-09T00:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem, cannot interoperability with internal and DMZ z</title>
      <link>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681988#M561084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greeting. The problem resolve as everybody reach the limit and -- revamp the whole config. haha.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the guidance these days. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Noel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2011 00:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problem-cannot-interoperability-with-internal-and-dmz-zone/m-p/1681988#M561084</guid>
      <dc:creator>yong khang NG</dc:creator>
      <dc:date>2011-06-13T00:34:43Z</dc:date>
    </item>
  </channel>
</rss>

