<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 8.3 Pat problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506134#M579579</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;EM&gt;access-list outside_access_in extended permit tcp any object Webserver eq www&lt;/EM&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;so you are permitting port 80 not port 5030 which is blocked by implicit deny from outside to inside or dmz.&lt;/P&gt;&lt;P&gt;if you want the telnet on port 80 to work then you must change your nat command&amp;nbsp; and leave port 80 and if you want port 5030 to work you must change your ACL to permit this port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it work when doing so?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Nov 2010 15:06:40 GMT</pubDate>
    <dc:creator>cadet alain</dc:creator>
    <dc:date>2010-11-26T15:06:40Z</dc:date>
    <item>
      <title>ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506125#M579570</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer with a ASA 8.3 version. The customer wants to make pat from the public ASA IP to several internal IP address in the inside interface (diferent ports).&lt;/P&gt;&lt;P&gt;something like, everyone who telnet to port 50030 on public ASA IP is send to port 80 in a private IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configure the ASA this way:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;object network Webserver&lt;BR /&gt; host 192.168.100.100&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;object network Webserver&lt;BR /&gt; nat (inside,outside) static interface service tcp 80 50030&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-list outside_access_in extended permit tcp any object Webserver eq 50030&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-group outside_access_in in interface outside&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I type the command «show xlate» I have this result:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;show xlate | inc 192.168.100.100&lt;/EM&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;TCP PAT from inside:192.168.100.100 80-80 to&amp;nbsp; outside:194.38.X.X 50030-50030&lt;/EM&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;»&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;So I assume the nat is well done. The question is that, from the outside, when I make a telnet to 194.38.X.X port 50030, he doesn´t hit the access-list.&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;the port 80 in private IP is open and I can telnet him from the inside.&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;Any help ?&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV style="direction: ltr; color: #000000; font-size: 9pt;"&gt;Nelson&lt;BR /&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506125#M579570</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2019-03-11T19:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506126#M579571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;change your access-list to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-list outside_access_in extended permit tcp any object Webserver eq 80&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your translated port is 50030 and original port is 80 correct???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Nov 2010 13:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506126#M579571</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-11-24T13:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506127#M579572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks jathaval,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I change the configuration as you suggest:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in extended permit tcp any object Webserver eq www&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it still not working and when I telnet to public IP in port 50030, it still not hit the access-list:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in line 57 extended permit tcp any object Webserver eq www 0xdbbb2b68&lt;BR /&gt;&amp;nbsp; access-list outside_access_in line 57 extended permit tcp any host 192.168.100.100 eq www (hitcnt=0) 0xdbbb2b68&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Nov 2010 14:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506127#M579572</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-11-24T14:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506128#M579573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please run packet tracer and see if it is getting blocked anywhr&lt;/P&gt;&lt;P&gt;Also if it matches any of the rules above this rule in the access-list it will not show hit counts on this one, so please past eyour access-list rules for outside_access_in if it is not too big&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Nov 2010 15:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506128#M579573</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-11-24T15:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506129#M579574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jathaval,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You right. But I still don´t get it because the packet is droped due to a implicit rule (probably the last one that deny any any right ?):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, why the packet don´t match with the rule we created to this particular packets ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in line 57 extended permit tcp any object Webserver eq www 0xdbbb2b68&lt;BR /&gt;&amp;nbsp; access-list outside_access_in line 57 extended permit tcp any host 192.168.100.100 eq www (hitcnt=0) 0xdbbb2b68&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list applied to outside interface is this one:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list outside_access_in extended permit gre host 62.28.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 195.245.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 81.193.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 82.154.X.X any&lt;BR /&gt;access-list outside_access_in extended permit gre host 213.13.X.X any&lt;BR /&gt;access-list outside_access_in extended permit icmp any object-group SITES_LAN&lt;BR /&gt;access-list outside_access_in extended permit tcp any object Webserver eq www&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Nov 2010 14:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506129#M579574</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-11-25T14:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506130#M579575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh the packet is getting dropped here because you are running a packet tracer to the interface ip and also your static looks to be your outside interface ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, In the static nat rules and interface rules use the keyword interface instead of interface ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jitendriya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Nov 2010 15:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506130#M579575</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-11-25T15:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506131#M579576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the config I have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;object network Webserver &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;host 192.168.100.100&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in extended permit tcp any object Webserver eq www&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;object network Webserver&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;nat (inside,outside) static interface service tcp www 50030&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-group outside_access_in in interface outside&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really miss something and I cannot understand what is it&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Nov 2010 16:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506131#M579576</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-11-25T16:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506132#M579577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what test are you doing in packet tracer and while doing real world testing.&lt;/P&gt;&lt;P&gt;please paste the command you use for packet tracer&lt;/P&gt;&lt;P&gt;please move the access-list applied to line 1 in the access-group&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 01:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506132#M579577</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-11-26T01:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506133#M579578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again for your pacient,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I move the access-list to line 1 but is the same. Nothing hits.&lt;/P&gt;&lt;P&gt;In "real world" I´m doing a telnet from another customer with a ADSL line.&lt;/P&gt;&lt;P&gt;When I make telnet to port 50030 of the public IP, i don´t see anything in the ASDM Real Time Log Viewer. But if I make the same command but to port 80 (it should NOT work) i see the packet being denied in the ASDM Real Time Log Viewer.&lt;/P&gt;&lt;P&gt;The message thar appears is (telnet to ASA outside interface at port 80):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;TCP access denied by ACL from 213.58.X.X/17927 to outside:194.38.X.X/80&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same command but to port 50030, nothing apears. It seems like the packets don´t reach the ASA. I make this test from several local and the result is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the packet tracker command, I´m doing this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;packet-tracer input outside tcp 213.58.X.X 17927 194.38.X.X 50030&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 194.38.X.X&amp;nbsp;&amp;nbsp; 255.255.255.255 identity&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 09:47:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506133#M579578</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-11-26T09:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506134#M579579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;EM&gt;access-list outside_access_in extended permit tcp any object Webserver eq www&lt;/EM&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;so you are permitting port 80 not port 5030 which is blocked by implicit deny from outside to inside or dmz.&lt;/P&gt;&lt;P&gt;if you want the telnet on port 80 to work then you must change your nat command&amp;nbsp; and leave port 80 and if you want port 5030 to work you must change your ACL to permit this port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it work when doing so?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 15:06:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506134#M579579</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-11-26T15:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506135#M579580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the server 192.168.100.100 listens on port 80 then what you have is correct.&amp;nbsp; If you try the following url from the browser&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://ip_address_of_interface:50030"&gt;http://ip_address_of_interface:50030&lt;/A&gt;&lt;SPAN&gt; it should work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to add the access-list as line 1 and give it a shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in line 1 extended permit tcp any host 192.168.100.100 eq www&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 20:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506135#M579580</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-26T20:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506136#M579581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Poonguzhali,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried your suggestion but it still not work.&lt;/P&gt;&lt;P&gt;Yes, the real port is 80 in IP 192.168.100.100 and the "outside" port is 50030 in outside IP of ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 1 extended permit tcp any host 192.168.100.100 eq www (hitcnt=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but is strange because I´m making a telnet to outside interface on port 50030. So it should be something like this (also not hit):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 2 extended permit tcp any host 194.38.X.X eq 50030 (hitcnt=0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 17:18:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506136#M579581</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-11-30T17:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506137#M579582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another thing that I really don´t undrestand is why when I make a telnet to ASA public IP at port 80 it appears at Real Time Log Viewer (ASDM) and if I make the same telnet but to port 50030 nothing appears. It seems like the packet do not reach ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 17:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506137#M579582</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-11-30T17:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506138#M579583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears so. A quick capture will prove it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap capout int outside match tcp any any eq 50030&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test your telent to the interface IP address on port 50030 and look a the capture to see there are any packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh cap capout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not see any packets you need to check the upstream router to see if it is even sending these packets towards the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 03:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506138#M579583</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-01T03:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506139#M579584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You right Sankar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I test the command you suggest and the packets arrive to ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;ASA-Customer-DatacenterC# show capture capout&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;4 packets captured&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 1: 08:18:14.857804 213.58.X.X.29703 &amp;gt; 194.38.X.X.50030: S 1410453446:1410453446(0) win 4128 &lt;MSS 536=""&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2: 08:18:17.856599 213.58.X.X.29703 &amp;gt; 194.38.X.X.50030: S 1410453446:1410453446(0) win 4128 &lt;MSS 536=""&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3: 08:18:23.857530 213.58.X.X.29703 &amp;gt; 194.38.X.X.50030: S 1410453446:1410453446(0) win 4128 &lt;MSS 536=""&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4: 08:18:35.860642 213.58.X.X.29703 &amp;gt; 194.38.X.X.50030: S 1410453446:1410453446(0) win 4128 &lt;MSS 536=""&gt;&lt;/MSS&gt;&lt;/MSS&gt;&lt;/MSS&gt;&lt;/MSS&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it still not hit the access-list &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 15:30:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506139#M579584</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-12-02T15:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506140#M579585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the first entry of my access-list that is applied to outside interface (&lt;EM&gt;&lt;STRONG&gt;access-group outside_access_in in interface outside&lt;/STRONG&gt;&lt;/EM&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in line 1 extended permit tcp any host 194.38.X.X eq 50030 (hitcnt=0)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packets appear at show capture but don´t hit the entry at access-list. WHY ?????????????? &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/confused.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 15:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506140#M579585</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-12-02T15:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506141#M579587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;They don't hit your ACL entry because you are referencing public IP and you must reference real IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 15:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506141#M579587</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-12-02T15:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506142#M579589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cadetalain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It´s not that because I have all this entrys in access-list:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in extended permit tcp any host 194.38.X.X eq 50030&lt;BR /&gt;access-list outside_access_in extended permit tcp host 213.58.X.X any eq www&amp;nbsp; - IP 213.58.X.X is the IP of the router from where I´m testing telnet to port&lt;BR /&gt;access-list outside_access_in extended permit tcp host 213.58.X.X any eq 50030&lt;BR /&gt;access-list outside_access_in extended permit tcp any object Webserver eq 50030&lt;BR /&gt;access-list outside_access_in extended permit tcp any object Webserver eq www&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the packet don´t hit any of this entrys&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 15:51:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506142#M579589</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-12-02T15:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506143#M579591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I put this entry at access-list (with the real private IP address) but is exacly the same (no hits):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;«&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;access-list outside_access_in line 1 extended permit ip any host 192.168.100.100 (hitcnt=0)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;»&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 16:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506143#M579591</guid>
      <dc:creator>nelson.mendes</dc:creator>
      <dc:date>2010-12-02T16:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Pat problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506144#M579593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok. This is very interesting. Could you pls. quickly open a TAC case and provide the case number here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will take a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the capture command that I gave you, you can include the word "trace" in the end and issue "sh cap capout trace" and see where we are dropping the packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 16:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-pat-problem/m-p/1506144#M579593</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-02T16:51:45Z</dc:date>
    </item>
  </channel>
</rss>

