<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nat issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626391#M592642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do the following:&lt;/P&gt;&lt;P&gt;no nat (DMZ) 2 10.10.15.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 10.10.15.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as resolved if you think your query is answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 Feb 2011 16:14:18 GMT</pubDate>
    <dc:creator>andamani</dc:creator>
    <dc:date>2011-02-04T16:14:18Z</dc:date>
    <item>
      <title>nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626390#M592636</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an asa wichi s configured to handle to network, one dmz and other inside network, I can map my inside subnet to public ip with nat but I can't do this with DMZ subnet , I thought I configured correctly, I also attached my configuration file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wouls someone please tell me if there is something wrong in configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when I do packet tracing with ASDM it gives me "ASDM is not able to select the entry for the followoing configuration"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;-Rouzbeh&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626390#M592636</guid>
      <dc:creator>rouzbehta</dc:creator>
      <dc:date>2019-03-11T19:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626391#M592642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do the following:&lt;/P&gt;&lt;P&gt;no nat (DMZ) 2 10.10.15.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 10.10.15.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as resolved if you think your query is answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 16:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626391#M592642</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-02-04T16:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626392#M592651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did this , packet tracer still drops the packet "from 10.10.15.0 255.255.255.0 subnet" with the following message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASDM is not able to select the entry for the following configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside21) 0.0.0.0 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I haven't set this rule!! I don't where this came from in this message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;match ip inside21 any outside any&lt;/P&gt;&lt;P&gt;no translation group, implicit deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy_hits=2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;-Rouzbeh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 16:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626392#M592651</guid>
      <dc:creator>rouzbehta</dc:creator>
      <dc:date>2011-02-04T16:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626393#M592656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I re-checked your configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please remove the following statement:&lt;/P&gt;&lt;P&gt;global (DMZ) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i see that there exists a default route for the DMZ and it is heading to a routable ip. could you please explain why are you doing this?&lt;/P&gt;&lt;P&gt;route DMZ 0.0.0.0 0.0.0.0 66.128.95.145 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say please change the route.&lt;/P&gt;&lt;P&gt;route DMZ 10.10.15.0 255.255.255.0 &lt;NEXT-HOP i.e.="" in="" 10.10.15.0=""&gt; 1&lt;/NEXT-HOP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it makes any difference&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 16:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626393#M592656</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-02-04T16:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626394#M592659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing nat translation for inside network using PAT on interface gig0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to use nat pool for DMZ part and that's why I used the global (DMZ) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248 should I still remove this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;66.128.95.145 is the next hop router, that's why I used the route DMZ 0.0.0.0 0.0.0.0 66.128.95.145 1&lt;/P&gt;&lt;P&gt; I removed the route and added the route you requested&amp;nbsp; route DMZ 10.10.15.0 255.255.255.0 66.128.95.145 but got the mesageg "can not add route, connected route exits"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;-Rouzbeh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 17:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626394#M592659</guid>
      <dc:creator>rouzbehta</dc:creator>
      <dc:date>2011-02-04T17:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626395#M592663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rouzbeh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alright i got the natting part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please do the following:&lt;/P&gt;&lt;P&gt;no global (DMZ) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;global (outside1) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;nat (DMZ) 2 10.10.15.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am not sure of the routing part. by the statement "route DMZ 0.0.0.0 0.0.0.0 66.128.95.145 1" you mean to say that any traffic on the DMZ interface should head to ip&amp;nbsp; 66.128.95.145. The DMZ network is 10.10.15.0/24. the ip&amp;nbsp; 66.128.95.145 is not in the same subnet as 10.10.15.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to understand the routing in here. According to me you should remove the statement "route DMZ 0.0.0.0 0.0.0.0 66.128.95.145 1".&lt;/P&gt;&lt;P&gt;If the DMZ network is directly connected then i don't think there is an explicit need to add a route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you get what i am trying to explain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 17:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626395#M592663</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-02-04T17:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626396#M592667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the followings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no global (DMZ) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;global (outside1) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;net (DMZ) 2 10.10.15.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also removed the route 0.0.0.0 0.0.0.0 66.128.95.145 1 you correct the next hop is directly connected and no need to static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic leaving dmz subnet with 10.10.15.0/24 should be translated to a address from 66.128.95.147-66.128.95.150 right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW after you suggested chages took efect agaib I get packe drop from packet tracer with the following message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 2 10.10.15.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;match ip DMZ 10.10.15.0 255.255.255.0 outside2 any&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;dynamic translation to pool 2 (NO matching global)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Rouzbeh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 18:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626396#M592667</guid>
      <dc:creator>rouzbehta</dc:creator>
      <dc:date>2011-02-04T18:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: nat issue</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626397#M592672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do the following:&lt;/P&gt;&lt;P&gt;no global (outside1) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;global (outside2) 2 66.128.95.147-66.128.95.150 netmask 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark this thread as resolved if you feel your query is answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Feb 2011 01:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue/m-p/1626397#M592672</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-02-05T01:43:13Z</dc:date>
    </item>
  </channel>
</rss>

