<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse path translation problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646446#M595949</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; mac-address 0019.30c9.6f0c&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 189.X.X.X 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.6.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2.1&lt;BR /&gt; description &lt;BR /&gt; vlan 2&lt;BR /&gt; nameif dmz-7&lt;BR /&gt; security-level 4&lt;BR /&gt; ip address 172.6.5.4 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2.2&lt;BR /&gt; vlan 4&lt;BR /&gt; nameif dmz&lt;BR /&gt; security-level 4&lt;BR /&gt; ip address 172.6.18.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sh run route&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 189.39.32.33 1&lt;BR /&gt;route inside 10.21.0.0 255.255.0.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.2.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.6.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.10.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.20.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.60.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 192.168.21.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 192.168.224.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route dmz1 199.X.X.X 255.255.248.0 172.6.5.12 1&lt;BR /&gt;route dmz1 199.X.X.X 255.255.255.248 172.6.5.12 1&lt;BR /&gt;route dmz1 199.X.X.X 255.255.255.254 172.6.5.12 1&lt;BR /&gt;route dmz1 205.X.X.X 255.255.255.0 172.6.5.12 1&lt;BR /&gt;route dmz1 208.X.X.X&amp;nbsp; 255.255.255.0 172.6.5.12 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sh run nat&lt;BR /&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;BR /&gt;nat (inside) 1 172.6.1.201 255.255.255.255&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (dmz2) 1 172.6.18.25 255.255.255.255&lt;/P&gt;&lt;P&gt;SPOFWL01# sh run global&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;global (dmz1) 1 interface&lt;BR /&gt;global (dmz2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sh run stat&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.22 82 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.22 81 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X https 172.6.18.22 https netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.22 www netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.250 www netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 172.6.1.21 172.6.1.21 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 172.6.1.22 172.6.1.22 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 172.6.1.71 172.6.1.71 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 189.X.X.X 172.6.1.225 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.11 10.21.4.11 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.21 10.21.4.21 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.32 10.21.4.32 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.71 10.21.4.71 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.76 10.21.4.76 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.1.21 10.21.1.21 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.1.22 10.21.1.22 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.1.76 10.21.1.76 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.91 10.21.4.91 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.25 10.21.4.25 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.77 10.21.4.77 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,inside) 172.6.18.23 172.6.18.23 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,inside) 172.6.18.25 172.6.18.25 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) 189.X.X.X 172.6.18.25 netmask 255.255.255.255 dns&lt;BR /&gt;static (dmz2,inside) 172.6.18.22 172.6.18.22 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) 189.X.X.X 172.6.18.21 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,inside) 172.6.18.200 172.6.18.250 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) 189.X.X.X 172.16.50.250 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follows the output requested, This might be a NAT exemption deployment case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Dec 2010 13:16:37 GMT</pubDate>
    <dc:creator>anunes1987</dc:creator>
    <dc:date>2010-12-27T13:16:37Z</dc:date>
    <item>
      <title>Reverse path translation problem</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646444#M595947</link>
      <description>&lt;P&gt;I'm having a problem with NAT , i have a Videoconference system and from site A to SIte B is all good. But when site b tries to dial site A, is not completing and in ASA logs on site B i get reverse path translation failed from DMZ to Inside. Dialing from outside to SITe B is also ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This connection between site A and B is made thru MPLS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone can help to fix this?&amp;nbsp; site A IP VC ip is 10.21.2.300&amp;nbsp; and Site B VC 172.6.18.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Calibri; "&gt;match tcp dmz host 172.6.18.200 eq 80 outside any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN lang="EN-US" style="mso-ansi-language: EN-US;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 189.X.X.X/80&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 25&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;If any command is need just let me know taht i put up the output&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646444#M595947</guid>
      <dc:creator>anunes1987</dc:creator>
      <dc:date>2019-03-11T19:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse path translation problem</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646445#M595948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the ASA perspective, how is site A and site B connected? Can you please share the output of:&lt;/P&gt;&lt;P&gt;show run interface&lt;/P&gt;&lt;P&gt;show run route&lt;/P&gt;&lt;P&gt;show run nat&lt;/P&gt;&lt;P&gt;show run global&lt;/P&gt;&lt;P&gt;show run static&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 12:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646445#M595948</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-12-27T12:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse path translation problem</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646446#M595949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; mac-address 0019.30c9.6f0c&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 189.X.X.X 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.6.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2.1&lt;BR /&gt; description &lt;BR /&gt; vlan 2&lt;BR /&gt; nameif dmz-7&lt;BR /&gt; security-level 4&lt;BR /&gt; ip address 172.6.5.4 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2.2&lt;BR /&gt; vlan 4&lt;BR /&gt; nameif dmz&lt;BR /&gt; security-level 4&lt;BR /&gt; ip address 172.6.18.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sh run route&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 189.39.32.33 1&lt;BR /&gt;route inside 10.21.0.0 255.255.0.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.2.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.6.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.10.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.20.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 172.16.60.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 192.168.21.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route inside 192.168.224.0 255.255.255.0 172.6.1.10 1&lt;BR /&gt;route dmz1 199.X.X.X 255.255.248.0 172.6.5.12 1&lt;BR /&gt;route dmz1 199.X.X.X 255.255.255.248 172.6.5.12 1&lt;BR /&gt;route dmz1 199.X.X.X 255.255.255.254 172.6.5.12 1&lt;BR /&gt;route dmz1 205.X.X.X 255.255.255.0 172.6.5.12 1&lt;BR /&gt;route dmz1 208.X.X.X&amp;nbsp; 255.255.255.0 172.6.5.12 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sh run nat&lt;BR /&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;BR /&gt;nat (inside) 1 172.6.1.201 255.255.255.255&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (dmz2) 1 172.6.18.25 255.255.255.255&lt;/P&gt;&lt;P&gt;SPOFWL01# sh run global&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;global (dmz1) 1 interface&lt;BR /&gt;global (dmz2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;sh run stat&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.22 82 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.22 81 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X https 172.6.18.22 https netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.22 www netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) tcp 189.X.X.X www 172.6.18.250 www netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 172.6.1.21 172.6.1.21 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 172.6.1.22 172.6.1.22 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 172.6.1.71 172.6.1.71 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 189.X.X.X 172.6.1.225 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.11 10.21.4.11 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.21 10.21.4.21 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.32 10.21.4.32 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.71 10.21.4.71 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.76 10.21.4.76 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.1.21 10.21.1.21 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.1.22 10.21.1.22 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.1.76 10.21.1.76 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.91 10.21.4.91 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.25 10.21.4.25 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz2) 10.21.4.77 10.21.4.77 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,inside) 172.6.18.23 172.6.18.23 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,inside) 172.6.18.25 172.6.18.25 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) 189.X.X.X 172.6.18.25 netmask 255.255.255.255 dns&lt;BR /&gt;static (dmz2,inside) 172.6.18.22 172.6.18.22 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) 189.X.X.X 172.6.18.21 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,inside) 172.6.18.200 172.6.18.250 netmask 255.255.255.255&lt;BR /&gt;static (dmz2,outside) 189.X.X.X 172.16.50.250 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follows the output requested, This might be a NAT exemption deployment case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 13:16:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646446#M595949</guid>
      <dc:creator>anunes1987</dc:creator>
      <dc:date>2010-12-27T13:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse path translation problem</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646447#M595950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just adding information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SITE A (INSIDE) ----- MPLS ---------- (INSIDE) SITE B &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 13:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646447#M595950</guid>
      <dc:creator>anunes1987</dc:creator>
      <dc:date>2010-12-27T13:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse path translation problem</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646448#M595951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you also post a sh run access-list&amp;nbsp; inside_nat0_outbound?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And can you please send the output of the same commands on the other ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 19:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646448#M595951</guid>
      <dc:creator>jgraafmans</dc:creator>
      <dc:date>2010-12-27T19:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse path translation problem</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646449#M595952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The name of the interfaces do not match up. On your static statement you have "dmz2", however on your interface you don't have "dmz2", but you have "dmz" and "dmz-7". Can you please advise if you have copy the correct configuration from the same ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also how many ASA is there? and can you advise which ASA you receive the error message from?&lt;/P&gt;&lt;P&gt;Complete config from both sites would help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 22:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-translation-problem/m-p/1646449#M595952</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-12-27T22:54:06Z</dc:date>
    </item>
  </channel>
</rss>

