<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: translation status in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/translation-status/m-p/1562906#M597903</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The numbers in the paranthesis are the port numbers it is using. PAT Global 20.20.10.10(24777) Local 172.16.24.10(37296) tells us that inside ip 172.16.24.10 on source port 37296 is getting translated and will go out with ip 20.20.10.10 and source port 24777. The second connection will be using the next line of translations.Hope it answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Nov 2010 12:04:15 GMT</pubDate>
    <dc:creator>rmavila</dc:creator>
    <dc:date>2010-11-22T12:04:15Z</dc:date>
    <item>
      <title>translation status</title>
      <link>https://community.cisco.com/t5/network-security/translation-status/m-p/1562905#M597902</link>
      <description>&lt;P&gt;can some one help to understand the following translation i see on&amp;nbsp; a remote firewall,asa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAT Global 20.20.10.10(24777) Local 172.16.24.10(37296) &lt;/P&gt;&lt;P&gt;PAT Global 20.20.10.10(63227) Local 172.16.24.10(34569) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can numerous of these types.&lt;/P&gt;&lt;P&gt;what does the no. in parenthesis stand for each line and does this mean the connections are working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-status/m-p/1562905#M597902</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T19:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: translation status</title>
      <link>https://community.cisco.com/t5/network-security/translation-status/m-p/1562906#M597903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The numbers in the paranthesis are the port numbers it is using. PAT Global 20.20.10.10(24777) Local 172.16.24.10(37296) tells us that inside ip 172.16.24.10 on source port 37296 is getting translated and will go out with ip 20.20.10.10 and source port 24777. The second connection will be using the next line of translations.Hope it answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Nov 2010 12:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-status/m-p/1562906#M597903</guid>
      <dc:creator>rmavila</dc:creator>
      <dc:date>2010-11-22T12:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: translation status</title>
      <link>https://community.cisco.com/t5/network-security/translation-status/m-p/1562907#M597904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, that clears it.&lt;/P&gt;&lt;P&gt;Now , if suppose the connection has a problem for any reasons &amp;amp; is not working. would i still be seeing translate like this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Nov 2010 14:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-status/m-p/1562907#M597904</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2010-11-22T14:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: translation status</title>
      <link>https://community.cisco.com/t5/network-security/translation-status/m-p/1562908#M597905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, The ASA might be building an xlate, but for example there might not be return traffic coming back.&lt;/P&gt;&lt;P&gt;You woule need to investigate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest to use command "capture capout interface outside match ip host &lt;REMOT ip="" address=""&gt; any" and after testing doing "sh cap capout" to see if you are sending the packets to the remote site and if there are packets coming back.&lt;/REMOT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Nov 2010 17:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-status/m-p/1562908#M597905</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-11-22T17:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: translation status</title>
      <link>https://community.cisco.com/t5/network-security/translation-status/m-p/1562909#M597906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks. following is a trace from asa for the packet flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.200.5 - host&lt;/P&gt;&lt;P&gt;2.2.2.2 - internet based service&lt;/P&gt;&lt;P&gt;3.3.3.3 - public ip for host 192.168.100.5 ( nat done on asa )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat ( local ) 1 192.168.100.5 255.255.255.255&lt;/P&gt;&lt;P&gt;global ( internet) 1 3.3.3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6 packets captured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 07:20:03.624570 192.168.200.5.39419 &amp;gt; 2.2.2.2.25: S 3942230736:3942230736(0) win 8192 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 2: 07:20:03.632047 2.2.2.2.25 &amp;gt; 192.168.200.5.39419: S 2209827644:2209827644(0) ack 3942230737 win 8192 &lt;MSS 1380=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 3: 07:20:03.719887 192.168.200.5.39419 &amp;gt; 2.2.2.2.25: . ack 2209827645 win 1460&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 4: 07:20:03.726189 2.2.2.2.25 &amp;gt; 192.168.200.5.39419: P 2209827645:2209827739(94) ack 3942230737 win 64860&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 5: 07:20:03.814822 192.168.200.5.39419 &amp;gt; 2.2.2.2.25: P 3942230737:3942230751(14) ack 2209827739 win 64766&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 6: 13:50:04.013579 2.2.2.2.25 &amp;gt; 192.168.200.5.39419: . ack 3942230751 win 64846&lt;/P&gt;&lt;P&gt;____________&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1: 07:29:03.137276 3.3.3.3.24363 &amp;gt; 2.2.2.2.25: S 1840215282:1840215282(0) win 8192 &lt;MSS 1380=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 2: 07:29:03.142967 2.2.2.2.25 &amp;gt; 3.3.3.3.24363: S 762906101:762906101(0) ack 1840215283 win 8192 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 3: 07:29:03.146644 3.3.3.3.24363 &amp;gt; 2.2.2.2.25: . ack 762906102 win 1460&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 4: 07:29:03.153724 2.2.2.2.25 &amp;gt; 3.3.3.3.24363: P 762906102:762906196(94) ack 1840215283 win 64860&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 5: 07:29:03.157599 3.3.3.3.24363 &amp;gt; 2.2.2.2.25: P 1840215283:1840215297(14) ack 762906196 win 64766&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 6: 07:29:03.344052 2.2.2.2.25 &amp;gt; 3.3.3.3.24363: . ack 1840215297 win 64846&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 7: 07:29:05.164099 2.2.2.2.25 &amp;gt; 3.3.3.3.24363: P 762906196:762906228(32) ack 1840215297 win 64846&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 8: 07:29:05.168661 3.3.3.3.24363 &amp;gt; 2.2.2.2.25: P 1840215297:1840215303(6) ack 762906228 win 64734&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 9: 07:29:05.168722 3.3.3.3.24363 &amp;gt; 2.2.2.2.25: F 1840215303:1840215303(0) ack 762906228 win 64734&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10: 07:29:05.175573 2.2.2.2.25 &amp;gt; 3.3.3.3.24363: . ack 1840215304 win 64840&lt;/P&gt;&lt;P&gt;&amp;nbsp; 11: 07:29:05.175741 2.2.2.2.25 &amp;gt; 3.3.3.3.24363: P 762906228:762906276(48) ack 1840215304 win 64840&lt;/P&gt;&lt;P&gt;&amp;nbsp; 12: 07:29:05.175772 2.2.2.2.25 &amp;gt; 3.3.3.3.24363: F 762906276:762906276(0) ack 1840215304 win 64840&lt;/P&gt;&lt;P&gt;&amp;nbsp; 13: 07:29:05.179296 3.3.3.3.24363 &amp;gt; 2.2.2.2.25: R 1840215304:1840215304(0) ack 762906276 win 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; 14: 14:01:33.674754 3.3.3.3.13197 &amp;gt; 2.2.2.2.25: S 3161967592:3161967592(0) win 8192 &lt;MSS 1380=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My sight dont see any wrong with the flow. however emails cant be sent out from hosts.&lt;/P&gt;&lt;P&gt;packet trace gives allowed flow for each stage.&lt;/P&gt;&lt;P&gt;I also tried permitting tls under mail policy map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other part remaining to be checked on the asa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: suthomas1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Nov 2010 06:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/translation-status/m-p/1562909#M597906</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2010-11-23T06:27:34Z</dc:date>
    </item>
  </channel>
</rss>

