<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One public IP using PAT to two internal deviecs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468864#M613541</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When ASA is in production, it has same internal IP address that is set as the default gateway for the subnet and no traffic registers on the ACL for SMTP, 3389 or 443.&amp;nbsp; It is like there is another default/hidden ACL that is blocking the traffic.&amp;nbsp; The results of the show access-list does not show any hits on the specified public address nor the PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going to reset the device to factory defaults and build the configuration from scratch.&amp;nbsp; I'll report back the results.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Aug 2010 11:56:27 GMT</pubDate>
    <dc:creator>ddrodge</dc:creator>
    <dc:date>2010-08-25T11:56:27Z</dc:date>
    <item>
      <title>One public IP using PAT to two internal deviecs</title>
      <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468860#M613526</link>
      <description>&lt;P&gt;I have a scenerio whereby one public IP is directed to two internal private IP using PAT.&amp;nbsp; A PIX501 is currently in production and an ASA5505 is scheduled to be installed.&amp;nbsp; If the configuration from the PIX501 is ported to the ASA5505 and the devices switched (DSL modem is power cycled), Internat traffic flows through the ASA5505 but inbound traffic to the two devices (SPAM filter and Exchange Server) stops.&amp;nbsp; If I change the ASA 5505 out for the PIX501 (again DSL is powered cycled), traffic flows as designed.&lt;/P&gt;&lt;P&gt;I have attached the current config on the ASA5505.&amp;nbsp; ASA is running 8.2(2)&lt;/P&gt;&lt;P&gt;Can someone help to find where the issue lies on the ASA5505, thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468860#M613526</guid>
      <dc:creator>ddrodge</dc:creator>
      <dc:date>2019-03-11T18:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: One public IP using PAT to two internal deviecs</title>
      <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468861#M613530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you switched your hardware, did you reboot the ISP router? Your&lt;/P&gt;&lt;P&gt;configuration looks good. Most likely, your ISP has cached the PIX MAC for&lt;/P&gt;&lt;P&gt;the SMTP IP. Please reboot the ISP router or bounce the ISP port and see if&lt;/P&gt;&lt;P&gt;that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Aug 2010 19:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468861#M613530</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-24T19:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: One public IP using PAT to two internal deviecs</title>
      <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468862#M613534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply, Yes in all cases I power-cycled the DSL modem when switching the ASA for the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should the switch on the inside also be power-cycled as the inside MAC change as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dereck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Aug 2010 19:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468862#M613534</guid>
      <dc:creator>ddrodge</dc:creator>
      <dc:date>2010-08-24T19:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: One public IP using PAT to two internal deviecs</title>
      <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468863#M613537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, the inside should not matter. When you put it back in production, can&lt;/P&gt;&lt;P&gt;you check the access-list hit counts to see if the packets are hitting the&lt;/P&gt;&lt;P&gt;outside interface of the firewall? Also, what is the default gateway of the&lt;/P&gt;&lt;P&gt;servers? Are they pointing to the ASA inside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Aug 2010 19:27:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468863#M613537</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-24T19:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: One public IP using PAT to two internal deviecs</title>
      <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468864#M613541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When ASA is in production, it has same internal IP address that is set as the default gateway for the subnet and no traffic registers on the ACL for SMTP, 3389 or 443.&amp;nbsp; It is like there is another default/hidden ACL that is blocking the traffic.&amp;nbsp; The results of the show access-list does not show any hits on the specified public address nor the PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going to reset the device to factory defaults and build the configuration from scratch.&amp;nbsp; I'll report back the results.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 11:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468864#M613541</guid>
      <dc:creator>ddrodge</dc:creator>
      <dc:date>2010-08-25T11:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: One public IP using PAT to two internal deviecs</title>
      <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468865#M613544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not seeing any hits on the outside interface ACL, most likely&lt;/P&gt;&lt;P&gt;your DSL modem/ISP router has wrong ARP entry for the second IP. Is the DSL&lt;/P&gt;&lt;P&gt;modem in Bridged mode? If so, can you please ask your ISP what MAC entry&lt;/P&gt;&lt;P&gt;they have for the SMTP address? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 13:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468865#M613544</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-25T13:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: One public IP using PAT to two internal deviecs</title>
      <link>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468866#M613548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 10pt;"&gt;The issue was in an upstream network device that was holding the incorrect ARP entry for the other IP Addresses.&amp;nbsp; Waiting past the 60 minute timeout on the ARP table of the upstream device (independent of the ISP DSL modem) and traffic flowed.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 12:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-public-ip-using-pat-to-two-internal-deviecs/m-p/1468866#M613548</guid>
      <dc:creator>ddrodge</dc:creator>
      <dc:date>2010-08-30T12:42:29Z</dc:date>
    </item>
  </channel>
</rss>

