<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problems w/ PAT under 8.3 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636319#M615094</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;nat pool and interface PAT for the DMZ network:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network &lt;BR /&gt; subnet 172.16.0.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt; object network DMZ_nat_pool &lt;BR /&gt; range 72.232.6.9 72.232.6.11&lt;BR /&gt; &lt;BR /&gt; object network DMZ_network&lt;BR /&gt; nat(DMZ,outside) dynamic DMZ_nat_pool interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Second PAT in addition to the above&lt;/SPAN&gt; &lt;SPAN style="color: #ff0000;"&gt;for the same DMZ network:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network_1 &lt;BR /&gt;&amp;nbsp; subnet 172.16.0.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_nat_pool &lt;BR /&gt;&amp;nbsp; range 72.232.6.9 72.232.6.11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network second-pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 1.1.1.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network dyn-nat-pat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object object &lt;SPAN class="mediumtext"&gt;DMZ_nat_pool&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object object second-pat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network_1&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="mediumtext"&gt;&amp;nbsp; nat(DMZ,outside) dynamic &lt;/SPAN&gt;dyn-nat-pat interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have added the above as an example in this link: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-9129"&gt;https://supportforums.cisco.com/docs/DOC-9129&lt;/A&gt;&lt;/P&gt;&lt;P&gt;under &lt;STRONG&gt;NAT &amp;amp; Interface PAT with additional PAT together.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Dec 2010 20:19:45 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-12-24T20:19:45Z</dc:date>
    <item>
      <title>problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636311#M615084</link>
      <description>&lt;P&gt;&lt;SPAN class="mediumtext"&gt;We have problems with 8.3 firmware on our ASA. &lt;BR /&gt; I try to configure pooled-dynamic-pat and it appears that it is natting properly but doesn\'t do pat but instead does pooled-nat. &lt;BR /&gt; &lt;BR /&gt; According to: &lt;BR /&gt; &lt;A href="https://community.cisco.com/document/33921/asa-pre-83-83-nat-configuration-examples" target="_blank"&gt;https://supportforums.cisco.com/docs/DOC-9129&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt; object network Inside_network &lt;BR /&gt; subnet 172.16.1.0 255.255.255.0&lt;BR /&gt; description internal_network_object &lt;BR /&gt; object network DMZ_network &lt;BR /&gt; subnet 172.16.0.0 255.255.255.0&lt;BR /&gt; description dmz_network_object &lt;BR /&gt; object network Inside_nat_pool &lt;BR /&gt; range 72.232.6.6 72.232.6.8&lt;BR /&gt; object network DMZ_nat_pool &lt;BR /&gt; range 72.232.6.9 72.232.6.11&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt; I tried both with doule nat rule in global config:&lt;BR /&gt; nat (DMZ,outside) source dynamic DMZ_network DMZ_nat_pool&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt; and also with the local (network object singleton) nat rule&lt;BR /&gt; object network DMZ_network&lt;BR /&gt; nat(DMZ,outside) dynamic DMZ_nat_pool&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt; After pool i exhausted (tried with packettracer and live servers) it returns error message saying it cannot create any new xlate and returns:&lt;BR /&gt; %ASA-3-305006: regular translation creation failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636311#M615084</guid>
      <dc:creator>w951duu</dc:creator>
      <dc:date>2019-03-11T19:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636312#M615085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That link is talking about&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pre 8.3&lt;/P&gt;&lt;PRE&gt; nat (inside) 1 10.1.2.0 255.255.255.0&lt;BR /&gt; global (outside) 1 interface &lt;BR /&gt; global (outside) 1 192.168.100.100-192.168.100.200&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8.3:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt; object network obj-192.168.100.100_192.168.100.200&lt;BR /&gt;&amp;nbsp;&amp;nbsp; range 192.168.100.100 192.168.100.200&lt;BR /&gt; object network obj-10.1.2.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; subnet 10.1.2.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic obj-192.168.100.100_192.168.100.200 interface&lt;BR /&gt;&lt;BR /&gt;But that is not what you have.&lt;BR /&gt;&lt;BR /&gt;Can you try &lt;/PRE&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network&lt;BR /&gt; nat(DMZ,outside) dynamic DMZ_nat_pool interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Dont' miss my ATE event: &lt;/SPAN&gt;&lt;A class="jive-link-community-small" href="https://community.cisco.com/community/netpro/ask-the-expert"&gt;https://supportforums.cisco.com/community/netpro/ask-the-expert&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 18:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636312#M615085</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-23T18:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636313#M615086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are talking about the same thing so please accept my update on this matter:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I did try what you suggested and the result is the same. It is not creating pat-pool over few addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WIth interface keyword it creates a pat over one address (of external IF) and then 1-1 nat pool of the pool object group specified in nat command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT from DMZ:172.16.0.102 to outside:1.1.1.10 flags i idle 0:00:40 timeout 3:00:00&lt;/P&gt;&lt;P&gt;NAT from DMZ:172.16.0.101 to outside:1.1.1.9 flags i idle 0:00:48 timeout 3:00:00&lt;/P&gt;&lt;P&gt;UDP PAT from DMZ:172.16.0.163/41364 to outside:1.1.1.2/64950 flags ri idle 0:00:01 timeout 0:00:30&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;1.1.1.2 is external interface&lt;/DIV&gt;&lt;DIV&gt;.9 and .10 are in the DMZ_nat_pool object range&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When pool gets exhausted by either packet tracer and or real hosts it cannot create any new translations.&lt;/P&gt;&lt;P&gt;When dynamic pat over pool is configured it is not attempting to use the pat anymore It does nat only for the number of hosts that are in the pool and then stops giving error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was also another nat rule with twice-nat so I added it in front of everything:&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) 1 source dynamic DMZ_network DMZ_nat_pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That didn't help too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try using 'interface' keyword that you suggested but also no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I have to reload the box or do anything else than 'clear xlate' to be effective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try deleting DMZ_nat_pool and DMZ_network objects and re-creating them. No luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When looking at the debug there is a message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat: WARNING - alloc socket in pool -1401456072 failed, prot 17/0, DMZ:172.16.0.5/54435 to outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a another idea I tried to do multiple host like mappings for outside traffic hoping it will start doing pat over pool properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config)# object network obj_100&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config-network-object)# host 1.1.1.100&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config-network-object)# exit&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config)# object network obj_101&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config-network-object)# host 1.1.1.101&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config-network-object)# exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config)# nat (DMZ,outside) source dynamic DMZ_network obj_100&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config)# nat (DMZ,outside) source dynamic DMZ_network obj_101&lt;/P&gt;&lt;P&gt;WARNING: Pool (1.1.1.101) overlap with existing pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;When pool is exhausted any new packet generated is giving such error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dfw-prod-asa-01(config)# packet-tracer input DMZ icmp 172.16.0.211 0 0 8.8.8.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: DEBUG-ICMP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) source dynamic DMZ_network DMZ_nat_pool interface&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: DMZ&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Any ideas?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Has anyone seen this behaviour before?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;dfw-prod-asa-01(config)# show ver&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Cisco Adaptive Security Appliance Software Version 8.3(2)&lt;/DIV&gt;&lt;DIV&gt;Device Manager Version 6.2(1)&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Compiled on Fri 30-Jul-10 17:49 by builders&lt;/DIV&gt;&lt;DIV&gt;System image file is "disk0:/asa832-k8.bin"&lt;/DIV&gt;&lt;DIV&gt;Config file at boot was "startup-config"&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;dfw-prod-asa-01 up 2 days 20 hours&lt;/DIV&gt;&lt;DIV&gt;failover cluster up 9 days 10 hours&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Hardware:&amp;nbsp;&amp;nbsp; ASA5510, 1024 MB RAM, CPU Pentium 4 Celeron 1599 MHz&lt;/DIV&gt;&lt;DIV&gt;Internal ATA Compact Flash, 256MB&lt;/DIV&gt;&lt;DIV&gt;BIOS Flash M50FW016 @ 0xfff00000, 2048KB&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;MB&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 10:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636313#M615086</guid>
      <dc:creator>michal.bicz</dc:creator>
      <dc:date>2010-12-24T10:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636314#M615087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls. remove this line:&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) 1 source dynamic DMZ_network DMZ_nat_pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. only use what I had mentioned earlier which is below and see if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network&lt;BR /&gt; nat(DMZ,outside) dynamic DMZ_nat_pool interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 14:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636314#M615087</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-24T14:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636315#M615088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I mentioned it does not work as intended.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside communication is possible but the PAT is only occuring using the external interface IP address (.2) and not the whole pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using your config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;send 4 pings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 executed exhausted the DMZ_nat_pool&lt;/P&gt;&lt;P&gt;then it started PAT over external IP address while it should do PAT over all the IPs from DMZ_nat_pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ICMP PAT from DMZ:172.16.0.165/38958 to outside:1.1.1.2/54843 flags ri idle 0:00:26 timeout 0:00:30&lt;/P&gt;&lt;P&gt;NAT from DMZ:172.16.0.10 to outside:1.1.1.10 flags i idle 0:02:00 timeout 3:00:00&lt;/P&gt;&lt;P&gt;NAT from DMZ:172.16.0.101 to outside:1.1.1.9 flags i idle 0:01:54 timeout 3:00:00&lt;/P&gt;&lt;P&gt;ICMP PAT from DMZ:172.16.0.163/18493 to outside:1.1.1.2/8051 flags ri idle 0:00:02 timeout 0:00:30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ_nat_pool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; range 1.1.1.9 1.1.1.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ_network&lt;/P&gt;&lt;P&gt; subnet 172.16.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt; nat (DMZ,outside) dynamic DMZ_nat_pool interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try to reproduce this error?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 15:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636315#M615088</guid>
      <dc:creator>michal.bicz</dc:creator>
      <dc:date>2010-12-24T15:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636316#M615089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it is working as expected.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;&lt;BR /&gt; object network DMZ_network &lt;BR /&gt; subnet 172.16.0.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt; object network DMZ_nat_pool &lt;BR /&gt; range 72.232.6.9 72.232.6.11&lt;BR /&gt; &lt;BR /&gt; object network DMZ_network&lt;BR /&gt; nat(DMZ,outside) dynamic DMZ_nat_pool interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When&amp;nbsp; the range gets exhaused (DMZ_nat_pool) it is using the interface for PAT. That is what the above command is supposed to do and is doing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see both NAT and PAT in the ouput that you posted above. For ICMP and dynamic NAT - I'd enable icmp inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not clear as to what you are explaining as incorrect behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 16:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636316#M615089</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-24T16:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636317#M615090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think best course of action is to open a case with cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Iphone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Dec 24, 2010, at 9:04 AM, "michal.bicz" &lt;SUPPORTFORUMS-DONOTREPLY&gt;&lt;/SUPPORTFORUMS-DONOTREPLY&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 17:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636317#M615090</guid>
      <dc:creator>w951duu</dc:creator>
      <dc:date>2010-12-24T17:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636318#M615092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to clarify. What you have is nat + masquerade pat. We want to do pat over multiple IPs and apparently this is immposible with 8.3(2)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 18:33:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636318#M615092</guid>
      <dc:creator>michal.bicz</dc:creator>
      <dc:date>2010-12-24T18:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636319#M615094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;nat pool and interface PAT for the DMZ network:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network &lt;BR /&gt; subnet 172.16.0.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt; object network DMZ_nat_pool &lt;BR /&gt; range 72.232.6.9 72.232.6.11&lt;BR /&gt; &lt;BR /&gt; object network DMZ_network&lt;BR /&gt; nat(DMZ,outside) dynamic DMZ_nat_pool interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Second PAT in addition to the above&lt;/SPAN&gt; &lt;SPAN style="color: #ff0000;"&gt;for the same DMZ network:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network_1 &lt;BR /&gt;&amp;nbsp; subnet 172.16.0.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_nat_pool &lt;BR /&gt;&amp;nbsp; range 72.232.6.9 72.232.6.11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network second-pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 1.1.1.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network dyn-nat-pat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object object &lt;SPAN class="mediumtext"&gt;DMZ_nat_pool&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-object object second-pat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="mediumtext"&gt;object network DMZ_network_1&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="mediumtext"&gt;&amp;nbsp; nat(DMZ,outside) dynamic &lt;/SPAN&gt;dyn-nat-pat interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have added the above as an example in this link: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-9129"&gt;https://supportforums.cisco.com/docs/DOC-9129&lt;/A&gt;&lt;/P&gt;&lt;P&gt;under &lt;STRONG&gt;NAT &amp;amp; Interface PAT with additional PAT together.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Dec 2010 20:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636319#M615094</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-24T20:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636320#M615096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still think we are not on the same page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just want to do this and from the traffic and nat table I am unable to do so. I don't need pooled nat but rather a pooled PAT meaning any given host from inside/dmz will be portmaped with the IP from the pool. So in the theory I might have POOL_MEMBERS * 64000 number of connections. &lt;/P&gt;&lt;P&gt;When your config is activated first what is happening is any DMZ host is taking one-by-one members of the pool and because timeout of xlate is longer (3hrs) it stays there in xlate table. Any new connection is then PATed to single IP of .2 with shorter xlate timeout (30s). Essentially this reduces number of connections to only 64000. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show xlate when trying different hosts from DMZ:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP PAT from DMZ:172.16.0.121/8213 to outside:72.232.6.2/33144 flags ri idle 0:00:10 timeout 0:00:30&lt;/P&gt;&lt;P&gt;NAT from DMZ:172.16.0.10 to outside:72.232.6.10 flags i idle 0:01:21 timeout 3:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from DMZ:172.16.0.123/8213 to outside:72.232.6.2/33114 flags ri idle 0:00:05 timeout 0:00:30&lt;/P&gt;&lt;P&gt;NAT from DMZ:172.16.0.11 to outside:72.232.6.9 flags i idle 0:01:10 timeout 3:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from DMZ:172.16.0.120/8213 to outside:72.232.6.2/7174 flags ri idle 0:00:15 timeout 0:00:30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pre 8.3 config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---snip---&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.9&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.5&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.6&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.7&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.8&lt;/P&gt;&lt;P&gt;global (outside) 5 12.2.2.33&lt;/P&gt;&lt;P&gt;nat (Inside) 10 172.17.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (DMZ) 5 access-list acl_outside_1&lt;/P&gt;&lt;P&gt;nat (DMZ) 10 172.17.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---snip---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you create a PAT pool under 8.3(2) that would reflect the above config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;MB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 08:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636320#M615096</guid>
      <dc:creator>michal.bicz</dc:creator>
      <dc:date>2010-12-27T08:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636321#M615099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;I think you didn't refer the sample that I added to this link:&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/docs/DOC-9129"&gt;https://supportforums.cisco.com/docs/DOC-9129&lt;/A&gt;&lt;/P&gt;&lt;P&gt;All you had to do was to add all the pat addresses to the &lt;STRONG style="color: #ff0000; "&gt;object-group&lt;/STRONG&gt;. If you do an upgrade from old 8.2 config to 8.3 the upgrade will automatically do this for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pre 8.3: (only focusing on nat id 10)&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.9&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.5&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.6&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.7&lt;/P&gt;&lt;P&gt;global (outside) 10 1.1.1.8&lt;/P&gt;&lt;P&gt;nat (Inside) 10 172.17.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (DMZ) 10 172.17.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8.3: (I am only providing the conversion for nat ID 10)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ-network&lt;/P&gt;&lt;P&gt;subnet 172.17.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network inside-network&lt;/P&gt;&lt;P&gt;subnet 172.17.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network pat-addr-1&lt;/P&gt;&lt;P&gt;host 1.1.1.9&lt;/P&gt;&lt;P&gt;object network pat-addr-2&lt;/P&gt;&lt;P&gt;host 1.1.1.5&lt;/P&gt;&lt;P&gt;object network pat-addr-3&lt;/P&gt;&lt;P&gt;host 1.1.1.6&lt;/P&gt;&lt;P&gt;object network pat-addr-4&lt;/P&gt;&lt;P&gt;host 1.1.1.7&lt;/P&gt;&lt;P&gt;object network pat-addr-5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network 5-pat-addr&lt;/P&gt;&lt;P&gt;network-object object pat-addr-1&lt;/P&gt;&lt;P&gt;network-object object&amp;nbsp; pat-addr-2&lt;/P&gt;&lt;P&gt;network-object object pat-addr-3&lt;/P&gt;&lt;P&gt;network-object object pat-addr-4&lt;/P&gt;&lt;P&gt;network-object objec pat-addr-5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ-network&lt;/P&gt;&lt;P&gt;nat (DMZ,outside) dynamic 5-pat-addr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network inside-network&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic 5-pat-addr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 15:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636321#M615099</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-27T15:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636322#M615101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;That worked perfectly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 11:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636322#M615101</guid>
      <dc:creator>michal.bicz</dc:creator>
      <dc:date>2010-12-28T11:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: problems w/ PAT under 8.3</title>
      <link>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636323#M615102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear.&amp;nbsp; Thanks for rating. Pls. consider marking this thread answered as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 13:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-w-pat-under-8-3/m-p/1636323#M615102</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-28T13:48:41Z</dc:date>
    </item>
  </channel>
</rss>

