<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with a Cisco ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560795#M615272</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The version of the ASA is 8.23 (asa823-k8.bin) and it's a base license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I applied the class-map for tcp state bypass to global_policy but I still have the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;EM&gt;access-list TCP_STATE_BYPASS extended permit ip 10.0.2.0 255.255.255.0 10.0.3.0 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;EM&gt;class-map TCP_STATE_BYPASS&lt;BR /&gt;match access-list TCP_STATE_BYPASS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;class TCP_STATE_BYPASS&lt;BR /&gt;&amp;nbsp; set connection random-sequence-number disable&lt;BR /&gt;&amp;nbsp; set connection advanced-options tcp-state-bypass&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I don't know very well MPF witch class-map so I think I'll use the solution with nail option and failover timeout...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;For information, I post the output for the command:&lt;STRONG&gt; packet-tracer input inside tcp 10.0.2.10 1234 10.0.3.10 80 det&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 1&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: UN-NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: static&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.3.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.3.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 24&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;NAT divert to egress interface Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Untranslate 10.0.3.0/0 to 10.0.3.0/0 using netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 2&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: ACCESS-LIST&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: log&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;access-group ACL_Inside_IN in interface Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;access-list ACL_Inside_IN extended permit ip any any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd7d35db8, priority=12, domain=permit, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=1157, user_data=0xd64581c0, cs_id=0x0, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 3&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: IP-OPTIONS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd741aec0, priority=0, domain=inspect-ip-options, deny=true&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=49334, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 4&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.2.0 10.0.2.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.2.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.2.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 24, untranslate_hits = 4368&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Static translate 10.0.2.0/0 to 10.0.2.0/0 using netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd7625540, priority=5, domain=nat, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=24, user_data=0xd7d000f0, cs_id=0x0, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=10.0.2.0, mask=255.255.255.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 5&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: host-limits&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Outside) 10.0.1.10. 10.0.2.10 netmask 255.255.255.255&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside host 10.0.2.10 Outside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.68.226.9&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 3325, untranslate_hits = 385&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd81111a8, priority=5, domain=host, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=4396, user_data=0xd7419798, cs_id=0x0, reverse, flags=0x0, protocol&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=10.0.2.10, mask=255.255.255.255, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 6&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: rpf-check&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.3.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.3.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 24&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;out id=0xd8103678, priority=5, domain=nat-reverse, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=24, user_data=0xd7d44800, cs_id=0x0, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=10.0.3.0, mask=255.255.255.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 7&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: host-limits&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.3.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.3.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 24&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Reverse Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd8103710, priority=5, domain=host, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=34, user_data=0xd7d44800, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=10.0.3.0, mask=255.255.255.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 8&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: IP-OPTIONS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Reverse Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd741aec0, priority=0, domain=inspect-ip-options, deny=true&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=49336, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 9&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: FLOW-CREATION&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;New flow created with id 45678, packet dispatched to next module&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Module information for forward flow ...&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tracer_drop&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_inspect_ip_options&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tcp_normalizer&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_translate&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_adjacency&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_fragment&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_ifc_stat&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Module information for reverse flow ...&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tracer_drop&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_inspect_ip_options&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_translate&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tcp_normalizer&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_adjacency&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_fragment&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_ifc_stat&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;input-interface: Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;input-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;input-line-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;output-interface: Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;output-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri;"&gt;&lt;EM&gt;output-line-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri;"&gt;&lt;EM&gt;Action: allow&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Dec 2010 09:13:00 GMT</pubDate>
    <dc:creator>frbachel05</dc:creator>
    <dc:date>2010-12-16T09:13:00Z</dc:date>
    <item>
      <title>Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560782#M615249</link>
      <description>&lt;P&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;I post this message because I encounter a problem&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt; with my Cisco ASA&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Quick Schema:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;/SPAN&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/9/4/9493-schema%20reseau.jpg" alt="schema reseau.jpg" class="jive-image-thumbnail jive-image" height="375" onclick="" width="768" /&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Plan:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;The network 10.0.2.0 must have access to:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Internet via the interface 10.0.1.1&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Client network 10.0.3.0 via a Citrix connection&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Internet access:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- NAT rule:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;global (outside) 1 interface&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;nat (inside) 1 10.0.2.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Default route:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Outside route 0.0.0.0 0.0.0.0 10.0.1 1 1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG style="text-decoration: underline; "&gt;Network Access Client:&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Added the way to the client network that has no IP interface on the FW:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;route inside 10.0.3.0 255.255.255.0 10.0.2.1 1&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Order &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt;&lt;/SPAN&gt; to enter and exit from the same interface.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Adding a NAT Exempt to join the client:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Access-list extended permit ip 10.0.2.0 IN_NAT_0 10.0.3.0 255.255.255.0 255.255.255.0&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I'm not sure that this rule is necessary ...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG style="text-decoration: underline; "&gt;Result:&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;From the LAN 10.0.2.0, I go on internet with NAT rule but i can't connect to the network client 10.0.3.0.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;For info:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- NAT for the client network is managed by the client router.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- When I add the route10.0.3.0 255.255.255.0 10.0.2.1 directly on client PC, il doesn't pass through the firewall and it works. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So, there is &lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;a problem with my FW config.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Logs:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;Errors: portmap translation creation failed for udp src inside: 10.0.2.10 / X dst inside: 10.0.3.X / X&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I don't understand the link with my problem...&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Config ASA:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I reset the config &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;and i have not others config on the FW&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Questions?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Should I add specific commands to access a network that is not directly connected to the FW from a network who is?&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Normally, with&amp;nbsp; the command &lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt;, you can enter&amp;nbsp; and exit through the same interface...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box" lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Thank you in advance for your help and sorry for my poor english!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560782#M615249</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2019-03-11T19:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560783#M615250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic from 10.0.2.0/24 to 10.0.3.0/24 should not go through the ASA (both are Inside from the ASA perspective). &lt;BR /&gt;However, if your setup mandates to communicate both networks through the ASA, try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface &lt;BR /&gt;static (in,in) 10.0.2.0 10.0.2.0 netmask 255.255.255.0 &lt;BR /&gt;static (in,in) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure if there's an ACL applied to the inside interface that is permitting this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Dec 2010 19:12:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560783#M615250</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-13T19:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560784#M615251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help! &lt;/P&gt;&lt;P&gt;I test tomorrow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Dec 2010 23:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560784#M615251</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-13T23:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560785#M615252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had the commands below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface &lt;BR /&gt;static (in,in) 10.0.2.0 10.0.2.0 netmask 255.255.255.0 &lt;BR /&gt;static (in,in) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And a ACL for testing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACLINSIDE_IN extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I still have the problem &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 09:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560785#M615252</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-14T09:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560786#M615253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I post the config for more details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.2(3)&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0.705&lt;BR /&gt; vlan 705&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.0.2.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 10.0.1.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.0.4.0 255.255.255.0&lt;BR /&gt; management-only&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;access-list ACLOUTSIDE_IN extended permit ip any host 10.0.1.10&lt;BR /&gt;access-list ACLINSIDE_IN extended permit ip any any&lt;BR /&gt;access-list IN_NAT0 remark NAT exempt 10.0.3.0&lt;BR /&gt;access-list IN_NAT0 extended permit ip 10.0.3.0 255.252.0.0 10.0.2.0 255.255.255.0&lt;BR /&gt;access-list IN_NAT0 extended permit ip 10.0.2.0 255.255.255.0 10.0.3.0 255.255.252.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging host outside X.X.X.X&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-634-53.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list IN_NAT0&lt;BR /&gt;nat (inside) 1 10.0.2.0 255.255.255.0&lt;BR /&gt;static (inside,outside) 10.0.1.10 10.0.2.10 netmask 255.255.255.255&lt;BR /&gt;access-group ACLINSIDE_IN in interface inside&lt;BR /&gt;access-group ACLOUTSIDE_IN in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 10.0.1.1 1&lt;BR /&gt;route management X.X.X.X 255.255.255.255 X.X.X.X 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;username admin password d/N8a6sCspr9dLCz encrypted privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;Cryptochecksum:94cd9ffbc575d2a8acd49ee109e6b1ca&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 10:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560786#M615253</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-14T10:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560787#M615254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Francois,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; Config looks ok to me. Post the output of the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;packet-tracer input inside icmp 10.0.2.10 8 0 10.0.3.10 detail&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should give us a better idea of what's going wrong. I suppose you are still seeing the &lt;STRONG&gt;portmap translation&lt;/STRONG&gt; errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 14:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560787#M615254</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-12-14T14:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560788#M615255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I post the output of the following comand:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;packet-tracer input inside icmp 10.0.2.10 8 0 10.0.3.10 detail&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="FR"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt;in id=0xd74189b8, priority=1, domain=permit, deny=false&lt;/P&gt;&lt;P&gt;hits=522199, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;/P&gt;&lt;P&gt;src mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;dst mac=0000.0000.0000, mask=0100.0000.0000&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;match ip inside 10.0.3.0 255.255.255.0 inside any&lt;/P&gt;&lt;P&gt;static translation to 10.0.3.0&lt;/P&gt;&lt;P&gt;translate_hits = 0, untranslate_hits = 1&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface inside&lt;/P&gt;&lt;P&gt;Untranslate 10.0.3.0/0 to 10.0.3.0/0 using netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group ACLINSIDE_IN in interface inside&lt;/P&gt;&lt;P&gt;access-list ACLINSIDE_IN extended permit ip any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt;in id=0xd8074fb8, priority=12, domain=permit, deny=false&lt;/P&gt;&lt;P&gt;hits=21446, user_data=0xd64581c0, cs_id=0x0, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt;in id=0xd741aec0, priority=0, domain=inspect-ip-options, deny=true&lt;/P&gt;&lt;P&gt;hits=41873, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt;in id=0xd741ab38, priority=66, domain=inspect-icmp-error, deny=false&lt;/P&gt;&lt;P&gt;hits=2024, user_data=0xd7654958, cs_id=0x0, use_real_addr, flags=0x0, protocol=1&lt;/P&gt;&lt;P&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.0.2.0 10.0.2.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;match ip inside 10.0.2.0 255.255.255.0 inside any&lt;/P&gt;&lt;P&gt;static translation to 10.2.2.0&lt;/P&gt;&lt;P&gt;translate_hits = 1, untranslate_hits = 1089&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 10.0.2.0 /0 to 10.0.2.0/0 using netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt;in id=0xd754a088, priority=5, domain=nat, deny=false&lt;/P&gt;&lt;P&gt;hits=2, user_data=0xd76a17d8, cs_id=0x0, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;src ip=10.0.2.0, mask=255.255.255.0, port=0&lt;/P&gt;&lt;P&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: host-limits&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.0.1.10 10.0.2.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;match ip inside host 10.0.2.10 outside any&lt;/P&gt;&lt;P&gt;static translation to 10.0.1.10&lt;/P&gt;&lt;P&gt;translate_hits = 1046, untranslate_hits = 105&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt;in id=0xd81111a8, priority=5, domain=host, deny=false&lt;/P&gt;&lt;P&gt;hits=1130, user_data=0xd7419798, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;src ip=10.0.2.10, mask=255.255.255.255, port=0&lt;/P&gt;&lt;P&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;match ip inside 10.0.3.0 255.255.255.0 inside any&lt;/P&gt;&lt;P&gt;static translation to 10.0.3.0&lt;/P&gt;&lt;P&gt;translate_hits = 0, untranslate_hits = 1&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt;out id=0xd5b50ad8, priority=5, domain=nat-reverse, deny=false&lt;/P&gt;&lt;P&gt;hits=1, user_data=0xd76d9e00, cs_id=0x0, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;dst ip=10.0.3.0, mask=255.255.255.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;Phase: 9&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 40017, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Module information for forward flow ...&lt;/P&gt;&lt;P&gt;snp_fp_tracer_drop&lt;/P&gt;&lt;P&gt;snp_fp_inspect_ip_options&lt;/P&gt;&lt;P&gt;snp_fp_translate&lt;/P&gt;&lt;P&gt;snp_fp_adjacency&lt;/P&gt;&lt;P&gt;snp_fp_fragment&lt;/P&gt;&lt;P&gt;snp_ifc_stat&lt;/P&gt;&lt;P&gt;Module information for reverse flow ...&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your information, I don't have any message "portmap translation..." since I add:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-list: Ignore; color: black; mso-ansi-language: EN-US; mso-fareast-font-family: Calibri; "&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri;"&gt;-&lt;/SPAN&gt;&lt;SPAN style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 12pt; mso-ansi-language: EN-US; font-family: Calibri; "&gt;static (inside,inside) 10.0.2.0 10.0.2.0 netmask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-list: Ignore; color: black; mso-ansi-language: EN-US; mso-fareast-font-family: Calibri; "&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri;"&gt;-&lt;/SPAN&gt;&lt;SPAN style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 12pt; mso-ansi-language: EN-US; font-family: Calibri; "&gt;static (inside,inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoListParagraph" style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-list: Ignore; color: black; mso-ansi-language: EN-US; mso-fareast-font-family: Calibri; "&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri;"&gt;-&lt;/SPAN&gt;&lt;SPAN style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-size: 12pt; mso-ansi-language: EN-US; font-family: Calibri; "&gt;access-list ACLINSIDE_IN extended permit ip any any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I have this "level 6" messages when I try a connection to 10.0.3.X from 10.0.2.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;built inbound UDP connection X for inside:10.0.2.10/X (10.0.2.10/X) to inside:10.0.3.X/X(10.0.3.X/X)&lt;/P&gt;&lt;P&gt;teardown UDP connection X for inside:10.0.2.10/X to inside:10.0.3.X/X/X duration 0:00:00 bytes ...&lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 16:15:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560788#M615255</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-14T16:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560789#M615256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Francois,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hmmm. So i think now the issue is with how U-turning works with firewalls. In our case, when we send a packet from 10.0.2.x to 10.0.3.x, the original packet goes through the ASA but the return packet goes directly to the 10.0.2.x host bypassing the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hence, the ASA sees only one direction of traffic and hence will drop all subsequent packets from 10.0.2.x destined to 10.0.3.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of UDP traffic are you passing between 10.0.2.x and 10.0.3.x, If it's DNS, remove the "inspect dns" that may be present under "global_policy".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If TCP traffic is also going to pass between 10.0.2.x to 10.0.3.x, you will need to create tcp state bypass config and also disable seq number randomization. please follow the below document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-13728"&gt;https://supportforums.cisco.com/docs/DOC-13728&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 12pt;"&gt;set connection advanced-opti&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt;"&gt;ons&amp;nbsp; tcp-state-bypass&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you will also need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;set connection random-seq disable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try this out and let me know how it goes!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 16:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560789#M615256</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-12-14T16:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560790#M615258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks Prapanch for your response and the link.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;The first solution below works:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Configuring NAT for both subnets:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;static (inside,inside) 192.168.1.0 192.168.1.0 netmask 255.255.255.0 norandom nailed&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;static (inside,inside) 172.16.10.0 172.16.10.0 netmask 255.255.255.0 norandom nailed&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Adding the &lt;STRONG&gt;nailed&lt;/STRONG&gt; option to the &lt;STRONG&gt;static&lt;/STRONG&gt; command causes TCP state tracking and sequence checking to be skipped for the connection. More info can be found here:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;However, I would like use the second solution with TCP_STATE_BYPASS and class-map creation who is more secure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;But this solution doesn't works, I still have dropped TCP connections.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;- I created a class-map "TCP_STATE_BYPASS"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;- I match access-list TCP_STATE_BYPASS (access-list TCP_STATE_BYPASS extended permit ip 10.0.2.0 255.255.255.0 10.0.3.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;- I created a policy-map "inside_policy" and I added the class-map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;- On the policy-map I added the commands:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; set connection random-sequence-number disable&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; set connection advanced-options tcp-state-bypass&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;- Finally, I linked the policy-map to the service-policy and the service-policy to the interface "inside"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; "&gt;But I still have the policy-map global_policy enabled on all the interfaces.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; "&gt;Is this a problem? I understand that a service-policy on an interface was priorituy on the global_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;class-map TCP_STATE_BYPASS&lt;BR /&gt; match access-list TCP_STATE_BYPASS&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map inside_policy&lt;BR /&gt; class TCP_STATE_BYPASS&lt;BR /&gt;&amp;nbsp; set connection random-sequence-number disable&lt;BR /&gt;&amp;nbsp; set connection advanced-options tcp-state-bypass&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;service-policy inside_policy interface Inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks in advance for your help&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 13:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560790#M615258</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-15T13:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560791#M615259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the packet-tracer here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp 10.0.2.10 1234 10.0.3.10 80 det&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, just to clarify, the config does look good. @ servicepolocies should not cause an issue. But in our case, you can apply the calss-map for tcp state bypass to global_policy" itself like below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;class TCP_STATE_BYPASS&lt;BR /&gt;&amp;nbsp; set&amp;nbsp; connection random-sequence-number disable&lt;BR /&gt;&amp;nbsp; set connection&amp;nbsp; advanced-options tcp-state-bypass&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case, you can remove the service-policy from the inside interface. What version ar you running on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 14:47:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560791#M615259</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-12-15T14:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560792#M615262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fancois,&lt;/P&gt;&lt;P&gt;Can we address this problem a little different?&amp;nbsp; The right way to fix this issue is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When 10.0.2.0/24 and 10.0.3.0/24 want to talk with each other, these packets should not come to the firewall.&amp;nbsp; The router should be able to do the routing and these packets should not arrive on the firewall.&amp;nbsp; Is this not possible in your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the GW configured on the clients in the 10.0.2.0/24 are pointing to the firewall, then we need to swap the IP addresses between the ASA and the router and give the router the IP address or the firewall and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router should only have a default route pointing to the firewall for any route it does not know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 14:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560792#M615262</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-15T14:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560793#M615265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="almost_half_cell" id="gt-res-content"&gt;Hi,&lt;/DIV&gt;&lt;DIV class="almost_half_cell"&gt; &lt;/DIV&gt;&lt;DIV class="almost_half_cell"&gt;I know that the network infrastructure is not optimized but I can't change&lt;/DIV&gt;&lt;DIV class="almost_half_cell"&gt;I don't have access to the client router in 10.0.3.1 so the default gateway on 10.0.2.0 must be the ASA.&lt;/DIV&gt;&lt;DIV class="almost_half_cell"&gt; &lt;/DIV&gt;&lt;DIV class="almost_half_cell"&gt;Regards&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 15:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560793#M615265</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-15T15:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560794#M615268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I were you, I would track the folks who manage the router and get this think configured the right way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides that like Prapanch says tcp state bypass is another option. All tcp packets will be treated like udp packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 22:38:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560794#M615268</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-15T22:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560795#M615272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The version of the ASA is 8.23 (asa823-k8.bin) and it's a base license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I applied the class-map for tcp state bypass to global_policy but I still have the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;EM&gt;access-list TCP_STATE_BYPASS extended permit ip 10.0.2.0 255.255.255.0 10.0.3.0 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;EM&gt;class-map TCP_STATE_BYPASS&lt;BR /&gt;match access-list TCP_STATE_BYPASS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;class TCP_STATE_BYPASS&lt;BR /&gt;&amp;nbsp; set connection random-sequence-number disable&lt;BR /&gt;&amp;nbsp; set connection advanced-options tcp-state-bypass&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I don't know very well MPF witch class-map so I think I'll use the solution with nail option and failover timeout...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;For information, I post the output for the command:&lt;STRONG&gt; packet-tracer input inside tcp 10.0.2.10 1234 10.0.3.10 80 det&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 1&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: UN-NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: static&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.3.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.3.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 24&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;NAT divert to egress interface Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Untranslate 10.0.3.0/0 to 10.0.3.0/0 using netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 2&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: ACCESS-LIST&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: log&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;access-group ACL_Inside_IN in interface Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;access-list ACL_Inside_IN extended permit ip any any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd7d35db8, priority=12, domain=permit, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=1157, user_data=0xd64581c0, cs_id=0x0, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 3&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: IP-OPTIONS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd741aec0, priority=0, domain=inspect-ip-options, deny=true&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=49334, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 4&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.2.0 10.0.2.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.2.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.2.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 24, untranslate_hits = 4368&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Static translate 10.0.2.0/0 to 10.0.2.0/0 using netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd7625540, priority=5, domain=nat, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=24, user_data=0xd7d000f0, cs_id=0x0, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=10.0.2.0, mask=255.255.255.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 5&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: host-limits&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Outside) 10.0.1.10. 10.0.2.10 netmask 255.255.255.255&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside host 10.0.2.10 Outside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.68.226.9&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 3325, untranslate_hits = 385&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd81111a8, priority=5, domain=host, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=4396, user_data=0xd7419798, cs_id=0x0, reverse, flags=0x0, protocol&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=10.0.2.10, mask=255.255.255.255, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 6&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: rpf-check&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.3.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.3.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 24&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Forward Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;out id=0xd8103678, priority=5, domain=nat-reverse, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=24, user_data=0xd7d44800, cs_id=0x0, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=10.0.3.0, mask=255.255.255.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 7&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: NAT&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype: host-limits&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;static (Inside,Inside) 10.0.3.0 10.0.3.0 netmask 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;match ip Inside 10.0.3.0 255.255.255.0 Inside any&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static translation to 10.0.3.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 24&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Reverse Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd8103710, priority=5, domain=host, deny=false&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=34, user_data=0xd7d44800, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=10.0.3.0, mask=255.255.255.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 8&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: IP-OPTIONS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Reverse Flow based lookup yields rule:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;in&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;id=0xd741aec0, priority=0, domain=inspect-ip-options, deny=true&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;hits=49336, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Phase: 9&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Type: FLOW-CREATION&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Subtype:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result: ALLOW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Config:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Additional Information:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;New flow created with id 45678, packet dispatched to next module&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Module information for forward flow ...&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tracer_drop&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_inspect_ip_options&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tcp_normalizer&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_translate&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_adjacency&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_fragment&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_ifc_stat&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Module information for reverse flow ...&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tracer_drop&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_inspect_ip_options&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_translate&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_tcp_normalizer&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_adjacency&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_fp_fragment&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;snp_ifc_stat&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;Result:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;input-interface: Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;input-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;input-line-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;output-interface: Inside&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; mso-ansi-language: EN-US;"&gt;&lt;EM&gt;output-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri;"&gt;&lt;EM&gt;output-line-status: up&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri;"&gt;&lt;EM&gt;Action: allow&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 09:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560795#M615272</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-16T09:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560796#M615276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, it works with class-map and policy-map.&lt;/P&gt;&lt;P&gt;I made a mistake with the ACL TCP_STATE_BYPASS (bad network).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2010 16:38:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560796#M615276</guid>
      <dc:creator>frbachel05</dc:creator>
      <dc:date>2010-12-20T16:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with a Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560797#M615278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey glad to know that. Please mark this as answered if all is done. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2010 17:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-a-cisco-asa-5510/m-p/1560797#M615278</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-12-20T17:43:17Z</dc:date>
    </item>
  </channel>
</rss>

