<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA STATIC NAT ISSUE in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513949#M635494</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I remove the current static nat and then apply yours and test the status?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Nov 2010 07:37:46 GMT</pubDate>
    <dc:creator>arumugasamy</dc:creator>
    <dc:date>2010-11-04T07:37:46Z</dc:date>
    <item>
      <title>ASA STATIC NAT ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513947#M635492</link>
      <description>&lt;P&gt;Pros,&lt;/P&gt;&lt;P&gt;ASA firewall with 3 zones inside,outside,dmz are configured. The front end email server in dmz was natted to the public IP (static NAT) and MX&amp;nbsp; record also updated.&lt;/P&gt;&lt;P&gt;The firewall outside IP is x.x.x.171 (Public)&lt;/P&gt;&lt;P&gt;Email Nated IP address x.x.x.170 (Public)&lt;/P&gt;&lt;P&gt;show xlate shows &lt;STRONG&gt;global x.x.x.170 local y.y.y.12&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;y.y.y.12 is email front end server in dmz.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat(dmz) 1 0.0.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (ouside) 1 interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (dmz,outside) x.x.x.170 y.y.y.12 netmask 255.255.255.25&lt;/STRONG&gt;5.&lt;/P&gt;&lt;P&gt;ACL applied in outside with required ports are opened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is that the user get the email and the header shows that it received with &lt;STRONG&gt;public IP x.x.x.171&lt;/STRONG&gt; of firewall outside interface instead of the MX record &lt;STRONG&gt;IP of x.x.x.170&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we solve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sami&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513947#M635492</guid>
      <dc:creator>arumugasamy</dc:creator>
      <dc:date>2019-03-11T19:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA STATIC NAT ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513948#M635493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sami,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the issue of Source NAT vs Destination NAT. You have not mentioned the version of your software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adding the following line should fix this for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (outside,dmz) y.y.y.12 x.x.x.170 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mubarak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Nov 2010 05:46:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513948#M635493</guid>
      <dc:creator>syedmubarakahmed</dc:creator>
      <dc:date>2010-11-04T05:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA STATIC NAT ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513949#M635494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I remove the current static nat and then apply yours and test the status?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Nov 2010 07:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513949#M635494</guid>
      <dc:creator>arumugasamy</dc:creator>
      <dc:date>2010-11-04T07:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA STATIC NAT ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513950#M635495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No don't remove existing NAT. Add this one as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Nov 2010 08:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513950#M635495</guid>
      <dc:creator>syedmubarakahmed</dc:creator>
      <dc:date>2010-11-04T08:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA STATIC NAT ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513951#M635496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed, this is incorrect, you shouldn't need to add the following line:&lt;/P&gt;&lt;P&gt;static (outside,dmz) y.y.y.12 x.x.x.170 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arumugasamy, the existing static NAT statement is already sufficient:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (dmz,outside) x.x.x.170 y.y.y.12 netmask 255.255.255.25&lt;/STRONG&gt;5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please kindly perform a "clear xlate" to clear existing connection. You might be using the .171 earlier before configuring the static NAT statement therefore it still uses .171 for outbound mail (as you have nat/global pair statements) for outbound traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Nov 2010 10:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513951#M635496</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-04T10:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA STATIC NAT ISSUE</title>
      <link>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513952#M635497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try creating a more specific NAT to achieve this for outbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat(dmz) 2 &lt;/STRONG&gt;&lt;STRONG&gt;y.y.y.12 255.255.255.255&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (ouside) 2 &lt;/STRONG&gt;&lt;STRONG&gt;x.x.x.170 netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Feb 2011 04:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-static-nat-issue/m-p/1513952#M635497</guid>
      <dc:creator>syedmubarakahmed</dc:creator>
      <dc:date>2011-02-16T04:16:01Z</dc:date>
    </item>
  </channel>
</rss>

