<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reg packet tracer in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466812#M642159</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the response . please find attached the config containing the nat order .Also i need to know the meaning of host-limits over here as well as&lt;/P&gt;&lt;P&gt;rpf-check.The ASA Software version is 7.2(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt; Subtype: rpf-check&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jun 2010 00:57:58 GMT</pubDate>
    <dc:creator>ankurs2008</dc:creator>
    <dc:date>2010-06-09T00:57:58Z</dc:date>
    <item>
      <title>Reg packet tracer</title>
      <link>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466810#M642156</link>
      <description>&lt;P&gt;Hi halijenn / pkampana / all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A sample output of packet tracer is as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know what is the exact meaning of the following type of NAT Outputs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt; Subtype: rpf-check&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: NAT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (moon) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip moon any aviod any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (172.17.10.2)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in&amp;nbsp; id=0x4cef4b8, priority=1, domain=nat, deny=false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=2746, user_data=0x4cef448, cs_id=0x0, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;/STRONG&gt;&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (moon) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip moon any moon any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (10.0.0.2)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in&amp;nbsp; id=0x4ceeda8, priority=1, domain=host, deny=false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=9082, user_data=0x4ceeb98, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Phase: 9&lt;BR /&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;/STRONG&gt;&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (aviod) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip aviod any moon any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (10.0.0.2)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 86, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; out id=0x4cf41a8, priority=1, domain=nat-reverse, deny=false&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=2746, user_data=0x4cf4008, cs_id=0x0, flags=0x0, protocol=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: moon&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: aviod&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466810#M642156</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2019-03-11T17:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Reg packet tracer</title>
      <link>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466811#M642158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is probably because your packets hit a rule inbound but the return traffic will hit another one.&lt;/P&gt;&lt;P&gt;Is it ASA 8.3?&lt;/P&gt;&lt;P&gt;Check the order of your nat statements and which ones you would hit for forward and backwards flow.&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jun 2010 00:02:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466811#M642158</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-06-09T00:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Reg packet tracer</title>
      <link>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466812#M642159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the response . please find attached the config containing the nat order .Also i need to know the meaning of host-limits over here as well as&lt;/P&gt;&lt;P&gt;rpf-check.The ASA Software version is 7.2(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Type: NAT&lt;BR /&gt; Subtype: rpf-check&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jun 2010 00:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466812#M642159</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-09T00:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Reg packet tracer</title>
      <link>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466813#M642160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please look into this and reply to my query&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jun 2010 23:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466813#M642160</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-09T23:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Reg packet tracer</title>
      <link>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466814#M642161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;need urgent help on this , can anyone please explain my query&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 22:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466814#M642161</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-10T22:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Reg packet tracer</title>
      <link>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466815#M642162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The poroblem I see is that moon and aviod are same security interface, but you are also doing nat 1 for everything from either interface and also have global 1 configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing you can try is to create an identity NAT to itself for traffic going from either interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (moon,aviod) 10.0.0.0 10.0.0.0 netmask 255.255.0.0&lt;/P&gt;&lt;P&gt;static ( aviod,moon) 172.17.10.0 172.17.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then do clear xlate. and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is still problems, you can think of changing the sequence numbers you are using for the nat and global for the moon and the aviod interface, so they are not doing dynamic nat when going between interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rpf is reverse path forwarding check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host limit is the number of host limit for nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 22:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reg-packet-tracer/m-p/1466815#M642162</guid>
      <dc:creator>edadios</dc:creator>
      <dc:date>2010-06-10T22:59:20Z</dc:date>
    </item>
  </channel>
</rss>

