<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 8.0(4) - NAT Issues - Returning Traffic Not Working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-0-4-nat-issues-returning-traffic-not-working/m-p/1547745#M649645</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your swift answer. It was very useful. I'll talk to my customer in order to re-arrange it. The returning traffic was something he didn't comment before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, thanks for this!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Nov 2010 17:02:36 GMT</pubDate>
    <dc:creator>vialves</dc:creator>
    <dc:date>2010-11-09T17:02:36Z</dc:date>
    <item>
      <title>ASA 8.0(4) - NAT Issues - Returning Traffic Not Working</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-4-nat-issues-returning-traffic-not-working/m-p/1547743#M649597</link>
      <description>&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Tabela normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;
	mso-fareast-language:EN-US;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;I have the following problem doing natting in between my inside and dmz_sp interface here is the diagram:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/7/7/8773-untitled%282%29.JPG" alt="untitled(2).JPG" class="jive-image-thumbnail jive-image" width="450" /&gt;&lt;/P&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;P align="center" class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: center;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt 36pt; text-indent: -18pt;"&gt;&lt;SPAN style="font-family: Symbol; font-size: 10pt;"&gt;&lt;SPAN&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;I need to, whenever these three hosts on the &lt;EM&gt;dmz_sp&lt;/EM&gt; access the &lt;EM&gt;inside&lt;/EM&gt;&lt;SPAN style="color: black;"&gt; network, it should be translated to the &lt;EM&gt;Inside&lt;/EM&gt; interface IP &lt;/SPAN&gt;address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt 36pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt 36pt; text-indent: -18pt;"&gt;&lt;SPAN style="font-family: Symbol; font-size: 10pt;"&gt;&lt;SPAN&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Static configuration is not an option, once that they don't have &lt;EM&gt;Inside&lt;/EM&gt; addresses for this;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt 36pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt 36pt; text-indent: -18pt;"&gt;&lt;SPAN style="font-family: Symbol; font-size: 10pt;"&gt;&lt;SPAN&gt;·&lt;SPAN style="font: 7pt &amp;amp;quot;Times New Roman&amp;amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;NAT0 is not an option, because internal network overlaps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="line-height: 115%; font-size: 10pt;"&gt;Based on these needs, I deployed the following configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;nat (dmz_sp) 2 10.241.48.136 255.255.255.255 outside &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;nat (dmz_sp) 2 10.241.48.151 255.255.255.255 outside &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;nat (dmz_sp) 2 10.241.48.171 255.255.255.255 outside&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;global (inside) 2 interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Here's the actual relevant configuration he already had there before I applied the config above:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;no nat-control&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;nat (inside) 0 access-list acl_nonat&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;nat (dmz) 1 access-list ACL_SCAN_MAIL&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;nat (inside) 1 172.16.0.0 255.240.0.0 &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;global (dmz) 1 interface&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;global (dmz_sp) 1 10.120.0.254&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;global (dmz_net) 1 10.120.3.254&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Now, I have the following problem after I added my &lt;EM&gt;dmz_sp&lt;/EM&gt; nat configurartion:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Whenever the hosts in the network on 172.16x.x are trying to access these three servers on &lt;EM&gt;dmz_sp&lt;/EM&gt;, the FW is not even capable to build the connection, showing me the following error message:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Nov 08 2010 16:46:27 FW-1 : %ASA-6-305011: Built dynamic TCP translation from inside:172.21.120.190/1223 to dmz_sp:10.120.0.254/11609&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Nov 08 2010 16:46:27 FW-1 : %ASA-3-305005: No translation group found for tcp src inside:172.21.120.190/1223 dst dmz_sp:10.241.48.136/1433&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;The weird thing is that it shows up in the xlate table but the connection is dropped anyway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US"&gt;The problem doesn't happen when the Inside network is trying to access any different host in the same network on dmz_SP.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Is this an expected behavior? What should be done in order to work around this issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;If any configuration is needed, please let me know. But as I said before, we can assume that routing and permissions are ok.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-4-nat-issues-returning-traffic-not-working/m-p/1547743#M649597</guid>
      <dc:creator>vialves</dc:creator>
      <dc:date>2019-03-11T19:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.0(4) - NAT Issues - Returning Traffic Not Working</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-4-nat-issues-returning-traffic-not-working/m-p/1547744#M649621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the DMZ_SP host is going to look like the inside interface IP address (hiding behind a pat pool) then, why is the inside host 172.21.120.190 trying to access it using its real IP address 10.241.48.136?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With what you have configured only the DMZ_SP hosts can initiate traffic and the inside hosts can only respond to them. Traffic cannot be initiated from the inside hosts to the dmz hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt;Nov&amp;nbsp; 08 2010 16:46:27 FW-1 : %ASA-3-305005: No translation group found for&amp;nbsp; tcp src inside:172.21.120.190/1223 dst dmz_sp:10.241.48.136/1433&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;It appear that you do not have a choice but to use static (inside,dmz_sp) instead of nat/global outside for the dmz hosts.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;Remember you cannot reach the hosts hiding behind a pat pool.&amp;nbsp; This will be like google trying to reach all your inside hosts hiding behind a pat pool. Just not possible unless you configure static NAT or PAT.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;-KS&lt;/P&gt;&lt;P class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 13:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-4-nat-issues-returning-traffic-not-working/m-p/1547744#M649621</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-09T13:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.0(4) - NAT Issues - Returning Traffic Not Working</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-4-nat-issues-returning-traffic-not-working/m-p/1547745#M649645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your swift answer. It was very useful. I'll talk to my customer in order to re-arrange it. The returning traffic was something he didn't comment before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, thanks for this!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 17:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-4-nat-issues-returning-traffic-not-working/m-p/1547745#M649645</guid>
      <dc:creator>vialves</dc:creator>
      <dc:date>2010-11-09T17:02:36Z</dc:date>
    </item>
  </channel>
</rss>

