<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM: NAT issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458174#M654941</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have opened a TAC case for this and the SR is 614803557. i have attached the show-tech and show run of both context...&lt;/P&gt;&lt;P&gt;plz let me know if you need further details...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also find the TAC initial response...&lt;/P&gt;&lt;P&gt;=======================&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Courier; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Sharing an outside interface on the FWSM is supported , But the packet&lt;/P&gt;&lt;P dir="ltr"&gt;classifier relies on active NAT sessions to classify the destination&lt;/P&gt;&lt;P dir="ltr"&gt;addresses to a context, the classifier is limited by how you can&lt;/P&gt;&lt;P dir="ltr"&gt;configure NAT. If you do not want to perform NAT, you must use unique&lt;/P&gt;&lt;P dir="ltr"&gt;interfaces.&lt;/P&gt;&lt;P dir="ltr"&gt;all vlan interfaces of FWSM share the same MAC address, so any kind of&lt;/P&gt;&lt;P dir="ltr"&gt;routing is simply not possible over shared interface - the&lt;/P&gt;&lt;P dir="ltr"&gt;packet classifier receives many packets from external world addressed to&lt;/P&gt;&lt;P dir="ltr"&gt;the same FWSM MAC address and it can't understand which context they&lt;/P&gt;&lt;P dir="ltr"&gt;belong to and which context they should be routed over. Packet&lt;/P&gt;&lt;P dir="ltr"&gt;classifier does not take route table into consideration because internal&lt;/P&gt;&lt;P dir="ltr"&gt;ip networks of contexts can overlap.&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide//co"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide//co&lt;/A&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;ntxt_f.html#wp1124172&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Please provide me with the following output from both contexts :&lt;/P&gt;&lt;P dir="ltr"&gt;- show xlate detail&lt;/P&gt;&lt;P dir="ltr"&gt;- show conn&lt;/P&gt;&lt;P dir="ltr"&gt;- show local&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;=================================&lt;/P&gt;&lt;P dir="ltr"&gt;Hope the above details help...&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Regards&lt;/P&gt;&lt;P dir="ltr"&gt;Amar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 03 Jul 2010 19:41:46 GMT</pubDate>
    <dc:creator>amardram123</dc:creator>
    <dc:date>2010-07-03T19:41:46Z</dc:date>
    <item>
      <title>FWSM: NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458172#M654939</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to set a new context and want to allow ainternet ccess to users through&amp;nbsp; new context...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology:&lt;/P&gt;&lt;P&gt;========&lt;/P&gt;&lt;P&gt;Internetrouter&amp;lt;==== FWSM (Admin, context1, context 2)&amp;lt;=====LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;internet router inside and outside ip is public ip...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM(outside of admin context and contex1 are allocated resource vlan 15 having same public subnet assigned)&lt;/P&gt;&lt;P&gt;and then Router inside interface is connected to access port(VLAN15)..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside interface for fwsm Context 1 is vlan 68 and one pc is attached to vlan 68.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping internet router inside ip from PC(vlan 68) but not able to nat the inside traffic..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assigned first PAT for inside subnet of context 1 and then also tried using static NAT but when chacking sh xlate i am not able to see any traslation... it show same address..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #ff0000; "&gt;fwsm/context1#nat-control&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;fwsm/context1# sh xlate&lt;/SPAN&gt;&lt;BR /&gt;1 in use, 2 most used&lt;BR /&gt;Global 192.168.3.234 Local 192.168.3.234&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;fwsm/context1# sh conn&lt;BR /&gt;&lt;/SPAN&gt;6 in use, 15 most used&lt;BR /&gt; Network Processor 1 connections&lt;BR /&gt;UDP KPTLOUT 8.8.8.8:53 KPTL 192.168.3.234:1032 idle 0:01:46 Bytes 940 FLAGS - D&lt;/P&gt;&lt;P&gt;TCP KPTLOUT 4.2.2.2:21 KPTL 192.168.3.234:1549 idle 0:00:05 Bytes 132 FLAGS - s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i captured the traffic at inside interface which show the icmp traffic sending the request and getting&amp;nbsp; reply on real ip..nat not working&lt;/P&gt;&lt;P&gt;&amp;nbsp; 21: 16:24:30.538159242 802.1Q vlan#68 P0 180.150.x.x &amp;gt; 192.168.3.234: icmp:&lt;BR /&gt;echo reply&lt;BR /&gt;&amp;nbsp; 22: 16:24:31.538160242 802.1Q vlan#68 P0 192.168.3.234 &amp;gt; 180.150.x.x: icmp:&lt;BR /&gt;echo request&lt;BR /&gt;&amp;nbsp; 23: 16:24:31.538160242 802.1Q vlan#68 P0 180.150.x.x &amp;gt; 192.168.3.234: icmp:&lt;BR /&gt;echo reply&lt;BR /&gt;&amp;nbsp; 24: 16:24:31.538160442 802.1Q vlan#68 P0 192.168.3.234 &amp;gt; 180.150.x.x: icmp:&lt;BR /&gt; echo request&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; 159: 17:45:23.543013072 802.1Q vlan#68 P0 192.168.3.234.1544 &amp;gt; 4.2.2.2.21: S 23&lt;BR /&gt;47316862:2347316862(0) win 65535 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;I have given NAT control also but no luck.. seems NAT is not working spl for new context...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;need help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458172#M654939</guid>
      <dc:creator>amardram123</dc:creator>
      <dc:date>2019-03-11T18:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM: NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458173#M654940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show ver&lt;/P&gt;&lt;P&gt;show run nat-co&lt;/P&gt;&lt;P&gt;show run nat&lt;/P&gt;&lt;P&gt;show run global&lt;/P&gt;&lt;P&gt;show run static&lt;/P&gt;&lt;P&gt;show run interface&lt;/P&gt;&lt;P&gt;show run same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be interesting to see before we move any further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Jul 2010 10:05:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458173#M654940</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-07-03T10:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM: NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458174#M654941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have opened a TAC case for this and the SR is 614803557. i have attached the show-tech and show run of both context...&lt;/P&gt;&lt;P&gt;plz let me know if you need further details...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also find the TAC initial response...&lt;/P&gt;&lt;P&gt;=======================&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Courier; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Sharing an outside interface on the FWSM is supported , But the packet&lt;/P&gt;&lt;P dir="ltr"&gt;classifier relies on active NAT sessions to classify the destination&lt;/P&gt;&lt;P dir="ltr"&gt;addresses to a context, the classifier is limited by how you can&lt;/P&gt;&lt;P dir="ltr"&gt;configure NAT. If you do not want to perform NAT, you must use unique&lt;/P&gt;&lt;P dir="ltr"&gt;interfaces.&lt;/P&gt;&lt;P dir="ltr"&gt;all vlan interfaces of FWSM share the same MAC address, so any kind of&lt;/P&gt;&lt;P dir="ltr"&gt;routing is simply not possible over shared interface - the&lt;/P&gt;&lt;P dir="ltr"&gt;packet classifier receives many packets from external world addressed to&lt;/P&gt;&lt;P dir="ltr"&gt;the same FWSM MAC address and it can't understand which context they&lt;/P&gt;&lt;P dir="ltr"&gt;belong to and which context they should be routed over. Packet&lt;/P&gt;&lt;P dir="ltr"&gt;classifier does not take route table into consideration because internal&lt;/P&gt;&lt;P dir="ltr"&gt;ip networks of contexts can overlap.&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide//co"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide//co&lt;/A&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;ntxt_f.html#wp1124172&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Please provide me with the following output from both contexts :&lt;/P&gt;&lt;P dir="ltr"&gt;- show xlate detail&lt;/P&gt;&lt;P dir="ltr"&gt;- show conn&lt;/P&gt;&lt;P dir="ltr"&gt;- show local&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;=================================&lt;/P&gt;&lt;P dir="ltr"&gt;Hope the above details help...&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Regards&lt;/P&gt;&lt;P dir="ltr"&gt;Amar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Jul 2010 19:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458174#M654941</guid>
      <dc:creator>amardram123</dc:creator>
      <dc:date>2010-07-03T19:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM: NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458175#M654942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amar, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're not sharing the inside interface sharing outside does not explain why packet is not NATed IF it matches the rules &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try to check up on the case it is however I have full confidence my counterparts in US will get to the bottom of it fast.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Jul 2010 21:38:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-issue/m-p/1458175#M654942</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-07-03T21:38:20Z</dc:date>
    </item>
  </channel>
</rss>

