<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT help on Pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546050#M685367</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would a fresh config help at all?&amp;nbsp; I can't think why I would need a NAT exempt rule in place can you?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Nov 2010 10:26:27 GMT</pubDate>
    <dc:creator>Andy White</dc:creator>
    <dc:date>2010-11-10T10:26:27Z</dc:date>
    <item>
      <title>NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546043#M685249</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using a PIX on our test network and I'm trying to get devices on interface "DMZ4_Wireless_PDA" (Ip range 172.25.1.x/24) to communicate with x.x.156.78 which NAT's to a server on the inside interface on 192.168.200.200.&amp;nbsp; Attached is my config but I can't get it to work.&amp;nbsp; The 172.25.1.x range needs to communicate on various ports especially ICMP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your time &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546043#M685249</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2019-03-11T19:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546044#M685258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There seems to be overlapped with ip address x.x.156.78 on the following:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;global (inside) 1 x.x.156.78&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;nat (outside) 1 192.168.201.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;static (inside,DMZ4_Wireless_PDA) x.x.156.78 192.168.200.200 netmask 255.255.255.255 &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Do you have a need for the nat/global pair?&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;BR /&gt;Also, do you need to ping the public ip address (x.x.156.78) instead of the private ip address (192.168.200.200)? or it doesn't really matter which ip address you ping as long as it's testing the actual server connectivity.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;To ping, you would also need to configure inspection for icmp:&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;policy-map global_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;class inspection_default&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 09:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546044#M685258</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-09T09:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546045#M685279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andy ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default PIX need to NAT flows from higher security level ( inside 100 )&amp;nbsp; to lower security level ( DMZ4_Wireless_PDA 20 ).&lt;/P&gt;&lt;P&gt;So the solutions are :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. configure nat of the inside host to DMZ4 segment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,DMZ4_Wireless_PDA) 172.25.1.200 192.168.200.200&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Allow on the access-list :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ4_Wireless_PDA_access_in permit icmp 172.25.1.0 255.255.255.0 host 172.25.1.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. disable this behaviod&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat-control&lt;/P&gt;&lt;P&gt;Then your configured access-list will work:&lt;/P&gt;&lt;P&gt;access-list DMZ4_Wireless_PDA_access_in extended permit udp 172.25.1.0 255.255.255.0 host 192.168.200.2 eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 09:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546045#M685279</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-11-09T09:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546046#M685307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Pix/ASA knowledge is a bit rusty, but all I need is all the devices on 172.25.1.x/24 to contact x.x.156.78 which is a server on the inside (192.168.200.200).&amp;nbsp; I'm not sure what ot why the global statement is there, what does that do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;x.x156.78 is a public IP, but for the scenario it is a server on the inside and yes I need to ping x.x156.78.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that's a little clearer as my explanation wasn't the best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 10:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546046#M685307</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2010-11-09T10:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546047#M685327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as the NAT statement is concern, you only need the following line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;static (inside,DMZ4_Wireless_PDA) x.x.156.78 192.168.200.200 netmask 255.255.255.255 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The nat/global pair as far as I understand does not serve any purpose, and it would be best to remove them as it overlaps with the static NAT statement above:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;no global (inside) 1 x.x.156.78&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;no nat (outside) 1 192.168.201.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Please "clear xlate" after the changes, and also add "inspect icmp" as advised earlier.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 10:41:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546047#M685327</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-09T10:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546048#M685347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And also you need to enable proxyarp for DMZ4_Wireless_PDA interface:&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;no sysopt noproxyarp DMZ4_Wireless_PDA&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 10:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546048#M685347</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-09T10:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546049#M685361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe I have changed the config to match what you said, but I still can't connect to x.x.156.78.&amp;nbsp; I have configured my laptop to 172.5.1.10/24 and added me to the DMZ4_Wireless_PDA interface and tried to ping x.x.156.78 (192.168.200.200) and it fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I logged on the ASDM and did an packet trace from 172.25.1.10 to x.x.156.78 using echo-reply and it failed on the NAT-Exempt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas what I might be doing wrong?&amp;nbsp; Let me know if you need a fresh config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Nov 2010 16:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546049#M685361</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2010-11-09T16:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546050#M685367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would a fresh config help at all?&amp;nbsp; I can't think why I would need a NAT exempt rule in place can you?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 10:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546050#M685367</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2010-11-10T10:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT help on Pix</title>
      <link>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546051#M685371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, packet tracer is right.&lt;/P&gt;&lt;P&gt;NAT exemption takes precedence over Static NAT, hence it's failing the static NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following NAT exemption configuration:&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.0 255.255.255.0 192.168.201.0 255.255.255.0 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-list inside_nat0_outbound extended permit ip any 192.168.201.0 255.255.255.240 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.0 255.255.255.0 172.25.1.0 255.255.255.0 &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For testing purposes, I would take out that red line of ACL, "clear xlate", and test it. This should work now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can configure the following ACL instead to bypass 192.168.200.200 from being exempted:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.0 255.255.255.128 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.128 255.255.255.192 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.192 255.255.255.248 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip host 192.168.200.201 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip host 192.168.200.202 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip host 192.168.200.203 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.204 255.255.255.252 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.208 255.255.255.240 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG style="Courier New&amp;quot;: ; font-family: &amp;quot; "&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.224 255.255.255.224 172.25.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 10:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-help-on-pix/m-p/1546051#M685371</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-10T10:40:20Z</dc:date>
    </item>
  </channel>
</rss>

