<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Exempt not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351714#M723623</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do the logs show when it breaks? Could you pls. post the output of&lt;/P&gt;&lt;P&gt;sh run nat&lt;/P&gt;&lt;P&gt;with the access-list if nat 0 is tied to an acl?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do packet-tracker. You can use "?" and fill out the command very easily and see where it is getting dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jan 2010 13:59:22 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-01-26T13:59:22Z</dc:date>
    <item>
      <title>NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351713#M723622</link>
      <description>&lt;P&gt;folks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an asa 5540 &amp;amp; i'm trying to allow an outside IP through the asa &amp;amp; into another firewall's dmz on the inside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the external IP is 145.a.b.c/32 &amp;amp; the internal dmz address is 194.a.b.c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a nat exempt rule allowing 145.a.b.c/32 to talk to 194.a.b.c using inbound traffic but i get a no tranlsation group found&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the firewall's external interface is directly connected to 145145.a.b.c and it has a route via its inside interface to 194.a.b.c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can see the access rule incrementing and i can see a packet capture showing the source address trying to get to the destination address on the outside interface where the traffic arrives&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there is nothing from the packet capture showing traffic leaving the external interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks to anyone taking the time to respond or post a reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gratefully appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351713#M723622</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2019-03-11T17:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351714#M723623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do the logs show when it breaks? Could you pls. post the output of&lt;/P&gt;&lt;P&gt;sh run nat&lt;/P&gt;&lt;P&gt;with the access-list if nat 0 is tied to an acl?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do packet-tracker. You can use "?" and fill out the command very easily and see where it is getting dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 13:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351714#M723623</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-26T13:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351715#M723624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post your commands to configure the NAT exempt?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 15:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351715#M723624</guid>
      <dc:creator>rbermel83</dc:creator>
      <dc:date>2010-01-26T15:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351716#M723626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet---ASA5540--FW--dmz(194.a.b.c)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the external IP is 145.a.b.c/32 &amp;amp; the internal dmz address is 194.a.b.c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;Is this topology correct? What FW is the one on the inside? another ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;On the 5540 you are translating the 194.a.b.c to 145.a.b.c and on the one on the inside you are just doing identity translation or nat exempton?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;Which firewall is logging no translation group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;You should do nat exemption or identity static on the inside firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;nat (dmz) 0 access-list dmz-server&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;access-list dmz-server permit ip host 194.a.b.c any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;static (dmz,outside) 194.a.b.c 192.a.b.c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px; min-height: 8pt; height: 8pt;"&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 17:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351716#M723626</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-26T17:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351717#M723629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are you trying to accomplish? If you are just trying to allow use of a service like http then using a static nat like&lt;/P&gt;&lt;P style="padding: 0px;"&gt;static (dmz,outside) 194.a.b.c 192.a.b.c would be fine with an access list allowing the neccessary service.&lt;/P&gt;&lt;P style="padding: 0px;"&gt;access-list outside_access_in permit tcp any host 145.a.b.c 255.255.255.255 eq http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0px;"&gt;If you are trying to allow already trusted traffic access to a system then using the nat exemption would be neccessary.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 17:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351717#M723629</guid>
      <dc:creator>rbermel83</dc:creator>
      <dc:date>2010-01-26T17:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351718#M723633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;rbermel83&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm trying to allow traffic from an external host, 145.a.b.c, to an internal host, 194.a.b.c but i need to allow the traffic from the external host through without any translation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the access rule is allowing traffic from the outside to the inside for tcp DNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 19:55:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351718#M723633</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2010-01-26T19:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351719#M723637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kusankar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your topology is correct but i want to allow 145.a.b.c. through the firewall, from the outside to the inside, without translation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have no other nat rules from outside to inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an access rule allowing traffic from the outside, 145.a.b.c, to the inside, 194.a.b.c, and i'm seeing hits on it but my syslog shows 'no translation group.......'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for taking the time to look at this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm wondering if a nat exemption is the right action since i don't have any other nat in the relevant direction outside to inside - maybe i just use a static nat to nat the source to itself but i only want it to apply to traffic to the destination i've specified&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 20:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351719#M723637</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2010-01-26T20:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351720#M723645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kusankar/rbermel83&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;folks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've just got this working by inverting the exempt statement&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i changed the direction of the config in the gui &amp;amp; it works grand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm still a bit confused as it undermines my belief that i understood how to configure nat on an asa!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks to both of you for contributing&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 21:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351720#M723645</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2010-01-26T21:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351721#M723668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to clearly understand what nat exemption that you reversed and on which firewall so, I can explain why you needed to do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clearly copy and paste the lines and indicate which firewall you added it to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 21:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351721#M723668</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-26T21:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351722#M723679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kusankar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;old config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (Outside) 0 access-list Outside_nat0_outbound_1 outside&lt;/P&gt;&lt;P&gt;access-list Outside_nat0_outbound_1 extended permit ip host 145.a.b.c host 194.a.b.c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;new config&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;nat (Inside) 0 access-list Inside_nat0_outbound_1&lt;BR /&gt;nat (Inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-list Inside_nat0_outbound_1 line 1 extended permit ip host 194.a.b.c host 145.a.b.c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i only needed to re-configure my external ASA as the traffic wasn't even getting to the internal firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'd be keen to hear your views and if you need i can draft up a quick topology diagram&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 22:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351722#M723679</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2010-01-26T22:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351723#M723701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nat exemption with an acl&amp;nbsp; is bidirectional by default - provided you apply that on the higher security interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You did what I had suggested which to apply nat 0 on the inside or dmz interface with an acl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Earlier you had provided exemption for the host 145.a.b.c that lived on the outside. That is incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Outside) 0 access-list Outside_nat0_outbound_1 outside&lt;/P&gt;&lt;P&gt;access-list Outside_nat0_outbound_1 extended permit ip host 145.a.b.c host 194.a.b.c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This firewall probably logged no translation group messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 22:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351723#M723701</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-26T22:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Exempt not working</title>
      <link>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351724#M723714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kusankar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks my friend&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jan 2010 23:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-exempt-not-working/m-p/1351724#M723714</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2010-01-26T23:15:02Z</dc:date>
    </item>
  </channel>
</rss>

