<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static PAT/ACL help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365278#M734340</link>
    <description>&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-size: 10pt; color: #000000; font-family: Tahoma;"&gt;Hello,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-size: 10pt; font-family: tahoma;"&gt;I have a client that needs access to a particular server on the DMZ from the outside Interface - I have created a static PAT statement 1200 translated to 1200 (I have created the 1200 port so they can access this particular server) and created an access-list from outside to the DMZ. When i run packet tracer it fails at the last part at the NAT.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: tahoma;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV dir="ltr"&gt;Type - NAT&lt;BR /&gt;Subtype - rpf-check&lt;BR /&gt;Action - DROP&lt;BR /&gt;Show rule in NAT Rules table. &lt;BR /&gt;Config&lt;BR /&gt;static (DMZ,Outside) tcp interface 1200 access-list DMZ_nat_static_2 &lt;BR /&gt;nat-control match tcp DMZ host 2.2.2.2eq 1200 &lt;BR /&gt;Outside host 80.80.80.80 static translation to 90.90.90.90/1200 translate_hits = 0, untranslate_hits = 11&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;config;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;DIV dir="ltr"&gt;static (DMZ,Outside) tcp interface 1200 access-list DMZ_nat_static_2&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: tahoma;"&gt;access-list DMZ extended permit object-group DM_INLINE_PROTOCOL_1 host 2.2.2.2 host 80.80.80.80 &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: tahoma;"&gt;access-list DMZ_nat_static_2 extended permit tcp host 2.2.2.2. host eq 1200 host 80.80.80.80&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: tahoma;"&gt;access-list Outside_access_in extended permit tcp host 80.80.80.80 host 2.2.2.2&amp;nbsp; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Not sure if the above access-list/PAT are correct&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Thanks&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:33:13 GMT</pubDate>
    <dc:creator>tahirs001</dc:creator>
    <dc:date>2019-03-11T17:33:13Z</dc:date>
    <item>
      <title>Static PAT/ACL help</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365278#M734340</link>
      <description>&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-size: 10pt; color: #000000; font-family: Tahoma;"&gt;Hello,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-size: 10pt; font-family: tahoma;"&gt;I have a client that needs access to a particular server on the DMZ from the outside Interface - I have created a static PAT statement 1200 translated to 1200 (I have created the 1200 port so they can access this particular server) and created an access-list from outside to the DMZ. When i run packet tracer it fails at the last part at the NAT.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: tahoma;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV dir="ltr"&gt;Type - NAT&lt;BR /&gt;Subtype - rpf-check&lt;BR /&gt;Action - DROP&lt;BR /&gt;Show rule in NAT Rules table. &lt;BR /&gt;Config&lt;BR /&gt;static (DMZ,Outside) tcp interface 1200 access-list DMZ_nat_static_2 &lt;BR /&gt;nat-control match tcp DMZ host 2.2.2.2eq 1200 &lt;BR /&gt;Outside host 80.80.80.80 static translation to 90.90.90.90/1200 translate_hits = 0, untranslate_hits = 11&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;config;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;DIV dir="ltr"&gt;static (DMZ,Outside) tcp interface 1200 access-list DMZ_nat_static_2&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: tahoma;"&gt;access-list DMZ extended permit object-group DM_INLINE_PROTOCOL_1 host 2.2.2.2 host 80.80.80.80 &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: tahoma;"&gt;access-list DMZ_nat_static_2 extended permit tcp host 2.2.2.2. host eq 1200 host 80.80.80.80&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: tahoma;"&gt;access-list Outside_access_in extended permit tcp host 80.80.80.80 host 2.2.2.2&amp;nbsp; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Not sure if the above access-list/PAT are correct&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;Thanks&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365278#M734340</guid>
      <dc:creator>tahirs001</dc:creator>
      <dc:date>2019-03-11T17:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT/ACL help</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365279#M734341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doesn't look correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please advise what is the ip address of the outside interface, and the ip address of the DMZ server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2010 10:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365279#M734341</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-15T10:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT/ACL help</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365280#M734342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I will give made up IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Remote IP:&amp;nbsp; 22.22.22.22&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;My outside IP: 11.11.11.11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;My DMZ Server: 33.33.33.33&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2010 11:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365280#M734342</guid>
      <dc:creator>tahirs001</dc:creator>
      <dc:date>2010-04-15T11:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT/ACL help</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365281#M734343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, base on the following information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Remote IP:&amp;nbsp;&amp;nbsp; 22.22.22.22&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;My outside IP: 11.11.11.11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;My DMZ Server: 33.33.33.33&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,Outside) tcp interface 1200 &lt;SPAN style="background-color: #f8fafd;"&gt;33.33.33.33 1200 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;access-list &lt;SPAN style="font-size: 10pt; font-family: tahoma; "&gt;Outside_access_in permit tcp host &lt;/SPAN&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;22.22.22.22 host &lt;/SPAN&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;11.11.11.11 eq 1200&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume you already have the following:&lt;/P&gt;&lt;P&gt;access-group &lt;SPAN style="font-size: 10pt; font-family: tahoma; "&gt;Outside_access_in in interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;OR/&lt;/STRONG&gt; alternatively if you need to be very specific that only traffic from 22.22.22.22 needs to be translated, then the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ-NAT permit tcp host 33.33.33.33 eq 1200 host 22.22.22.22 eq 1200&lt;/P&gt;&lt;P&gt;static (DMZ,Outside) tcp interface 1200 &lt;SPAN style="background-color: #f8fafd;"&gt;access-list DMZ-NAT&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2010 12:07:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365281#M734343</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-15T12:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Static PAT/ACL help</title>
      <link>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365282#M734344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I will give that a bash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have sent you a PM. Can you have a look please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2010 12:17:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-pat-acl-help/m-p/1365282#M734344</guid>
      <dc:creator>tahirs001</dc:creator>
      <dc:date>2010-04-15T12:17:46Z</dc:date>
    </item>
  </channel>
</rss>

