<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to access server from static NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528142#M803971</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume the 8.0 unit and the 8.2 unit have the exact same IP address and static NAT configurations, correct?&amp;nbsp; And when you initially tested, you just swapped the 8.0 unit with the 8.2 unit and tested the NAT, correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason the static statements were most likely failing is because the upstream device (probably the ISP router) still had the IP addresses of the static associated with the MAC address of the 8.0 unit.&amp;nbsp; To resolve this issue, you can simply clear the arp cache on the upstream device (clear arp-cache) if you have management access to it, or you can simply reload it to clear the arp cache as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore, please try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-replace the 8.0 ASA with the 8.2 ASA (I am assuming both devices have the exact same IP address assignment and configuration)&lt;/P&gt;&lt;P&gt;-clear the arp cache on the upstream device either with the command "clear arp-cache" or reloading the device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Oct 2010 21:41:31 GMT</pubDate>
    <dc:creator>Allen P Chen</dc:creator>
    <dc:date>2010-10-06T21:41:31Z</dc:date>
    <item>
      <title>Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528134#M803957</link>
      <description>&lt;P&gt;%ASA-session-6-302021: Teardown ICMP connection for faddr 192.168.1.109/0 gaddr 192.168.1.4/0 laddr 192.168.1.4/0&lt;BR /&gt; I have upgraded my ASA from 8.0 to 8.2.&lt;/P&gt;&lt;P&gt;However, none of static NAT working. All outside_access_in access-list has no HIT. Please help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528134#M803957</guid>
      <dc:creator>Alex Chan</dc:creator>
      <dc:date>2019-03-11T18:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528135#M803958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the config? That would help us identify where the problem lies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 20:15:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528135#M803958</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-10-06T20:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528136#M803959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have attached the config file. Please check.&lt;/P&gt;&lt;SPAN lang="EN"&gt;&lt;SPAN lang="EN"&gt;&lt;SPAN lang="EN"&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 20:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528136#M803959</guid>
      <dc:creator>Alex Chan</dc:creator>
      <dc:date>2010-10-06T20:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528137#M803961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which static statements aren't working? I tried to connect to a handful on TCP/80 and they all seemed to go through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 20:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528137#M803961</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-10-06T20:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528138#M803962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is because the primary firewall with old 8.0 version is still in production.&lt;/P&gt;&lt;P&gt;I am updating the standby firewall and testing tonight.&lt;/P&gt;&lt;P&gt;But fail to access any of NAT, so I put it offline now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 20:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528138#M803962</guid>
      <dc:creator>Alex Chan</dc:creator>
      <dc:date>2010-10-06T20:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528139#M803964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Support:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 210.177.218.1 192.168.1.23 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.2 192.168.1.24 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.3 192.168.1.11 netmask 255.255.255.255 dns &lt;BR /&gt;static (DMZ,outside) 210.177.98.33 192.168.41.63 netmask 255.255.255.255 dns &lt;BR /&gt;static (DMZ,outside) 210.177.98.35 192.168.41.62 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.4 192.168.1.51 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.11 192.168.1.20 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.12 192.168.1.18 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.16 192.168.1.19 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.17 192.168.1.48 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.18 192.168.2.16 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.19 192.168.1.81 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.20 192.168.1.17 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.21 192.168.1.26 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.22 192.168.1.37 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.23 192.168.1.52 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.218.24 192.168.1.54 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.98.36 192.168.1.53 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.98.38 192.168.1.27 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.98.39 192.168.1.65 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.98.40 192.168.1.30 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.98.42 192.168.1.3 netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) 210.177.98.43 192.168.1.71 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) 210.177.98.37 192.168.1.92 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of them are able to ping or access via Internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 20:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528139#M803964</guid>
      <dc:creator>Alex Chan</dc:creator>
      <dc:date>2010-10-06T20:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528140#M803965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this on the 8.0 or 8.2 unit? They cannot run simultaneously with the same config since the upstream router's ARP table will not be correct and won't know which firewall actually owns the public addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 21:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528140#M803965</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-10-06T21:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528141#M803967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Support:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 8.0 unit is in production now. The 8.2 unit is currently offline. But I am wondering if there is any wrong configuration I have done in the 8.2 unit per attached file I sent since I can't get any of NAT server up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 21:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528141#M803967</guid>
      <dc:creator>Alex Chan</dc:creator>
      <dc:date>2010-10-06T21:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access server from static NAT</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528142#M803971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume the 8.0 unit and the 8.2 unit have the exact same IP address and static NAT configurations, correct?&amp;nbsp; And when you initially tested, you just swapped the 8.0 unit with the 8.2 unit and tested the NAT, correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason the static statements were most likely failing is because the upstream device (probably the ISP router) still had the IP addresses of the static associated with the MAC address of the 8.0 unit.&amp;nbsp; To resolve this issue, you can simply clear the arp cache on the upstream device (clear arp-cache) if you have management access to it, or you can simply reload it to clear the arp cache as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore, please try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-replace the 8.0 ASA with the 8.2 ASA (I am assuming both devices have the exact same IP address assignment and configuration)&lt;/P&gt;&lt;P&gt;-clear the arp cache on the upstream device either with the command "clear arp-cache" or reloading the device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 21:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-server-from-static-nat/m-p/1528142#M803971</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2010-10-06T21:41:31Z</dc:date>
    </item>
  </channel>
</rss>

