<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error PATing on a PIX515E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253538#M810703</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It works with that ver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Aug 2009 12:48:18 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2009-08-24T12:48:18Z</dc:date>
    <item>
      <title>Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253531#M810696</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;My client has a need to PAT via a L2L tunnel on a PIX515E 6.3(5.  Allusers on the inside should be able to connect to 2 VLSM IP scopes and one test machine via a VPN tunnel.  The remote site is allowing all connections to appear comming from a single IP address.&lt;/P&gt;&lt;P&gt;I created the access lists for PATing but I am getting an error message whaen I try to nat the single IP to an access list.  Here is my configration and the error message:&lt;/P&gt;&lt;P&gt;name 10.254.1.1 partners_tunneltest&lt;/P&gt;&lt;P&gt;name 10.254.1.128 partners_portal&lt;/P&gt;&lt;P&gt;name 10.254.11.80 partners_meditech&lt;/P&gt;&lt;P&gt;name x.x.x.x PHS_router&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object-group network PARTNERS_OUT &lt;/P&gt;&lt;P&gt;  network-object partners_tunneltest 255.255.255.255 &lt;/P&gt;&lt;P&gt;  network-object partners_portal 255.255.255.128 &lt;/P&gt;&lt;P&gt;  network-object partners_meditech 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_51 permit ip host 10.255.11.62 object-group PARTNERS_OUT &lt;/P&gt;&lt;P&gt;access-list PARTNERS permit ip any object-group PARTNERS_OUT &lt;/P&gt;&lt;P&gt;crypto map mymap 51 ipsec-isakmp&lt;/P&gt;&lt;P&gt;crypto map mymap 51 match address outside_cryptomap_51&lt;/P&gt;&lt;P&gt;crypto map mymap 51 set pfs group2&lt;/P&gt;&lt;P&gt;crypto map mymap 51 set peer PHS_router&lt;/P&gt;&lt;P&gt;crypto map mymap 51 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map mymap 51 set security-association lifetime seconds 28800 kilobytes 86400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;PIX-515(config)#static (inside,outside) 10.255.11.62 access-list PARTNERS&lt;/P&gt;&lt;P&gt;ERROR: invalid netmask 255.0.0.0 with global address 10.255.11.62&lt;/P&gt;&lt;P&gt;Usage:  [no] static [(real_ifc, mapped_ifc)]&lt;/P&gt;&lt;P&gt;                {&amp;lt;mapped_ip&amp;gt;|interface}&lt;/P&gt;&lt;P&gt;                {&amp;lt;real_ip&amp;gt; [netmask &amp;lt;mask&amp;gt;]} | {access-list &amp;lt;acl_name&amp;gt;}&lt;/P&gt;&lt;P&gt;                [dns] [norandomseq] [&amp;lt;max_conns&amp;gt; [&amp;lt;emb_lim&amp;gt;]]&lt;/P&gt;&lt;P&gt;        [no] static [(real_ifc, mapped_ifc)] {tcp|udp}&lt;/P&gt;&lt;P&gt;                {&amp;lt;mapped_ip&amp;gt;|interface} &amp;lt;mapped_port&amp;gt;&lt;/P&gt;&lt;P&gt;                {&amp;lt;real_ip&amp;gt; &amp;lt;real_port&amp;gt; [netmask &amp;lt;mask&amp;gt;]} |&lt;/P&gt;&lt;P&gt;                {access-list &amp;lt;acl_name&amp;gt;}&lt;/P&gt;&lt;P&gt;                [dns] [norandomseq] [&amp;lt;max_conns&amp;gt; [&amp;lt;emb_lim&amp;gt;]]&lt;/P&gt;&lt;P&gt;pix-515(config)# static (inside,outside) 10.255.11.62 netmask 255.255.255.255 access-list PARTNERS&lt;/P&gt;&lt;P&gt;ERROR: invalid local IP address netmask&lt;/P&gt;&lt;P&gt;Usage:  [no] static [(real_ifc, mapped_ifc)]&lt;/P&gt;&lt;P&gt;                {&amp;lt;mapped_ip&amp;gt;|interface}&lt;/P&gt;&lt;P&gt;                {&amp;lt;real_ip&amp;gt; [netmask &amp;lt;mask&amp;gt;]} | {access-list &amp;lt;acl_name&amp;gt;}&lt;/P&gt;&lt;P&gt;                [dns] [norandomseq] [&amp;lt;max_conns&amp;gt; [&amp;lt;emb_lim&amp;gt;]]&lt;/P&gt;&lt;P&gt;        [no] static [(real_ifc, mapped_ifc)] {tcp|udp}&lt;/P&gt;&lt;P&gt;                {&amp;lt;mapped_ip&amp;gt;|interface} &amp;lt;mapped_port&amp;gt;&lt;/P&gt;&lt;P&gt;                {&amp;lt;real_ip&amp;gt; &amp;lt;real_port&amp;gt; [netmask &amp;lt;mask&amp;gt;]} |&lt;/P&gt;&lt;P&gt;                {access-list &amp;lt;acl_name&amp;gt;}&lt;/P&gt;&lt;P&gt;                [dns] [norandomseq] [&amp;lt;max_conns&amp;gt; [&amp;lt;emb_lim&amp;gt;]]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253531#M810696</guid>
      <dc:creator>ramzi-kotob</dc:creator>
      <dc:date>2019-03-11T16:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253532#M810697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try this instead:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 99 10.255.11.62&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 99 access-list PARTNERS &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 11:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253532#M810697</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-24T11:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253533#M810698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also tried this policy NAT and did not work.  I was able to create it using CLI but PDM reported as an invalid configuration and I had to remove it.  The configurastion I listed in my initial post works for another client but they have an ASA instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ramzi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253533#M810698</guid>
      <dc:creator>ramzi-kotob</dc:creator>
      <dc:date>2009-08-24T12:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253534#M810699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have this as a workking config on multiple sites, what testing did you perform to confirm it did not work?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253534#M810699</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-24T12:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253535#M810700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Testing is browsing to 10.254.1.1.  I just realized my tunnel is no longer up, I have to fix that.  Attached is the error from PDM regarding the policy NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253535#M810700</guid>
      <dc:creator>ramzi-kotob</dc:creator>
      <dc:date>2009-08-24T12:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253536#M810701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - I see one potential issue, my testing (lab) and my working config, my firewalls are running ios 7.x &amp;amp; 8.x - what version are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:33:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253536#M810701</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-24T12:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253537#M810702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;6.3(5)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253537#M810702</guid>
      <dc:creator>ramzi-kotob</dc:creator>
      <dc:date>2009-08-24T12:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253538#M810703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It works with that ver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:48:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253538#M810703</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-24T12:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253539#M810704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know why PDM rejects the Policy NAT and disable PDM configuration until these 2 lines are removed.  My client depends on PDM for simple configurations so PDM configuration must be available.  Did you see the attached error earlier?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253539#M810704</guid>
      <dc:creator>ramzi-kotob</dc:creator>
      <dc:date>2009-08-24T12:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253540#M810705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I personally do not use the PDM.  Just becuase the PDM does not recongnise/like the config - does not mean it is not working.  The fact the PDM only configures about 10% of the availble commands in the PIX says it all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest your client upgrades the IOS to a version that supports the ASDM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 12:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253540#M810705</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-24T12:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253541#M810706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I figured the static works for one to one and does it errors on one to many, the mask error).  I used the policy nat and told the client he needs to upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help, I appreciate it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 16:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253541#M810706</guid>
      <dc:creator>ramzi-kotob</dc:creator>
      <dc:date>2009-08-24T16:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Error PATing on a PIX515E</title>
      <link>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253542#M810707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 05:34:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-pating-on-a-pix515e/m-p/1253542#M810707</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-25T05:34:21Z</dc:date>
    </item>
  </channel>
</rss>

