<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic STATIC doesn't work in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266900#M825565</link>
    <description>&lt;P&gt;ASA 5520 running ver. 8.0(3).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the basic config:&lt;/P&gt;&lt;P&gt;global (outside) 101 interface&lt;/P&gt;&lt;P&gt;nat (101) 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) xxx.97.65.5 10.75.244.241 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I remove the static line then I send get to the Internet on 10.75.244.241. Re-apply the static command will kill the Internet connection. All clients (without static) are fine with or without the static command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No access-list created - everything is using default from out of the box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.0(3) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASA-5520&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; description Outside to TW&lt;/P&gt;&lt;P&gt; nameif OUTSIDE-TW&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address xxx.97.65.3 255.255.255.128 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description Connection to 4506&lt;/P&gt;&lt;P&gt; nameif INSIDE&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address INSIDE-10.75.244.12 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.200.3 255.255.255.128 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa803-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone PST -8&lt;/P&gt;&lt;P&gt;clock summer-time PDT recurring&lt;/P&gt;&lt;P&gt;dns domain-lookup INSIDE&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 10.75.244.252&lt;/P&gt;&lt;P&gt; name-server 10.75.244.151&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group icmp-type ICMP-ANY&lt;/P&gt;&lt;P&gt; description ICMP-ANY&lt;/P&gt;&lt;P&gt; icmp-object echo&lt;/P&gt;&lt;P&gt; icmp-object echo-reply&lt;/P&gt;&lt;P&gt; icmp-object traceroute&lt;/P&gt;&lt;P&gt; icmp-object unreachable&lt;/P&gt;&lt;P&gt;access-list INSIDE_nat_outbound extended permit ip object-group ALL_CRMC_SUBNET any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging trap notifications&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging mail emergencies&lt;/P&gt;&lt;P&gt;logging host INSIDE 10.75.244.158&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;mtu OUTSIDE-TW 1500&lt;/P&gt;&lt;P&gt;mtu INSIDE 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;ip local pool VPN_Pool 192.168.222.2-192.168.222.127 mask 255.255.255.128&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface OUTSIDE-TW&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-61551.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (OUTSIDE-TW) 101 interface&lt;/P&gt;&lt;P&gt;nat (INSIDE) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (INSIDE,OUTSIDE-TW) xxx.97.65.5 10.75.244.241 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;route OUTSIDE-TW 0.0.0.0 0.0.0.0 xxx.97.65.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 0:30:00&lt;/P&gt;&lt;P&gt;timeout conn 0:15:00 half-closed 0:05:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:22:18 GMT</pubDate>
    <dc:creator>jimmy.tran</dc:creator>
    <dc:date>2019-03-11T16:22:18Z</dc:date>
    <item>
      <title>STATIC doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266900#M825565</link>
      <description>&lt;P&gt;ASA 5520 running ver. 8.0(3).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the basic config:&lt;/P&gt;&lt;P&gt;global (outside) 101 interface&lt;/P&gt;&lt;P&gt;nat (101) 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) xxx.97.65.5 10.75.244.241 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I remove the static line then I send get to the Internet on 10.75.244.241. Re-apply the static command will kill the Internet connection. All clients (without static) are fine with or without the static command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No access-list created - everything is using default from out of the box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.0(3) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASA-5520&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; description Outside to TW&lt;/P&gt;&lt;P&gt; nameif OUTSIDE-TW&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address xxx.97.65.3 255.255.255.128 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description Connection to 4506&lt;/P&gt;&lt;P&gt; nameif INSIDE&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address INSIDE-10.75.244.12 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.200.3 255.255.255.128 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa803-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone PST -8&lt;/P&gt;&lt;P&gt;clock summer-time PDT recurring&lt;/P&gt;&lt;P&gt;dns domain-lookup INSIDE&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 10.75.244.252&lt;/P&gt;&lt;P&gt; name-server 10.75.244.151&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group icmp-type ICMP-ANY&lt;/P&gt;&lt;P&gt; description ICMP-ANY&lt;/P&gt;&lt;P&gt; icmp-object echo&lt;/P&gt;&lt;P&gt; icmp-object echo-reply&lt;/P&gt;&lt;P&gt; icmp-object traceroute&lt;/P&gt;&lt;P&gt; icmp-object unreachable&lt;/P&gt;&lt;P&gt;access-list INSIDE_nat_outbound extended permit ip object-group ALL_CRMC_SUBNET any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging trap notifications&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging mail emergencies&lt;/P&gt;&lt;P&gt;logging host INSIDE 10.75.244.158&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;mtu OUTSIDE-TW 1500&lt;/P&gt;&lt;P&gt;mtu INSIDE 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;ip local pool VPN_Pool 192.168.222.2-192.168.222.127 mask 255.255.255.128&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface OUTSIDE-TW&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-61551.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (OUTSIDE-TW) 101 interface&lt;/P&gt;&lt;P&gt;nat (INSIDE) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (INSIDE,OUTSIDE-TW) xxx.97.65.5 10.75.244.241 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;route OUTSIDE-TW 0.0.0.0 0.0.0.0 xxx.97.65.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 0:30:00&lt;/P&gt;&lt;P&gt;timeout conn 0:15:00 half-closed 0:05:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266900#M825565</guid>
      <dc:creator>jimmy.tran</dc:creator>
      <dc:date>2019-03-11T16:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266901#M825566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This looks to a gratuitous ARP issue. &lt;/P&gt;&lt;P&gt;I would suggest the following to get this fixed:&lt;/P&gt;&lt;P&gt;no static (inside,outside) xxx.97.65.5 10.75.244.241&lt;/P&gt;&lt;P&gt;int g0/0&lt;/P&gt;&lt;P&gt;ip address xxx.97.65.5 255.255.255.128 &lt;/P&gt;&lt;P&gt;ping 4.2.2.2&lt;/P&gt;&lt;P&gt;int g0/0&lt;/P&gt;&lt;P&gt;ip address xxx.97.65.3 255.255.255.128 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) xxx.97.65.5 10.75.244.241&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reason for the fix:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall does a proxy ARP for the public ip address applied in the static statement. At times this ARP is not learned by the upstream device so we have to force this ARP. The best way to do it is by applying that public ip address in the static statement to the firewall outside interface and then applying it to the static statement again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This might cause termination of the active connection through the firewall so applying it off production hours is always recommended.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Oct 2009 16:28:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266901#M825566</guid>
      <dc:creator>mkharban</dc:creator>
      <dc:date>2009-10-02T16:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266902#M825567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi mkharban,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did exactly as you suggested and it worked beautiful!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: Thought you may want to know this - Internet connection was up and running just fine during the process of changing the outside IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jimmy-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Oct 2009 20:04:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266902#M825567</guid>
      <dc:creator>jimmy.tran</dc:creator>
      <dc:date>2009-10-02T20:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266903#M825568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet connection generally stays up but to avoid any risks I always recommend adding that one-liner. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Manish Kharbanda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Oct 2009 20:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266903#M825568</guid>
      <dc:creator>mkharban</dc:creator>
      <dc:date>2009-10-02T20:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC doesn't work</title>
      <link>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266904#M825569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your professionalism!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a Great week-end!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jimmy-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Oct 2009 20:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-doesn-t-work/m-p/1266904#M825569</guid>
      <dc:creator>jimmy.tran</dc:creator>
      <dc:date>2009-10-02T20:26:08Z</dc:date>
    </item>
  </channel>
</rss>

