<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static NAT PIX Command in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081617#M878550</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That did it. I was missing the 2nd static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Dec 2008 20:23:13 GMT</pubDate>
    <dc:creator>ajohnson</dc:creator>
    <dc:date>2008-12-22T20:23:13Z</dc:date>
    <item>
      <title>Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081611#M878538</link>
      <description>&lt;P&gt;Running PIX 6.3(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Goal is to translate a outside external src IP 12.12.12.10 to a internal ip 172.16.1.200 on the inside of the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried to use static (outside,inside) 172.16.1.200 12.12.12.10 without any luck get &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;305005: No translation group found for icmp src outside:12.12.12.10 dst inside:1&lt;/P&gt;&lt;P&gt;72.16.1.200 (type 8, code 0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should work, what am I missing?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081611#M878538</guid>
      <dc:creator>ajohnson</dc:creator>
      <dc:date>2019-03-11T14:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081612#M878539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try it in other direction, to map 12.12.12.10 towards 172.16.1.200 your identity nat  must be in this format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside, outside) 12.12.12.10 172.16.1.200 netmask 255.255.255.255&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 18:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081612#M878539</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-22T18:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081613#M878545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get this error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;305006: regular translation creation failed for icmp src outside:12.12.12.10 dst&lt;/P&gt;&lt;P&gt; inside:172.16.1.200 (type 8, code 0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 18:35:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081613#M878545</guid>
      <dc:creator>ajohnson</dc:creator>
      <dc:date>2008-12-22T18:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081614#M878547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;clear xlate or local host and try again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;either do pix#&lt;B&gt;clear xlate&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix#clear local-host 172.16.1.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;btw you will need icmp acl to allow pings from outside ot inside , create an acl to allow different service such as rdp and test through that port instead of icmp  by rdping from outside to 12.12.12.10   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 18:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081614#M878547</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-22T18:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081615#M878548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes already have a permit any any on outside interface and have done clear xlate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 19:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081615#M878548</guid>
      <dc:creator>ajohnson</dc:creator>
      <dc:date>2008-12-22T19:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081616#M878549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you configure the above statement, where are you sourcing the ICMP packets from and what is the destination. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe below statement will translate the outside IP 12.12.12.10 to 172.16.1.200 and then you need a translation for whatever destination the IP Address is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router 1.1.1.1 - Inside ASA - Outside - 12.12.12.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (outside,inside) 172.16.1.200 12.12.12.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh xlate&lt;/P&gt;&lt;P&gt;2 in use, 2 most used&lt;/P&gt;&lt;P&gt;Global 1.1.1.1 Local 1.1.1.1&lt;/P&gt;&lt;P&gt;Global 172.16.1.200 Local 12.12.12.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if I telnet to 1.1.1.1 from the outside with 12.12.12.10, the packets get translated to 172.16.1.200 on the ASA and then the ASA looks for the regular inside/outside translation for the destination. That is why I have a static (inside,outside) for 1.1.1.1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router that is configured with IP 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Loopback101&lt;/P&gt;&lt;P&gt; ip address 1.1.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7140#sh users&lt;/P&gt;&lt;P&gt;    Line       User       Host(s)              Idle       Location&lt;/P&gt;&lt;P&gt;*  0 con 0                idle                 00:00:00&lt;/P&gt;&lt;P&gt;   2 vty 0                idle                 00:02:27 172.16.1.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate all helpful posts*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 19:23:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081616#M878549</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-22T19:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081617#M878550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That did it. I was missing the 2nd static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 20:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081617#M878550</guid>
      <dc:creator>ajohnson</dc:creator>
      <dc:date>2008-12-22T20:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT PIX Command</title>
      <link>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081618#M878552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why not a single command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.12.12.10 172.16.1.200 0 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Dec 2008 07:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-nat-pix-command/m-p/1081618#M878552</guid>
      <dc:creator>mohsin.khan</dc:creator>
      <dc:date>2008-12-23T07:57:23Z</dc:date>
    </item>
  </channel>
</rss>

