<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local NAT on ASA 5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100058#M893381</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also dug a little further and the site-to-site seems to be comming active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was a problem within the traffix selection for the L2L.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx a lot for the support on the access-list!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just having this problem right now:&lt;/P&gt;&lt;P&gt;6	Nov 19 2008	16:58:29	302013	10.10.10.87	10.0.74.5	Built inbound TCP connection 5460 for outside:10.10.10.87/37590 (10.10.10.87/37590) to inside:10.0.74.5/21 (192.168.222.1/21)&lt;/P&gt;&lt;P&gt;6	Nov 19 2008	16:58:59	302014	10.10.10.87	10.0.74.5	Teardown TCP connection 5460 for outside:10.10.10.87/37590 to inside:10.0.74.5/21 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;So connection goes through but time's out!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; think changing/adding the ftp instead of the ftp-data will resolve my issue!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx a lot!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Nov 2008 14:13:28 GMT</pubDate>
    <dc:creator>LSAEleander</dc:creator>
    <dc:date>2008-11-19T14:13:28Z</dc:date>
    <item>
      <title>Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100045#M893328</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm quit new to these boards so I'll try to explain my problem as best as I can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If something is missing or incorrect pls inform me so I can update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to do a local NAT before a VPN IPSEC because my internal range is allready know at the customers site. I've set up the static NAT rules and access policy.&lt;/P&gt;&lt;P&gt;Here you have the config as it is on the ASA right now.&lt;/P&gt;&lt;P&gt;Local server IP: 10.0.74.5&lt;/P&gt;&lt;P&gt;Required NAT address: 192.168.222.1&lt;/P&gt;&lt;P&gt;Customer range: 10.10.10.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Config:&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 match address outside_2_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set peer 200.200.200.200 &lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set transform-set ESP-AES-256-SHA&lt;/P&gt;&lt;P&gt;tunnel-group 200.200.200.200 type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 200.200.200.200 ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key "key"&lt;/P&gt;&lt;P&gt;access-list outside_2_cryptomap extended permit ip host 192.168.222.1 10.10.10.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_2_cryptomap extended permit ip host 10.0.74.5 10.10.10.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.222.1 10.0.74.5 netmask 255.255.255.255 -&amp;gt; 1-on-1 NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm allowing this first before I start narrowing it down to only ftp!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 192.168.222.1&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any host 192.168.222.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outboundnat2 permit ip host 10.0.74.5 10.10.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 2 access-list outboundnat2&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be grately appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100045#M893328</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2019-03-11T14:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100046#M893333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can remove this line &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_2_cryptomap extended permit ip host 10.0.74.5 10.10.10.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;because traffic will be from the Natted address ie. NAT happens before the crypto-map access-list check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The remote peer needs to have a mirror image of this access-list so &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_2_cryptomap extended permit ip 10.10.10.0 255.255.255.0 host 192.168.222.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also remove the following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 192.168.222.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as your next line permitting ip covers tcp. But then you say you will be looking to narrow that down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only other thing is you need to be aware that with a L2L VPN there are 2 ways in terms of acl's it can be setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) "sysopt connection permit-vpn" If you have this line in your config then traffic coming from the remote site down the tunnel is unencrypted and then it bypasses the acl attached to the outside interface ie. the acl on the outside interface does not have any effect on the traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If you don't have "sysopt connection permit-vpn" then the traffic will be then checked against the acl on the outside interface after being decrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see whether you are running sysopt connection permit-vpn run &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"sh running-config sysopt"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe it is on y default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 10:20:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100046#M893333</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T10:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100047#M893341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx for the quick reply.&lt;/P&gt;&lt;P&gt;Changed as you proposed but I can't find any sysopt connection entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 10:32:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100047#M893341</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T10:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100048#M893346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the output of running the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh running-config sysopt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want to turn off bypassing the acl then you will need to enter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)# no sysopt connection permit-vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but that is only if you want the traffic to be subject to your acl on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 10:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100048#M893346</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T10:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100049#M893351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No response, just a blank line.&lt;/P&gt;&lt;P&gt;Included the complete config in attachement!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx for the quick replies!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 10:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100049#M893351</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T10:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100050#M893354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay no problem. I just checked the command references and this is on by default - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s8_72.html#wp1198155" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s8_72.html#wp1198155&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you want to bypass the acl on the outside interface you don't need to do anything. If you want the incoming VPN traffic to be checked against the acl on the outside interface then you need to enter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#  no sysopt connection permit-vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still bit of a mystery as to why it doesn't show the sysopt settings - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s6_72.html#wp1287358" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s6_72.html#wp1287358&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 11:23:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100050#M893354</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T11:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100051#M893358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've changed the config as you proposed and mailed the customer to try the connection again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you by any chance had a look at the added config in my previous post? To see I didn't made any mistakes in the ACL's?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 11:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100051#M893358</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T11:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100052#M893362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to add the following &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 192.168.222.1 eq ftp-data&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FTP is a funny one. Do you know if it is passive ftp or not ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have problems getting the FTP to work then you may need to adjust your acl. But first things first, need to see if the VPN tunnel comes up &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 11:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100052#M893362</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T11:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100053#M893367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I addedd the information you requested and also the FTP into the access-list. (see attached word doc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now I'm having these problems.&lt;/P&gt;&lt;P&gt;"Rejecting IPSec Tunnel: no matching crypto map entry for remote proxy 10.10.10.87/255.255.255.255/0/0 local proxy 192.168.222.1/255.255.255.255/0/0 on interface outside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking into them right now.&lt;/P&gt;&lt;P&gt;What ACL am I missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Really appreciate you spending this much time to find a solution!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100053#M893367</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T12:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100054#M893371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And here's teh attachement! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:20:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100054#M893371</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T12:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100055#M893375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this coming up on the ASA we have been modifying the config on ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you happen to have the config for both devices ie. the one we have been dealing with and the other one ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just as a quick test could you add this line to your crypto-map access-list and retry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_2_cryptomap extended permit ip host 192.168.222.1 host 10.10.10.87 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It really should not make a difference but just in case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100055#M893375</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T12:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100056#M893377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Added the ACL but nothing changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the attachement you can find the latest config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We only manage this one firewall, which is a pitty and moreso because the firewall on the other site isn't a Cisco. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before making your proposed change for the sysopt the L2L was working. SO it must be in the access lists!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx a lot.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 12:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100056#M893377</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T12:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100057#M893379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you remove the sysopt line and then let me know if it is working ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# sysopt connection permit-vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 14:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100057#M893379</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T14:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100058#M893381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also dug a little further and the site-to-site seems to be comming active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was a problem within the traffix selection for the L2L.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx a lot for the support on the access-list!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just having this problem right now:&lt;/P&gt;&lt;P&gt;6	Nov 19 2008	16:58:29	302013	10.10.10.87	10.0.74.5	Built inbound TCP connection 5460 for outside:10.10.10.87/37590 (10.10.10.87/37590) to inside:10.0.74.5/21 (192.168.222.1/21)&lt;/P&gt;&lt;P&gt;6	Nov 19 2008	16:58:59	302014	10.10.10.87	10.0.74.5	Teardown TCP connection 5460 for outside:10.10.10.87/37590 to inside:10.0.74.5/21 duration 0:00:30 bytes 0 SYN Timeout&lt;/P&gt;&lt;P&gt;So connection goes through but time's out!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; think changing/adding the ftp instead of the ftp-data will resolve my issue!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx a lot!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 14:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100058#M893381</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T14:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100059#M893382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you think you have it working now or at least know what to do ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm dying to get out on my mountain bike but happy to hang around if you need further help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 14:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100059#M893382</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T14:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100060#M893384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've made several changes, but the customer also has a ISDN router, on that router I just added the needed entries. (completely forgot about that one)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Get out on your MTB and go out there.&lt;/P&gt;&lt;P&gt;I thank you a lot for your help allready and really appreciate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I can't solve it I'll repost in here.&lt;/P&gt;&lt;P&gt;Tomorrow is another day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;btw I'm situated in Belgium so on the GMT+1 time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have fun and hopefully i'll see you around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 14:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100060#M893384</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T14:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100061#M893385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Have fun and hopefully i'll see you around"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will do. I'm in UK so it's dark by about 4:00 (2:30 at the moment) so i'll check later or tomorrow morning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 14:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100061#M893385</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T14:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100062#M893387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tested with inspect ftp (enabled or disable) -&amp;gt; no reslut!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see that L2L is active within the ASDM logging. (there are only 2 L2L configs on this ASA and they semm both active)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FTP from one site works well. (but the data is exempted)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When checking the log I see SYN Timeouts for this connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Added the 10.10.10.0 network within my Cisco 800 router to pass by the firewall (10.0.74.252) to be sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm quit in the dark here. I'm overseeing something or I'm misunderstanding somthing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The sysopt is still active though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just let me know when you're back so we look any further!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 15:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100062#M893387</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-19T15:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100063#M893389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay. Quick test to see if it is the outside acl that is the problem. Can reenable sysopt connection permit-vpn ie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)# sysopt connection permit-vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then retest and let me know. If it works at least we can concentrate on the acl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 17:02:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100063#M893389</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-19T17:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Local NAT on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100064#M893391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good mornig Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you had a nice ride yesterday.&lt;/P&gt;&lt;P&gt;I've changed the sysopt again and awaiting confirmation from the other side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In attachement the current running &amp;amp; working config for our customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've exempted trafic from one site and everything works well for them, but to the other site (due to sec reasons) I an only allow ftp! (STill not working)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Getting SYN timeouts within the log but I see the translation is made! Really don't get it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Eleander&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Nov 2008 08:07:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-nat-on-asa-5505/m-p/1100064#M893391</guid>
      <dc:creator>LSAEleander</dc:creator>
      <dc:date>2008-11-20T08:07:41Z</dc:date>
    </item>
  </channel>
</rss>

