<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nat problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051066#M894470</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am always at the same point, y cannot make acces rules work (after have made nat work )car the pdm tells me (null rule).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me wath is wrong with my config?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Oct 2008 17:21:49 GMT</pubDate>
    <dc:creator>roussillon</dc:creator>
    <dc:date>2008-10-29T17:21:49Z</dc:date>
    <item>
      <title>nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051054#M894454</link>
      <description>&lt;P&gt;Hi everybody.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having used iptables and sofware firewall (like astaro) in the past  , now I 'am tring to understand nat on a pix 6.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm tring to redirect conexions to ports  on externals ip addresses to a server with an internal ip I mean:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the connexion to 212.44.229.2:ssh most be  redirected to 192.168.229.2:ssh ip &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the connexion to 212.44.229.3:80 most be  redirected to 192.168.229.2:80 ip &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the connexion to 212.44.229.4:25 most be  redirected to 192.168.229.2:25 ip &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did this configuration but only the ssh redirection works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 vlan229 logical&lt;/P&gt;&lt;P&gt;nameif vlan229 local security95&lt;/P&gt;&lt;P&gt;ip address local 192.168.229.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 192.168.229.2 lenovo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address local 192.168.229.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pdm location 212.44.229.2 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 212.44.229.3 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 212.44.229.4 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location lenovo 255.255.255.255 local&lt;/P&gt;&lt;P&gt;pdm location 192.168.229.0 255.255.255.255 local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 2 interface&lt;/P&gt;&lt;P&gt;nat (inside) 2 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (local) 2 192.168.229.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (outside,local) tcp lenovo ssh 212.44.229.2 ssh netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (outside,local) tcp lenovo www 212.44.229.3 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (outside,local) tcp lenovo smtp 212.44.229.4 smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) 212.44.229.2 lenovo netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but only th ssh conexion over 212.44.229.2 is routed to 192.168.229.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have red about nat on pix but this case is not clear to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea? thanks to you all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051054#M894454</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2019-03-11T14:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051055#M894456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco's NAT terminology can be weird at times. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setting up a NAT Port Translation&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 22 212.44.229.2 192.168.229.15 22 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setting up a NAT translation (all ports &amp;amp; protocols)&lt;/P&gt;&lt;P&gt;static (local,outside) 212.44.229.2 192.168.229.15 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like most of your NATs are backwards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a little HOW-TO on NAT's (look for NAT)-&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.packetpros.com/wiki/index.php/Cisco" target="_blank"&gt;http://www.packetpros.com/wiki/index.php/Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 14:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051055#M894456</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-27T14:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051056#M894460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes your are rigth , that is awesome they are backward. btu I created them PDM how is taht possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I fix the nat rule but I can not make the acl rule&lt;/P&gt;&lt;P&gt;it tell me: no communication is allowed between two interfaces wich have the same security level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the external interface of the pix is not in network 212.44.229.0/24 but in all net devices a route point network 212.44.229.2 to be accessed via the pix. The pix thinks that network 212.44.229.0/24 is in the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that  a new problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 16:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051056#M894460</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-27T16:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051057#M894461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you have a simple diagram with interface names?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 16:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051057#M894461</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-27T16:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051058#M894462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hy, this is the schema.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;My ISP route the 212.44.229.0/24 to my PIX &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    INTERNET&lt;/P&gt;&lt;P&gt;           |&lt;/P&gt;&lt;P&gt;           |&lt;/P&gt;&lt;P&gt;     ROUTER(ip route 212.44.229.0/24 via le pix)&lt;/P&gt;&lt;P&gt;        |&lt;/P&gt;&lt;P&gt;        |&lt;/P&gt;&lt;P&gt;    ______________________&lt;/P&gt;&lt;P&gt;   |outside (gb-ethernet0)|&lt;/P&gt;&lt;P&gt;   |                      |&lt;/P&gt;&lt;P&gt;   |   PIX                |&lt;/P&gt;&lt;P&gt;   |                      |&lt;/P&gt;&lt;P&gt;   |inside (gb-ethernet1) |&lt;/P&gt;&lt;P&gt;   |local (vlan229)       |&lt;/P&gt;&lt;P&gt;   |local (vlan228)       |&lt;/P&gt;&lt;P&gt;   |______________________|&lt;/P&gt;&lt;P&gt;         |&lt;/P&gt;&lt;P&gt;         |&lt;/P&gt;&lt;P&gt;         |&lt;/P&gt;&lt;P&gt;         |--192.168.229.0/24 (vlan229)&lt;/P&gt;&lt;P&gt;         |&lt;/P&gt;&lt;P&gt;         |--129.168.228.0/24 (vlan228)      &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2008 22:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051058#M894462</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-27T22:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051059#M894463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, you all&lt;/P&gt;&lt;P&gt;now I have changed my conf as follow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 vlan229 logical&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 vlan230 logical&lt;/P&gt;&lt;P&gt;nameif gb-ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif gb-ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif vlan229 local security95&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.3 eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.4 eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound permit ip any 192.168.229.192 255.255.255.192&lt;/P&gt;&lt;P&gt;ip address local 192.168.229.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pdm location 212.44.229.2 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 212.44.229.3 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 192.168.229.0 255.255.255.255 Admin&lt;/P&gt;&lt;P&gt;pdm location 192.168.229.192 255.255.255.192 Admin&lt;/P&gt;&lt;P&gt;pdm location 212.44.229.4 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 192.168.229.2 255.255.255.255 Admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 2 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 2 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (local) 2 192.168.229.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.3 www 192.168.229.2 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.4 smtp 192.168.229.2 smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.2 ssh 192.168.229.2 ssh netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, with no result either.&lt;/P&gt;&lt;P&gt;I do not want to come back to astaro firewall as I have a pix now and logically a pix is made for firewalling. &lt;/P&gt;&lt;P&gt;Any help please??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2008 11:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051059#M894463</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-28T11:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051060#M894464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the config above, the interface name is inside and outside, but in your statics, they are outside and local. They have to match, is the trusted interface named local or inside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2008 13:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051060#M894464</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-28T13:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051061#M894465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, but if you read carefully you will see this two lines too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 vlan229 logical&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif vlan229 local security95 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I can use local, am I rigth? or the nat rules  are not possible over logical interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2008 13:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051061#M894465</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-28T13:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051062#M894466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use anything you like so that's not a problem. Can you post a full sanitized config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2008 13:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051062#M894466</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-28T13:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051063#M894467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi you all.&lt;/P&gt;&lt;P&gt;I have made some changes and now NAT works. But there are several problemes. The PDM does not take into account my ACL it tell me this rule is null. After doing a translation I tested with an access rule and it's true my acces list is taged with (null rule) so I cannot filter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exemple of acl:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.x.x.3 eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface gb-ethernet0 1000auto&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 1000auto&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 vlan1000 physical&lt;/P&gt;&lt;P&gt;interface gb-ethernet1 vlan229 logical&lt;/P&gt;&lt;P&gt;nameif gb-ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif gb-ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif vlan229 local security95&lt;/P&gt;&lt;P&gt;enable password the_password encrypted&lt;/P&gt;&lt;P&gt;passwd the_password encrypted&lt;/P&gt;&lt;P&gt;hostname pix&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.168.229.2 lenovo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inbound permit tcp any host 192.168.225.55&lt;/P&gt;&lt;P&gt;access-list inbound permit tcp host 192.168.225.51 any&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.3 eq www&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound permit ip any 192.168.229.192 255.255.255.192&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 212.x.x.2 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 192.168.254.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address local 192.168.229.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pdm location 212.x.x.2 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 212.x.x.3 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location 192.168.229.0 255.255.255.255 local&lt;/P&gt;&lt;P&gt;pdm location 212.x.x.4 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm location lenovo 255.255.255.255 local&lt;/P&gt;&lt;P&gt;pdm location 192.168.229.192 255.255.255.192 local&lt;/P&gt;&lt;P&gt;pdm location 192.168.229.192 255.255.255.192 outside&lt;/P&gt;&lt;P&gt;pdm logging informational 100&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 2 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 2 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (local) 2 lenovo 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.2 ssh lenovo ssh netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.3 www lenovo www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.4 2525 lenovo smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.5 www lenovo 8080 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 212.44.228.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;aaa authentication secure-http-client&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2008 11:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051063#M894467</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-29T11:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051064#M894468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A null rule indicates that an access rule was configured for a host that is not visible on another interface. This rule is null because no traffic can flow between these two hosts even though the access rule would permit it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your ACL should look like this-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.3 eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.4 eq 2525&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.5 eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may have to remove the rule from the interface to edit it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2008 13:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051064#M894468</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-29T13:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051065#M894469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hy, thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My rules already are like this.:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.3 eq www &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2008 14:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051065#M894469</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-29T14:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051066#M894470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am always at the same point, y cannot make acces rules work (after have made nat work )car the pdm tells me (null rule).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me wath is wrong with my config?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2008 17:21:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051066#M894470</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-29T17:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: nat problems</title>
      <link>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051067#M894471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;after doing some tests I arrive to the following conclusion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; connexion to 212.44.229.2:ssh  redirect to 192.168.229.2:ssh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; connexion to 212.44.229.3:80  redirect to 192.168.229.2:80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; connexion to 212.44.229.4:25 most be redirect to 192.168.229.2:25 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this type of config does not work properly cause it does not permit manage acces-list(null rule).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connexion to 212.44.229.2:ssh  redirect to 192.168.229.2:ssh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; connexion to 212.44.229.3:80  redirect to 192.168.229.3:80 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; connexion to 212.44.229.4:25 redirect to 192.168.229.4:25  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that work well cause it allows me to manage acces-list to the destination hosts. This mean that in my server interface I have to add an ip alias  for each external ip I want to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can even do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connexion to 212.44.229.3:80  redirect to 192.168.229.3:8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mi conf looks like this(from my last test):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.3 eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 212.44.229.2 eq smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (local) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.2 ssh lenovo ssh netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.3 www 192.168.229.3 8080 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (local,outside) tcp 212.44.229.2 smtp lenovo smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I that all rigth or there is a way for not using ip alias?&lt;/P&gt;&lt;P&gt;Thank you all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2008 13:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-problems/m-p/1051067#M894471</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2008-10-30T13:34:38Z</dc:date>
    </item>
  </channel>
</rss>

