<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic not able to communicate from inside to inside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977160#M919059</link>
    <description>&lt;P&gt;Please look at the attached network diagram for your information. I added a command:&lt;/P&gt;&lt;P&gt;"same-security-traffic permit intra-interface" on the Internet FW, and I also force the traffic from internal firewall to 172.16.24.22 must pass through Internet FW by adding a route in the internal FW:&lt;/P&gt;&lt;P&gt;"route DMZ 172.16.24.22 255.255.255.255 172.16.24.3"&lt;/P&gt;&lt;P&gt;but this time I got the error message like this:"&lt;/P&gt;&lt;P&gt;%ASA-3-305006: portmap translation creation failed for tcp src inside:172.16.3.50/3925 dst inside:172.16.24.22/443"&lt;/P&gt;&lt;P&gt;and I did configured NAT and PAT on Internet FW, static NAt is used to translate the 172.16.24.22 into public IP and PAT is used to allow 172.16.3.0 to to able to access Internet:&lt;/P&gt;&lt;P&gt;global (outside) 1 2.x.x.41 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;global (outside) 2 2.x.x.42 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,outside) 2.x.x.40 172.16.24.22 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;someone has the solution for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:54:20 GMT</pubDate>
    <dc:creator>shibindong</dc:creator>
    <dc:date>2019-03-11T12:54:20Z</dc:date>
    <item>
      <title>not able to communicate from inside to inside interface</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977160#M919059</link>
      <description>&lt;P&gt;Please look at the attached network diagram for your information. I added a command:&lt;/P&gt;&lt;P&gt;"same-security-traffic permit intra-interface" on the Internet FW, and I also force the traffic from internal firewall to 172.16.24.22 must pass through Internet FW by adding a route in the internal FW:&lt;/P&gt;&lt;P&gt;"route DMZ 172.16.24.22 255.255.255.255 172.16.24.3"&lt;/P&gt;&lt;P&gt;but this time I got the error message like this:"&lt;/P&gt;&lt;P&gt;%ASA-3-305006: portmap translation creation failed for tcp src inside:172.16.3.50/3925 dst inside:172.16.24.22/443"&lt;/P&gt;&lt;P&gt;and I did configured NAT and PAT on Internet FW, static NAt is used to translate the 172.16.24.22 into public IP and PAT is used to allow 172.16.3.0 to to able to access Internet:&lt;/P&gt;&lt;P&gt;global (outside) 1 2.x.x.41 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;global (outside) 2 2.x.x.42 netmask 255.255.255.224&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,outside) 2.x.x.40 172.16.24.22 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;someone has the solution for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977160#M919059</guid>
      <dc:creator>shibindong</dc:creator>
      <dc:date>2019-03-11T12:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: not able to communicate from inside to inside interface</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977161#M919060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Put a global statement like this to allow inside users to access the DMZ server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (dmz) 1 172.16.24.200 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is just an example. Or use nat-exemption to bypass NAT for this traffic flow (From inside segement to DMZ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you enable dynamic NAT/PAT the whole 'no nat-control' thing blows away (for that zone).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 08:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977161#M919060</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-03T08:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: not able to communicate from inside to inside interface</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977162#M919063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Put a global statement like this to allow inside users to access the DMZ server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (dmz) 1 172.16.24.200 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is just an example. Or use nat-exemption to bypass NAT for this traffic flow (From inside segement to DMZ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you enable dynamic NAT/PAT the whole 'no nat-control' thing blows away (for that zone).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 08:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977162#M919063</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-03T08:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: not able to communicate from inside to inside interface</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977163#M919073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually I think I misunderstood your network, it should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 172.16.24.200 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you already have the same-security-traffic permit intra-interface, as stated in your email.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 09:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-communicate-from-inside-to-inside-interface/m-p/977163#M919073</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-03T09:28:32Z</dc:date>
    </item>
  </channel>
</rss>

