<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD NAT Matching in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3881740#M942122</link>
    <description>I suggested another nat not this one. &lt;BR /&gt;First, this nat you disabled to expose a server from the outside, should not be put at the first position. Order is important and I would have put it at the latest position.&lt;BR /&gt;Now this one is doing nat from DMZ to Outside and you're issue is from DMZ and Inside. Even on the packet-capture it's not being hit.&lt;BR /&gt;&lt;BR /&gt;Can you do a packet tracer like last time once this rule is disabled? &lt;BR /&gt;What version of FMC are you running?&lt;BR /&gt;</description>
    <pubDate>Fri, 28 Jun 2019 21:46:49 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2019-06-28T21:46:49Z</dc:date>
    <item>
      <title>FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3877193#M942100</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another NAT related question, i have a need to do some funky translations from our DMZ to the inside of our network for our migration, below is the topology for the lab environment that I'm testing this stuff on, the red line indicates the path of translation, below the image is the NAT rule and ACP Rule i have created to make it happen, at the very bottom is the actual question i have....if you make it that far &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;Topology&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT-Order.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/39259i3471F848630FBE55/image-size/large?v=v2&amp;amp;px=999" role="button" title="NAT-Order.jpg" alt="NAT-Order.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;NAT Rule&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21-06-2019 12-58-22 PM.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/39261i6470A35AC79E9D38/image-size/large?v=v2&amp;amp;px=999" role="button" title="21-06-2019 12-58-22 PM.jpg" alt="21-06-2019 12-58-22 PM.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21-06-2019 12-58-55 PM.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/39262i3CB4BFE0332A67C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="21-06-2019 12-58-55 PM.jpg" alt="21-06-2019 12-58-55 PM.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;ACP Rule&lt;/FONT&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21-06-2019 1-00-11 PM.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/39263i7BAE10F91C26F40F/image-size/large?v=v2&amp;amp;px=999" role="button" title="21-06-2019 1-00-11 PM.jpg" alt="21-06-2019 1-00-11 PM.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What needs to happen is a Full NAT, source and destination translation;&lt;/P&gt;&lt;P&gt;A Web call from Ubuntu-2 in the DMZ_Zone (172.16.1.100) destined for IP 172.16.1.200 is to have the source translated to 10.30.0.100 and destination to 10.20.20.100 (Inside_Zone)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now don't ask me why, its an application that cannot be changed, this configuration is a product of a dual layer checkpoint firewall architecture they had years ago, i can't change the way the app works, this unfortunately is the requirement at migration time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;The Question&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;FONT size="3"&gt;The question is about NAT Rule position, and about what matches in a NAT Rule, because, if i have this rule in the number 1 position as per below....everything works, if i move it to position 2, it does not......why&lt;/FONT&gt; &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;FONT size="3"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21-06-2019 1-07-44 PM.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/39264i4E4243D57CDC5CBB/image-size/large?v=v2&amp;amp;px=999" role="button" title="21-06-2019 1-07-44 PM.jpg" alt="21-06-2019 1-07-44 PM.jpg" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;FONT size="3"&gt;Thanks so much for your help, if you need anything clarified let me know and ill provide.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3877193#M942100</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2020-02-21T17:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3877200#M942105</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Can you move back your role at the position where it doesn't work and &lt;BR /&gt;Can you ssh your ftd and share in a text file the output of below commands please:&lt;BR /&gt;&lt;BR /&gt;- show run nat&lt;BR /&gt;- packet-tracer input DMZ_Zone icmp 172.16.1.100 8 0 172.16.1.200&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Jun 2019 03:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3877200#M942105</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-06-21T03:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3877222#M942110</link>
      <description>&lt;P&gt;Hi Francesco,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks heaps for the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did both commands the the rule in position 1 (successful) and 2 (Unsuccessful)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See attached;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 01:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3877222#M942110</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2019-06-22T01:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3878261#M942115</link>
      <description>When you moved your role into position 2, did you clear your xlate table? We can see the asa is doing a route lookup directly on going through the whole process.&lt;BR /&gt;&lt;BR /&gt;I also see you have the same nat but inverted with source from inside. Can you deactivate you nat (dmz,inside) and test only with nat(inside,dmz) by keeping it at the latest position as it's now?&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Jun 2019 04:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3878261#M942115</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-06-24T04:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3881172#M942119</link>
      <description>&lt;P&gt;Hi Francesco,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No i did not clear the xlate table, this is all done in the GUI, not command line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disabling the below rule as you suggested seems to have fixed the issue, yay!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="28-06-2019 12-03-12 PM.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/39738i4600439B27EFF915/image-size/large?v=v2&amp;amp;px=999" role="button" title="28-06-2019 12-03-12 PM.jpg" alt="28-06-2019 12-03-12 PM.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose my question is now....why? this (now disabled) rule published the 192.168.114.200 address on the outside interface and allowed me to access the webserver running on 172.16.1.100 from the outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once again, i truly appreciate the help you are giving me, its a big knowledge shift from other vendors to Cisco for NGFW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 02:08:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3881172#M942119</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2019-06-28T02:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3881740#M942122</link>
      <description>I suggested another nat not this one. &lt;BR /&gt;First, this nat you disabled to expose a server from the outside, should not be put at the first position. Order is important and I would have put it at the latest position.&lt;BR /&gt;Now this one is doing nat from DMZ to Outside and you're issue is from DMZ and Inside. Even on the packet-capture it's not being hit.&lt;BR /&gt;&lt;BR /&gt;Can you do a packet tracer like last time once this rule is disabled? &lt;BR /&gt;What version of FMC are you running?&lt;BR /&gt;</description>
      <pubDate>Fri, 28 Jun 2019 21:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3881740#M942122</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-06-28T21:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3886754#M942125</link>
      <description>&lt;P&gt;Hi Francesco,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;using FMC and FTD version 6.4.0&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 05:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3886754#M942125</guid>
      <dc:creator>Warren Sullivan - Corp</dc:creator>
      <dc:date>2019-07-09T05:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTD NAT Matching</title>
      <link>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3886809#M942130</link>
      <description>&lt;P&gt;When NAT rule "nat (DMZ,Outside) source static HOST_172.16.1.100 HOST_192.168.114.200" is in the first position, FTD is doing source translation&amp;nbsp;172.16.1.100 &amp;gt;192.168.114.200 and using Outside interface as the egress interface based on route-lookup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you use the NAT rule "nat (DMZ,Inside) source static HOST_172.16.1.100 HOST_10.30.0.100 destination static HOST_172.16.1.200 HOST_10.20.20.100", FTD is performing twice NAT -&amp;nbsp;172.16.1.100 to itself and 10.30.0.100&amp;nbsp; to&amp;nbsp;10.20.20.100. Since there is a destination NAT involved, the egress interface is taken from NAT, i.e. inside interface in this case, and routing table is not consulted for egress interface determination:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (DMZ,Inside) source static HOST_172.16.1.100 HOST_10.30.0.100 destination static HOST_172.16.1.200 HOST_10.20.20.100&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface Inside &amp;lt;----------------Here.&lt;BR /&gt;Untranslate 172.16.1.200/0 to 10.20.20.100/0&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 06:34:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-nat-matching/m-p/3886809#M942130</guid>
      <dc:creator>Ilkin</dc:creator>
      <dc:date>2019-07-09T06:34:53Z</dc:date>
    </item>
  </channel>
</rss>

