<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Management/NAT Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-management-nat-problem/m-p/830861#M958167</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the tip, however, I still cannot connect. When I try to establish a SSL connection from the remote CSM server to the internal interface of the local ASA I get a anti spoof error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny IP spoof from (x.x.x.x) to y.y.y.y on interface TRANSIT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, when I try to establish a SSL or SSH from the local CSM server to the external interface of the local ASA. I get the NP Indentity error previously posted. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't post the configs because its a clients network i.e. I don't have permission.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Dec 2007 14:44:08 GMT</pubDate>
    <dc:creator>paul.pearston</dc:creator>
    <dc:date>2007-12-21T14:44:08Z</dc:date>
    <item>
      <title>ASA Management/NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-nat-problem/m-p/830859#M958165</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I appear to have a NAT problem with ASA build 7.2(3). I cannot SSH or SSL (with CSM) through the inside interface to the outside interface i.e. I want to manage the device on its external interface. I want to manage the device on its external interface as I have a second CSM server at a remote site. I receive the following errors when I SSH from an internal host to the external interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-302013: Built inbound TCP connection 14343 for MANAGEMENT:x.x.x.x/3265 (x.x.x.x/3265) to NP Identity Ifc:y.y.y.y/22 (y.y.y.y/22)&lt;/P&gt;&lt;P&gt;%ASA-6-302014: Teardown TCP connection 14343 for MANAGEMENT:x.x.x.x/3265 to NP Identity Ifc:y.y.y.y/22 duration 0:00:00 bytes 0 TCP Reset-I&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the external and internal interface are logical interfaces on the same physical. Could this be the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-nat-problem/m-p/830859#M958165</guid>
      <dc:creator>paul.pearston</dc:creator>
      <dc:date>2019-03-13T00:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Management/NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-nat-problem/m-p/830860#M958166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you have "management-access outside" configured?&lt;/P&gt;&lt;P&gt;why don't you post your config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2007 13:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-nat-problem/m-p/830860#M958166</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-12-21T13:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Management/NAT Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-nat-problem/m-p/830861#M958167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the tip, however, I still cannot connect. When I try to establish a SSL connection from the remote CSM server to the internal interface of the local ASA I get a anti spoof error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny IP spoof from (x.x.x.x) to y.y.y.y on interface TRANSIT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, when I try to establish a SSL or SSH from the local CSM server to the external interface of the local ASA. I get the NP Indentity error previously posted. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't post the configs because its a clients network i.e. I don't have permission.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2007 14:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-nat-problem/m-p/830861#M958167</guid>
      <dc:creator>paul.pearston</dc:creator>
      <dc:date>2007-12-21T14:44:08Z</dc:date>
    </item>
  </channel>
</rss>

