<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse NAT issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382270#M958473</link>
    <description>&lt;P&gt;let me know which specfic config you need&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i can put that as it has lot of config?&lt;/P&gt;</description>
    <pubDate>Sat, 12 May 2018 18:33:21 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2018-05-12T18:33:21Z</dc:date>
    <item>
      <title>Reverse NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382123#M958466</link>
      <description>&lt;P&gt;Traffic is flowing from DMZ&amp;nbsp; where source IP is public and coming to inside on port 1812&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;9 19:28:17 efw-1 %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for udp src DMZ86:192.41.x.x/54535 dst inside:10.22.183.102/1812 denied due to NAT reverse path failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can i fix this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382123#M958466</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2020-02-21T15:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382134#M958468</link>
      <description>Hi,&lt;BR /&gt;Can you provide the configuration so we can have a look?&lt;BR /&gt;Can you run packet tracer and upload the output.&lt;BR /&gt;</description>
      <pubDate>Fri, 11 May 2018 22:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382134#M958468</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-05-11T22:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382247#M958470</link>
      <description>&lt;P&gt;here is packet tracer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;packet-tracer input DMZ86 udp 192.41.x.x 1024&amp;nbsp; 10.22.183.102 1812&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 10.0.0.0 255.0.0.0 inside&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group DMZ86_acl in interface DMZ86&lt;BR /&gt;access-list DMZ86_acl extended permit udp host 192.41.x.x host 10.22.183.102 eq 1812 log&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: CONN-SETTINGS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map class-default&lt;BR /&gt; match any&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class class-default&lt;BR /&gt; set connection decrement-ttl&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (DMZ86,DMZ64) 192.41.148.96 192.41.148.96 netmask 255.255.255.224&lt;BR /&gt;nat-control&lt;BR /&gt; match ip DMZ86 192.41.148.96 255.255.255.224 DMZ64 any&lt;BR /&gt; static translation to 192.41.148.96&lt;BR /&gt; translate_hits = 0, untranslate_hits = 33&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside) 2 0.0.0.0 0.0.0.0&lt;BR /&gt;nat-control&lt;BR /&gt; match ip inside any DMZ86 any&lt;BR /&gt; dynamic translation to pool 2 (192.41.148.97)&lt;BR /&gt; translate_hits = 895580, untranslate_hits = 1309&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: DMZ86&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;</description>
      <pubDate>Sat, 12 May 2018 16:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382247#M958470</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2018-05-12T16:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382248#M958471</link>
      <description>Please upload the config</description>
      <pubDate>Sat, 12 May 2018 17:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382248#M958471</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-05-12T17:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382270#M958473</link>
      <description>&lt;P&gt;let me know which specfic config you need&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i can put that as it has lot of config?&lt;/P&gt;</description>
      <pubDate>Sat, 12 May 2018 18:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382270#M958473</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2018-05-12T18:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382272#M958475</link>
      <description>Ok, please provide the running config for interfaces, nat, objects, access-list, routes&lt;BR /&gt;&lt;BR /&gt;Can you also upload the output of "show nat"</description>
      <pubDate>Sat, 12 May 2018 18:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382272#M958475</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-05-12T18:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse NAT issue</title>
      <link>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382274#M958477</link>
      <description>&lt;P&gt;config attached&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;seems i will need no nat from dmz 86 to inside?&lt;/P&gt;</description>
      <pubDate>Sat, 12 May 2018 18:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-nat-issue/m-p/3382274#M958477</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2018-05-12T18:40:55Z</dc:date>
    </item>
  </channel>
</rss>

