<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA nat issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337472#M969241</link>
    <description>&lt;P&gt;But his flow don't make sense. Why on earth you would like to start a connection from the real IP do the NAT IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;This would cause a hair pinning situation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
    <pubDate>Sun, 25 Feb 2018 20:36:26 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2018-02-25T20:36:26Z</dc:date>
    <item>
      <title>ASA nat issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337395#M969156</link>
      <description>&lt;P&gt;ASA Version 9.2(2)4&lt;/P&gt;
&lt;P&gt;I am having an issue creating NAT to my web server after following suggested sample from this link.&lt;/P&gt;
&lt;P&gt;Here is my config&lt;/P&gt;
&lt;P&gt;Webserver:192.168.16.28&lt;/P&gt;
&lt;P&gt;Public IP: 80.248.12.189&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network Web&lt;BR /&gt;host 192.168.16.28&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nat (inside,outside) static 80.248.12.189 service tcp 8080 8080&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;access-list outside-in extended permit IP any host 192.168.16.28&lt;/P&gt;
&lt;P&gt;access-group outside-in in interface outside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have another web server with similar config above which is working fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help on this issue, i have tried different config to no avail&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337395#M969156</guid>
      <dc:creator>olumidekolawole1</dc:creator>
      <dc:date>2020-02-21T15:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA nat issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337409#M969157</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you run a packet tracer what is the result?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 15:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337409#M969157</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-02-25T15:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA nat issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337443#M969158</link>
      <description>&lt;P&gt;Here is the result of packet tracer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;JEE-LAG# packet-tracer input inside tcp 80.248.12.189 8080 192.168.16.28 8080&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 192.168.16.0 255.255.255.0 inside&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group inside-out in interface inside&lt;BR /&gt;access-list inside-out extended permit ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 7&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 8&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 6857867, packet dispatched to next module&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;JEE-LAG#&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 17:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337443#M969158</guid>
      <dc:creator>olumidekolawole1</dc:creator>
      <dc:date>2018-02-25T17:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA nat issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337444#M969159</link>
      <description>I have another web server using public IP 80.248.12.183 with similar config with this new one I am trying to create, also on port 8080. Is there any problem using port 8080 for another web server?&lt;BR /&gt;</description>
      <pubDate>Sun, 25 Feb 2018 17:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337444#M969159</guid>
      <dc:creator>olumidekolawole1</dc:creator>
      <dc:date>2018-02-25T17:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA nat issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337445#M969160</link>
      <description>&lt;P&gt;Very sorry to border you.&lt;/P&gt;
&lt;P&gt;Since I am not with packet tracer command, I&amp;nbsp;am sending you another one with the input being the internal address, thus the packet drop at the end of the result&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;JEE-LAG# packet-tracer input inside tcp 192.168.16.28 8080 80.248.12.189 8080&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 80.248.12.128 255.255.255.192 outside&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group inside-out in interface inside&lt;BR /&gt;access-list inside-out extended permit ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network HR&lt;BR /&gt;nat (inside,outside) static 80.248.12.189 service tcp 8080 8080&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 192.168.16.28/8080 to 80.248.12.189/8080&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (sp-security-failed) Slowpath security checks failed&lt;/P&gt;
&lt;P&gt;JEE-LAG#&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 18:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337445#M969160</guid>
      <dc:creator>olumidekolawole1</dc:creator>
      <dc:date>2018-02-25T18:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA nat issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337449#M969161</link>
      <description>&lt;P&gt;You can't.&amp;nbsp; The firewall need to have different port externally in order to redirect correctly. Internally it is ok to have the same port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per the Packet Tracer, everything looks ok in terms of config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 18:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337449#M969161</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-02-25T18:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA nat issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337472#M969241</link>
      <description>&lt;P&gt;But his flow don't make sense. Why on earth you would like to start a connection from the real IP do the NAT IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;This would cause a hair pinning situation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 20:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-issue/m-p/3337472#M969241</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-02-25T20:36:26Z</dc:date>
    </item>
  </channel>
</rss>

