<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA NAT problem? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726796#M970723</link>
    <description>&lt;P&gt;I have two interfaces that I am trying to communicate.  VPNaccess is security level 100 and DMZ-50 is a SL50.  Default rules.  Below are the NATs currently in place.  When I try to ping 172.16.50.21 I get the following 305005 No translation group for icmp src VPNaccess:CyndiWS dst DMZ-50:syslog1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I try to ping 10.11.2.121 - nothing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC told me to put in 'static (VPNaccess,DMZ-50) 10.0.0.0 10.0.0.0'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that didn't work either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; description vpn access for technicians&lt;/P&gt;&lt;P&gt; nameif VPNaccess&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.11.2.111 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description Logging servers&lt;/P&gt;&lt;P&gt; nameif DMZ-50&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.50.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 172.16.50.21 syslog1&lt;/P&gt;&lt;P&gt;name 10.31.103.86 CyndiWS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (outside) 15 66.x.x.190 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (inside) 5 172.16.11.190 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (VPNaccess) 10 10.11.2.120 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (DMZ-50) 20 172.16.50.2 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (DMZ-50,outside) 66.x.x.132 inspector netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DMZ-50,VPNaccess) 10.11.2.121 syslog1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (VPNaccess,DMZ-50) 10.0.0.0 10.0.0.0 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:01:40 GMT</pubDate>
    <dc:creator>cmpiontek</dc:creator>
    <dc:date>2019-03-11T11:01:40Z</dc:date>
    <item>
      <title>ASA NAT problem?</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726796#M970723</link>
      <description>&lt;P&gt;I have two interfaces that I am trying to communicate.  VPNaccess is security level 100 and DMZ-50 is a SL50.  Default rules.  Below are the NATs currently in place.  When I try to ping 172.16.50.21 I get the following 305005 No translation group for icmp src VPNaccess:CyndiWS dst DMZ-50:syslog1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I try to ping 10.11.2.121 - nothing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC told me to put in 'static (VPNaccess,DMZ-50) 10.0.0.0 10.0.0.0'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that didn't work either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; description vpn access for technicians&lt;/P&gt;&lt;P&gt; nameif VPNaccess&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.11.2.111 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description Logging servers&lt;/P&gt;&lt;P&gt; nameif DMZ-50&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.50.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 172.16.50.21 syslog1&lt;/P&gt;&lt;P&gt;name 10.31.103.86 CyndiWS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (outside) 15 66.x.x.190 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (inside) 5 172.16.11.190 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (VPNaccess) 10 10.11.2.120 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (DMZ-50) 20 172.16.50.2 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (DMZ-50,outside) 66.x.x.132 inspector netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DMZ-50,VPNaccess) 10.11.2.121 syslog1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (VPNaccess,DMZ-50) 10.0.0.0 10.0.0.0 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726796#M970723</guid>
      <dc:creator>cmpiontek</dc:creator>
      <dc:date>2019-03-11T11:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT problem?</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726797#M970724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using this static instead of the one the TAC told you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (VPNaccess,DMZ-50) 10.11.2.0 10.11.2.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 13:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726797#M970724</guid>
      <dc:creator>rigoberto.cintron</dc:creator>
      <dc:date>2007-08-23T13:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT problem?</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726798#M970725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's not the problem. 10.0.0.0/8 and 10.11.2.0/16 would both include the inside host in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is you have a destination nat for the host you are pinging in the dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ-50,VPNaccess) 10.11.2.121 syslog1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To ping syslog1 via it's dmz address (172.16.50.21) you would have to remove that destination nat. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise you have to ping it by 10.11.2.121.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static that TAC gave you will allow you to ping any other dmz address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpfulp posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 13:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726798#M970725</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-23T13:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT problem?</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726799#M970726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, so i removed the  static 10.11.2.121  and ping 172.16.50.21 and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put the static back in and ping 10.11.2.121 and the packet doesn't go through.  I have scopes on both sides and it is never presented in the DMZ.  Should it work that way?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 14:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726799#M970726</guid>
      <dc:creator>cmpiontek</dc:creator>
      <dc:date>2007-08-23T14:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT problem?</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726800#M970727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"OK, so i removed the static 10.11.2.121 and ping 172.16.50.21 and it works."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I put the static back in and ping 10.11.2.121 and the packet doesn't go through."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Did you try a clear xlate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I have scopes on both sides and it is never presented in the DMZ. Should it work that way?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Could you explain what you mean?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 14:17:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726800#M970727</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-23T14:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA NAT problem?</title>
      <link>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726801#M970728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure 10.11.2.121 is not used by any machine in vpnaccess interface. 10.11.2.121 has to be a free public IP address, otherwise when you try to ping 10.11.2.121, the packets may go to the actual machine rather than going to the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If if it is indeed a free IP address, then do "debug icmp trace" or collect syslogs as you try to ping 10.11.2.121 and see if the ICMP requests are even reaching the PIX or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2007 20:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-nat-problem/m-p/726801#M970728</guid>
      <dc:creator>hsajwan</dc:creator>
      <dc:date>2007-08-23T20:01:57Z</dc:date>
    </item>
  </channel>
</rss>

