<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global &amp; Nat issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888028#M973240</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an issue using nat &amp;amp; global; i have the following config on my pix, running 6.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 access-list ftp_clients&lt;/P&gt;&lt;P&gt;nat (inside) 5 access-list DomainControllers&lt;/P&gt;&lt;P&gt;nat (inside) 5 172.16.254.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list ftp_clients permit any&lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.45 &lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.46&lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.47&lt;/P&gt;&lt;P&gt;global (outside) 5 212.98.x.x&lt;/P&gt;&lt;P&gt;global (outside) 2 216.236.y.y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the thing is that the sh xlate output shows that the Domain COntrollers are using the Global 2, and not the Global 5, as seen below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAT Global 216.236.y.y(1041) Local 172.16.16.45(1053) &lt;/P&gt;&lt;P&gt;PAT Global 216.236.x.x(1032) Local 172.16.16.47(1047)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any tips why this is so?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:29:10 GMT</pubDate>
    <dc:creator>m-mneimneh</dc:creator>
    <dc:date>2019-03-11T11:29:10Z</dc:date>
    <item>
      <title>Global &amp; Nat issue</title>
      <link>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888028#M973240</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an issue using nat &amp;amp; global; i have the following config on my pix, running 6.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 access-list ftp_clients&lt;/P&gt;&lt;P&gt;nat (inside) 5 access-list DomainControllers&lt;/P&gt;&lt;P&gt;nat (inside) 5 172.16.254.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list ftp_clients permit any&lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.45 &lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.46&lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.47&lt;/P&gt;&lt;P&gt;global (outside) 5 212.98.x.x&lt;/P&gt;&lt;P&gt;global (outside) 2 216.236.y.y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the thing is that the sh xlate output shows that the Domain COntrollers are using the Global 2, and not the Global 5, as seen below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAT Global 216.236.y.y(1041) Local 172.16.16.45(1053) &lt;/P&gt;&lt;P&gt;PAT Global 216.236.x.x(1032) Local 172.16.16.47(1047)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any tips why this is so?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888028#M973240</guid>
      <dc:creator>m-mneimneh</dc:creator>
      <dc:date>2019-03-11T11:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Global &amp; Nat issue</title>
      <link>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888029#M973241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe it is because they are matching first on this access list assigned to global 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ftp_clients permit any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2007 13:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888029#M973241</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-10-23T13:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Global &amp; Nat issue</title>
      <link>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888030#M973242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try it this way...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 access-list DomainControllers &lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.254.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;nat (inside) 5 access-list ftp_clients &lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.45 &lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.46 &lt;/P&gt;&lt;P&gt;access-list DomainControllers permit host 172.16.16.47 &lt;/P&gt;&lt;P&gt;access-list ftp_clients permit any &lt;/P&gt;&lt;P&gt;global (outside) 2 212.98.x.x &lt;/P&gt;&lt;P&gt;global (outside) 5 216.236.y.y &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2007 13:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888030#M973242</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-10-23T13:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Global &amp; Nat issue</title>
      <link>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888031#M973243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tried what you suggested, and it's still not working. is this a normal behavior?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any other tips please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2007 10:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888031#M973243</guid>
      <dc:creator>m-mneimneh</dc:creator>
      <dc:date>2007-10-26T10:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global &amp; Nat issue</title>
      <link>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888032#M973244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is something wrong in your &lt;/P&gt;&lt;P&gt;nat (inside) 5 access-list ftp_clients &lt;/P&gt;&lt;P&gt;you do no match any Subnet of your inside interface.. Try 0.0.0.0 0.0.0.0 or the subnet you would like to nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2007 12:33:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/global-nat-issue/m-p/888032#M973244</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2007-10-29T12:33:15Z</dc:date>
    </item>
  </channel>
</rss>

