01-26-2018 02:43 AM - edited 02-21-2020 07:12 AM
Hi folks,
I created a NAT rule on my ASA for my MPLS users to access a internal webserver, and the same server have a NAT to outside. until now all good my mpls users access a web-server from mpls IP and have a NAT to webserver IP. Now my internal LAN users can't access the server when I do packet tracer they went to outside interface instead to connect to server directly from the LAN.
Any idea why is happen?
Thank you
01-26-2018 04:02 AM
Can you share the sanitized nat config, interface config and packet tracer output ?
01-26-2018 04:19 AM
I have no errors from packet tracer. My sites user from MPLS access the server with an mpls IP 1.1.1.1 and i have natted this IP to rel server x.x.x.x. the real server x.x.x.x have a static nat to outside 8.8.8.8
I created a record on DNS server for the mpls IP for remote users in the mpls to access the webserver but now my local user on LAN can't have access to the webserver am not sure because i change the record to the mpls ip.
01-26-2018 05:57 AM
Anyone please help to understood why the webpage with ip 41.76.7.25 not open, i capture this logs:
1: 15:53:10.128518 10.0.1.46.1183 > 41.76.7.25.80: S 2477633111:2477633111(0) win 8192 <mss 1460,nop,wscale 8,nop,nop,sackOK>
2: 15:53:10.131020 41.76.7.25.80 > 10.0.1.46.1183: S 809984383:809984383(0) ack 2477633112 win 29040 <mss 1380,nop,nop,sackOK,nop,wscale 7>
3: 15:53:10.131127 10.0.1.46.1183 > 41.76.7.25.80: . ack 809984384 win 258
4: 15:53:11.795811 10.0.1.46.1183 > 41.76.7.25.80: P 2477633112:2477633442(330) ack 809984384 win 258
5: 15:53:11.800175 41.76.7.25.80 > 10.0.1.46.1183: . ack 2477633442 win 236
6: 15:53:21.799900 10.0.1.46.1183 > 41.76.7.25.80: . 2477633441:2477633442(1) ack 809984384 win 258
7: 15:53:21.802326 41.76.7.25.80 > 10.0.1.46.1183: . ack 2477633442 win 236 <nop,nop,sack sack 1 {2477633441:2477633442} >
8: 15:53:26.832537 41.76.7.25.80 > 10.0.1.46.1183: R 809984384:809984384(0) ack 2477633442 win 236
9: 15:53:26.833193 10.0.1.46.1219 > 41.76.7.25.80: S 2294215953:2294215953(0) win 8192 <mss 1460,nop,wscale 8,nop,nop,sackOK>
10: 15:53:26.835070 41.76.7.25.80 > 10.0.1.46.1219: S 668053221:668053221(0) ack 2294215954 win 29040 <mss 1380,nop,nop,sackOK,nop,wscale 7>
11: 15:53:26.835314 10.0.1.46.1219 > 41.76.7.25.80: . ack 668053222 win 258
12: 15:53:26.835436 10.0.1.46.1219 > 41.76.7.25.80: P 2294215954:2294216284(330) ack 668053222 win 258
13: 15:53:26.839022 41.76.7.25.80 > 10.0.1.46.1219: . ack 2294216284 win 236
14: 15:53:36.849382 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
15: 15:53:36.851945 41.76.7.25.80 > 10.0.1.46.1219: . ack 2294216284 win 236 <nop,nop,sack sack 1 {2294216283:2294216284} >
16: 15:53:46.862397 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
17: 15:53:47.862702 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
18: 15:53:48.866822 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
19: 15:53:49.867081 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
20: 15:53:50.867569 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
21: 15:53:51.867463 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
22: 15:53:52.867371 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
23: 15:53:53.875092 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
24: 15:53:54.874390 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
25: 15:53:55.882431 10.0.1.46.1219 > 41.76.7.25.80: . 2294216283:2294216284(1) ack 668053222 win 258
26: 15:53:56.895476 10.0.1.46.1219 > 41.76.7.25.80: R 2294216284:2294216284(0) ack 668053222 win 0
27: 15:53:56.896056 10.0.1.46.1254 > 41.76.7.25.80: S 3464581912:3464581912(0) win 8192 <mss 1460,nop,wscale 8,nop,nop,sackOK>
28: 15:53:56.899977 41.76.7.25.80 > 10.0.1.46.1254: S 886564:886564(0) ack 3464581913 win 29040 <mss 1380,nop,nop,sackOK,nop,wscale 7>
29: 15:53:56.900084 10.0.1.46.1254 > 41.76.7.25.80: . ack 886565 win 258
30: 15:53:56.900191 10.0.1.46.1254 > 41.76.7.25.80: P 3464581913:3464582243(330) ack 886565 win 258
31: 15:53:56.904799 41.76.7.25.80 > 10.0.1.46.1254: . ack 3464582243 win 236
32: 15:54:06.912123 10.0.1.46.1254 > 41.76.7.25.80: . 3464582242:3464582243(1) ack 886565 win 258
33: 15:54:06.914808 41.76.7.25.80 > 10.0.1.46.1254: . ack 3464582243 win 236 <nop,nop,sack sack 1 {3464582242:3464582243} >
34: 15:54:12.112390 41.76.7.25.80 > 10.0.1.46.1254: R 886565:886565(0) ack 3464582243 win 236
35: 15:54:12.114557 10.0.1.46.1290 > 41.76.7.25.80: S 1925115600:1925115600(0) win 8192 <mss 1460,nop,wscale 8,nop,nop,sackOK>
36: 15:54:12.116830 41.76.7.25.80 > 10.0.1.46.1290: S 1025074812:1025074812(0) ack 1925115601 win 29040 <mss 1380,nop,nop,sackOK,nop,wscale 7>
37: 15:54:12.117028 10.0.1.46.1290 > 41.76.7.25.80: . ack 1025074813 win 258
38: 15:54:12.117303 10.0.1.46.1290 > 41.76.7.25.80: P 1925115601:1925115931(330) ack 1025074813 win 258
39: 15:54:12.121972 41.76.7.25.80 > 10.0.1.46.1290: . ack 1925115931 win 236
40: 15:54:22.132561 10.0.1.46.1290 > 41.76.7.25.80: . 1925115930:1925115931(1) ack 1025074813 win 258
41: 15:54:22.134438 41.76.7.25.80 > 10.0.1.46.1290: . ack 1925115931 win 236 <nop,nop,sack sack 1 {1925115930:1925115931} >
42: 15:54:27.152412 41.76.7.25.80 > 10.0.1.46.1290: R 1025074813:1025074813(0) ack 1925115931 win 236
43: 15:54:27.153144 10.0.1.46.1326 > 41.76.7.25.80: S 3911527877:3911527877(0) win 8192 <mss 1460,nop,wscale 8,nop,nop,sackOK>
44: 15:54:27.156379 41.76.7.25.80 > 10.0.1.46.1326: S 3437459950:3437459950(0) ack 3911527878 win 29040 <mss 1380,nop,nop,sackOK,nop,wscale 7>
45: 15:54:27.156562 10.0.1.46.1326 > 41.76.7.25.80: . ack 3437459951 win 258
46: 15:54:27.156653 10.0.1.46.1326 > 41.76.7.25.80: P 3911527878:3911528208(330) ack 3437459951 win 258
47: 15:54:27.160605 41.76.7.25.80 > 10.0.1.46.1326: . ack 3911528208 win 236
48: 15:54:37.164816 10.0.1.46.1326 > 41.76.7.25.80: . 3911528207:3911528208(1) ack 3437459951 win 258
49: 15:54:37.166724 41.76.7.25.80 > 10.0.1.46.1326: . ack 3911528208 win 236 <nop,nop,sack sack 1 {3911528207:3911528208} >
50: 15:54:42.172430 41.76.7.25.80 > 10.0.1.46.1326: R 3437459951:3437459951(0) ack 3911528208 win 236
51: 15:54:42.174032 10.0.1.46.1360 > 41.76.7.25.80: S 3967763640:3967763640(0) win 8192 <mss 1460,nop,wscale 8,nop,nop,sackOK>
52: 15:54:42.177755 41.76.7.25.80 > 10.0.1.46.1360: S 3294256904:3294256904(0) ack 3967763641 win 29040 <mss 1380,nop,nop,sackOK,nop,wscale 7>
53: 15:54:42.178060 10.0.1.46.1360 > 41.76.7.25.80: . ack 3294256905 win 258
54: 15:54:42.178320 10.0.1.46.1360 > 41.76.7.25.80: P 3967763641:3967763971(330) ack 3294256905 win 258
55: 15:54:42.182958 41.76.7.25.80 > 10.0.1.46.1360: . ack 3967763971 win 236
01-26-2018 05:04 AM
01-29-2018 12:04 AM
Hi experts,
Please any idea?
Thank you,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide