ASA Asymmetric NAT

We had a normal AnyConnect VPN configured and everyone could get to the inside resources. We then put an application in the DMZ and some vendors needed access to it. When we tried to hit one of the servers we got the following error.

%ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp src outside: dst DMZ: denied due to NAT reverse path failure

Looking up the logging error on Cisco provided a little bit of info and scouring the net did too, but no clear definitive “fix”. Thinking about what it was doing and reviewing the NAT rules I was pretty sure I  knew what was happening. Traffic was getting NAT’d out of the DMZ. We certainly didn’t want that. I create a NAT0 entry (I’m running 8.2.5 on this particular firewall) and that fixed it.

VPN assigned addresses: /24
DMZ address space: /24

Commands to resolve:

ASA-VPN-FW(config)# access-list DMZ_ACCESS_FROM_VPN permit ip
ASA-VPN-FW(config)#  nat (DMZ) 0 access-list DMZ_ACCESS_FROM_VPN

120 Comments on “ASA Asymmetric NAT”

  1. Pingback: bunny vibe
  2. Pingback: FOREX SIGNALS
  3. Pingback: Trend Mystery
  4. Pingback: mint tutorial
  5. Pingback: wand massager
  6. Pingback: nuc5cpyh treiber
  7. Pingback: penis pump
  8. Pingback: silicone vibrator
  9. Pingback: first time anal
  10. Pingback: dildos for women
  11. Pingback: פורום סקס
  12. Pingback: sabung ayam online
  13. Pingback: bmw vin decoder
  14. Pingback: best strap on
  15. Pingback: vibrating panties
  16. Pingback: jelly dildo
  17. Pingback: movie ratings
  18. Pingback: 918kiss
  19. Pingback: sarkari rojgar
  20. Pingback:
  21. Pingback:
  22. Pingback: Baby
  23. Pingback: sexycam
  24. Pingback: Sexy live chat
  25. Pingback: Funny shirts
  26. Pingback: Gossip
  27. Pingback: 918kiss
  28. Pingback: Taste remix
  29. Pingback: sexy Latina dance
  30. Pingback: Hot Latina dance
  31. Pingback: slowdive dagger
  32. Pingback: Pandora Bracelets
  33. Pingback: sexy female cams
  34. Pingback: Hot ladies
  35. Pingback: Tellybuzz
  36. Pingback: Free adult sex
  37. Pingback: Free sexy cams
  38. Pingback: Funny Instagram
  39. Pingback: Free adult
  40. Pingback: Free chat
  41. Pingback: двуполье
  42. Pingback: Yeah yeah
  43. Pingback: hot girls live
  44. Pingback: Rap videos
  45. Pingback: beeg
  46. Pingback: sexy girls stream
  47. Pingback: sexy cams live
  48. Pingback: sexy stream
  49. Pingback: buy backlinks
  50. Pingback: Music videos
  51. Pingback: rap hip hop
  52. Pingback: Funny song
  53. Pingback: Hip hop videos
  54. Pingback: juicy chat
  55. Pingback: space_miamii chat
  56. Pingback: Hot rap mixtape
  57. Pingback: rf32fmqdbxwaa
  58. Pingback: deck tiling Nelson
  59. Pingback: girl chat
  60. Pingback: fun chat
  61. Pingback: Funny free chat
  62. Pingback: Mobile erotic chat
  63. Pingback: click this site
  64. Pingback: wand massager
  65. Pingback: clear dildo
  66. Pingback: free porn
  67. Pingback: psicologo avezzano
  68. Pingback: sexy gaming Chat
  69. Pingback: sexy Latina duo
  70. Pingback: sweet Sofia cam
  71. Pingback: sexy Melody webcam
  72. Pingback: Tory Burch
  73. Pingback: gucci handbags
  74. Pingback: Hot webcam
  75. Pingback: Sexy chat
  76. Pingback: funny hip hop
  77. Pingback: Comedy rap
  78. Pingback: hot hunk sexy
  79. Pingback:

Leave a Reply