Static NAT entry disappears when using NVI on Cisco 1921 (Multiple versions)

We have a Cisco 1921 as an IPSec tunnel endpoint where we assign static NAT entries. It is a static one-to-one NAT putting each remote endpoint as a local /24 subnet. We are using NVI and we see some of these static entries disappear when packets are unable to reach the destination. 
The production router is running 15.0(1r)M16 but we were able to reproduce this same behavior on 15.4(1)T2.
To reproduce, we add the static NVI entry:
ip nat source static X.X.X.X 172.30.250.11
And things look good for a bit:
ROUTER# sh ip nat nvi trans | i 172.30.250.11
gre 172.30.250.11:0 X.X.X>X:0 Y.Y.Y.Y:0 Y.Y.Y.Y:0
--- 172.30.250.11 138.54.32.9 --- ---
tcp Y.Y.Y.Y:60360 Z.Z.Z.Z:60360 172.30.250.11:22 X.X.X.X:22
There is a known issue with GRE traffic being dropped at this particular endpoint, so after generating GRE traffic, the entry completely disappears:
ROUTER# sh run | i 172.30.250.11
ROUTER#
ROUTER# sh ip nat nvi trans | i 172.30.250.11
gre 172.30.250.11:0 X.X.X>X:0 Y.Y.Y.Y:0 Y.Y.Y.Y:0
icmp Y.Y.Y.Y:59916 Z.Z.Z.Z:59916 172.30.250.11:59916 172.30.250.11:59916
tcp Y.Y.Y.Y:60360 Z.Z.Z.Z:60360 172.30.250.11:22 X.X.X.X:22
I can reproduce this by severing the tunnel to any other remote site, and after generating GRE traffic to the downed endpoint, the corresponding static NAT entry will disappear.
Debugging has not shown anything, and I have found some mentions of similar behavior on older versions. Has anyone seen this? We don't have support access to test all versions, so if it is known to be resolved in a particular one, we would love to know to work towards loading that version.
Thanks

Hi Ryan,
Asa cannot ahve 2 default routes, it can only have one. ASA also doesnt support PBR, so the setup that you are trying to configure would not work on the ASA. Router is the correct option for it.
Hope that helps.
Thanks,
Varun Rao
Security Team,
Cisco TAC

Similar Messages

  • Cursor disappears when using Photoshop, anyone else?

    My cursor disappears when using Photoshop, I have to leave the program to get it back. Happens constantly since installing 10.8.3.
    Was fine for years, until I upgraded my OS

    NEW, 1ST TIME POST
    I'd like to see some real effort on the part of Apple to 1) address the issue and 2) post a fix.
    I've been using the same equipment for several years (27" iMac and a Wacom Intous4).  Everything was lovely until 'upgrading' to the latest OS…  The cursor dissappears at will.  I can NOT predict the event, only that I have only found it occurring in Photoshop.
    Contacted Wacom.  No help there.
    I got VERY tired of having to close PS to get the cursor back.  My tablet is hard-wired and my keyboard is an Apple wireless.  Of course, w/o a cursor, how are you going to click on anything…  Keyboard worked, but not the Wacom.  Finally got out my wireless [Apple] mouse, fired it up, and used it as a 'backup' (for crashing my way out of PS).  The mouse never interferred with operation.  THOUGHT it was a Wacom problem, because I've yet to create the event with a normal mouse.  I admit I rarely, RARELY use a mouse.  Seems that I can't draw with a rock…
    Aggravated by the lack of interest across the board, I discovered quite by accident one day a work-around: flip to a different desktop and then right back.  Voila.  Cursor is back.  I've got 4 desktops available, so it is a quick CTL + arrow.  My work-around works for me WITHOUT FAIL.  Pay attention Apple/Adobe/Wacom.  Apparently something here is refreshing whatever and solving the problem.  Until the next time, of course.
    Apple - Adobe - Wacom, please don't think we're 'satisfied' and we'll fix it in the NEXT mulit-thousand dollar computer/OS/tablet purchase.  I love the products, but with this latest OS, you have a perfect storm of bugs (don't ask me about dropping the Internet DAILEY, s-l-o-w to non-existent blutooth connectivity, new 3D weird actions or [insert drumroll] 'THE CLOUD').
    Call any of those listed and get ready for a raft of denial and finger-pointing.  I admit, you quickly find yourself somewhere like the Phillipines or India, trying to talk to someone who can't converse with you in you own language, but that is NOT the fault of us, the end-users.
    Finally: 'Caps lock'?  Please.  Give the guy SOME credit.  Maybe the light was burnt out on the keyboard?
    C'mon.  Get with it guys!!  Denial mixed with 'passing the buck' is not an answer.  And you want MORE MONEY out of me?????
    I agree with lkooz, break out the Beseler — I'll get the trays ready…

  • Pages disappear when using xoffset

    Can anyone tell me why my pages disappear when using "crop pages xoffset" in Acrobat Pro XI?  It works fine in Acrobat Pro 9.

    The system has 4GB of memory.  The processor is Intel Core i5 - 2400.
    As per your suggestion, I updated the driver for the integrated graphics
    card (Intel Graphics HD 2000).  The new driver is dated January 2014.  The
    old driver was dated June 2011.
    I tried to replicate the blank pages situation, and none went blank.   Will
    continue to test over the next week or so, but this looks very promising.
    Many, many thanks, Pat!

  • Pasted image into gmail disappears when using Safari

    Pasted image into gmail disappears when using Safari
    I recently upgraded to Mavericks (after having a lot of seemingly unrelated trouble with my Macbook Pro (early 2011))
    Since then, when I create a new message in gmail, and paste in a screen shot (captured with command-control-shift-4), the image shows up nicely.  But after I hit send, the image disappears.  It doesn't show up to the recipient, and when I look at my sent mail, it doesn't show up there either.  There's nothing, no icon showing where the image should be, just empty space in the message.  This seems to happen in Safari, but seems to works fine when creating the message in Chrome.  (please, restrain yourself from telling me "Duh.  Use Chrome." I know it's tempting, but my computer has some issues and Chrome doesn't always work.)  If I create the same sort of message in Chrome, and then go to Safari gmail, I can see the image just fine.  So it appears to be something about keeping the image attached to the content of the message while sending (vs. a viewing problem).
    I know when Mavericks was installed, I had to install something in Safari for Adobe docs to show up again.  Is there something I need to install so that images will stay attached to the content of gmail messages again?
    Thanks

    After you click Download (the attachment) from your Safari menu bar click Window / Downloads.
    Right or control click the file in the Downloads window then click: Show in Finder
    I'm not sure if you can designate another folder for downloading web based attachments to, however, instead of accessing your Gmail
    account using Safari, you can set up the Gmail account from the Mail app on your hard drive. Mail preferences allow you to choose the
    folder you want to use for downloaded files.
    To add an account:
    Choose File > Add Account or click the Add button in the Accounts pane of Mail preferences.
    Enter information about the user.Mail searches for the information it needs to finish setting up your account. If it can’t find the information, continue to the next step.
    Enter information about the incoming and outgoing mail servers, review the account summary, and then click Create.For information about options, click the Help button (looks like a question mark).If you don’t want the account to be active immediately, deselect the “Take account online” checkbox. You can take the account online later.
    If you aren’t sure about the information to enter, contact your email service provider before you begin. When you talk with your provider, you can use the Mail settings “cheat sheet” available using the link below to record settings you might need to set up an account. If you’re switching from another application to Mail, use the cheat sheet to record information for each account you want to switch.

  • My keypad keeps disappearing when using google -- but only in the horizontal position.  In vertical, it works fine.  I have powered off and on, checked that Safari Instant is on, and cleared Safari cache.  Any help will be appreciated.

    My keypad keeps disappearing when using google -- but only in the horizontal position.   Vertically, it works fine.  I have powered off and then back on.  I have checked that Safari instant is on, and I have cleared Safari cache.  Nothing has worked so far.

    Okay -- it fixed itself.  Without any intervention, after all else had failed, and I was willing to live evermore with vertical searches.  If only everything else in my house mysteriously recovered from the broken state.
    Have no idea what was/is going on with the disappearing keypad.

  • I need to host a Shared PDF on SharePoint. If it is on SharePoint can only one person comment at a time? I know documents have to be checked out when using SharePoint. I need multiple users to be able to comment in real time and see comments in real time.

    I need to host a Shared PDF on SharePoint 2010. If it is on SharePoint can only one person comment at a time? I know documents have to be checked out when using SharePoint. I need multiple users to be able to comment in real time and see comments in real time. Is this possible?

    try here:
    http://www.bbb.org
    File a complaint with them. Verizon will call you to fix the blunder.
    But remember it is always up to the customer to insure what they are getting and what it costs. Don't trust the word of a sales person who makes their living on getting that sale. Lies, deceit or false promises will be and have been used by sales people for thousands of years.
    Good Luck

  • When using Numbers with iCloud, a new version of the spreadsheet is created even when no reisions have been made. Why is this, and how do I make it stop?

    When using Numbers with iCloud, a new version is created every time I make a change. I do not want all these revised documents. When I change a document, I commit to that change. How do I shut off this multiple-revision feature of Numbers being pushed to iCloud.
    Also....
    When using Numbers with iCloud, a new version of the spreadsheet is created even when no revisions have been made. Why is this, and how do I make it stop?
    My files are growing.

    Your plugins list shows outdated plugin(s) with known security and stability risks.
    # Java Plug-in 1.5.0_11 for Netscape Navigator (DLL Helper)
    # Adobe Shockwave for Director Netscape plug-in, version 11.0
    Update the [[Java]] and [[Shockwave|Shockwave for Director]] plugin to the latest version.
    See
    http://java.sun.com/javase/downloads/index.jsp#jdk (you need JRE)
    http://www.adobe.com/shockwave/welcome/

  • HT5925 I am trying to send data from my computer to my ipad, how do i do this if icloud says I cannot use it as I have multiple versions of outlook

    I am trying to send data from my computer to my ipad, how do i do this if icloud says I cannot use it as I have multiple versions of outlook

    Have you had more than one version of Outlook?

  • Static NAT to two servers using same port

    I have a small office network with a single public IP address. Currently we have a static nat for port 443 for the VPN. We just received new software that requires the server the software is on to be listening on port 443 across the internet. Thus, essentially I need to do natting (port forwarding) using port 443 to two different servers.
    I believe that the usual way to accomplish this would be to have the second natting use a different public facing port, natted to 443 on the inside of the network (like using port 80 and 8080 for http). But, if the software company says that it must use port 443, is there any other way to go about this? If, for example, I know the IP address that the remote server will be connecting to our local server on, is there any way to add the source IP address into the rule? Could it work like, any port 443 traffic also from x.x.x.x, forward to local machine 192.168.0.2. Forward all other port 443 traffic not from x.x.x.x to 192.168.0.3.
    Any help would be very much appreciated.
    Thanks,
    - Mike                  

    Hi,
    Using the same public/mapped port on software levels 8.2 and below would be impossible. Only one rule could apply. I think the Cisco FWSM accepts the second command while the ASA to my understanding simply rejects the second "static" statement with ERROR messages.
    On the software levels 8.3 and above you have a chance to build a rule for the same public/mapped port WHEN you know where the connections to the other overlapping public/mapped port is coming from. This usually is not the case for public services but in your situation I gather you know the source address where connections to this server are going to come from?
    I have not used this in production and would not wish to do so. I have only done a simple test in the past for a CSC user. I tested mapping port TCP/5900 for VNC twice while defining the source addresses the connections would be coming from in the "nat" configuration (8.4 software) and it seemed to work. I am not all that certain is this a stable solution. I would imagine it could not be recomended for a production environment setup.
    But nevertheless its a possibility.
    So you would need the newer software on your firewall but I am not sure what devce you are using and what software its using.
    - Jouni

  • ITunes entry disappears when I move the cursor - up to 3 times

    A small but nevertheless annoying problem - very often an entry typed into iTunes e.g. Album or Genre will disappear when I move the cursor. This will happen up to three times in a row. Then the iTunes software accepts the change. Anyone else having this experience? Thanks, Adrian OS 10.7.5 ITunes 11.0.1

    Hello mine also same problem.
    It is irritating a lot form past few days.
    I uninstalled and reinstalled the adobe reader but no use.
    I am using Windows 7 and adobe version 11.0.09
    Kindly help in this regard.

  • Static NAT inbound correct - Outbound using Interface IP

    Here is the scenario that i have:
    I have a router (2921) that has 2 interfaces:
         G0/0 - WAN - 10.254.1.10
         G0/1 - LAN - 192.168.1.230
    I have a few static NATs for servers that are behind g0/1, this is the only nat config i have except for an 'ip nat inside' and 'ip nat outside' on the interfaces:
         ip nat inside source static 192.168.1.231 10.254.1.11
         ip nat inside source static 192.168.1.232 10.254.1.12
         ip nat inside source static 192.168.1.240 10.254.1.13
    I can connect to each of these on their respective NAT'd IP.
    The issue that i have is when these servers go out they have the interface IP address!  So if i ping a server that is across the way i see
    SRC: 10.254.1.10 DST: 10.1.2.11 Protocol: ICMP
    I do not understand how this would work??  i have no other NAT configuration in the router.

    Here is the NAT table when pinging from the outside to one of the NAT'd servers:
    Pinging from 10.1.2.11 to 10.254.1.13
    Cisco2921#sh ip nat trans
    Pro Inside global      Inside local       Outside local      Outside global
    --- 10.254.1.11        192.168.1.231      ---                ---
    tcp 10.254.1.12:80     192.168.1.232:80   10.1.2.11:62512    10.1.2.11:62512
    tcp 10.254.1.12:443    192.168.1.232:443  10.1.2.11:62491    10.1.2.11:62491
    tcp 10.254.1.12:443    192.168.1.232:443  10.1.2.11:62493    10.1.2.11:62493
    --- 10.254.1.12        192.168.1.232      ---                ---
    icmp 10.254.1.13:1     192.168.1.240:1    10.1.2.11:1        10.1.2.11:1
    tcp 10.254.1.13:22     192.168.1.240:22   10.1.2.11:62386    10.1.2.11:62386
    tcp 10.254.1.13:80     192.168.1.240:80   10.1.2.11:62508    10.1.2.11:62508
    tcp 10.254.1.13:80     192.168.1.240:80   10.1.2.11:62510    10.1.2.11:62510
    tcp 10.254.1.13:80     192.168.1.240:80   10.1.2.11:62511    10.1.2.11:62511
    icmp 10.254.1.10:21531 192.168.1.240:21531 10.1.2.11:21531   10.1.2.11:21531
    udp 10.254.1.10:38288  192.168.1.240:38288 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:55051  192.168.1.240:55051 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:55383  192.168.1.240:55383 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:58944  192.168.1.240:58944 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:59854  192.168.1.240:59854 10.1.2.1:161      10.1.2.1:161
    --- 10.254.1.13        192.168.1.240      ---                ---
    Here is from an internal server to the same outside host:
    Pinging from 192.168.1.240 to 10.1.2.11
    Cisco2921#sh ip nat trans
    Pro Inside global      Inside local       Outside local      Outside global
    --- 10.254.1.11        192.168.1.231      ---                ---
    tcp 10.254.1.12:80     192.168.1.232:80   10.1.2.11:62517    10.1.2.11:62517
    tcp 10.254.1.12:443    192.168.1.232:443  10.1.2.11:62491    10.1.2.11:62491
    tcp 10.254.1.12:443    192.168.1.232:443  10.1.2.11:62493    10.1.2.11:62493
    --- 10.254.1.12        192.168.1.232      ---                ---
    tcp 10.254.1.13:22     192.168.1.240:22   10.1.2.11:62386    10.1.2.11:62386
    tcp 10.254.1.13:80     192.168.1.240:80   10.1.2.11:62515    10.1.2.11:62515
    tcp 10.254.1.13:80     192.168.1.240:80   10.1.2.11:62516    10.1.2.11:62516
    tcp 10.254.1.13:80     192.168.1.240:80   10.1.2.11:62518    10.1.2.11:62518
    icmp 10.254.1.10:7163  192.168.1.240:7163 10.1.2.1:7163      10.1.2.1:7163
    icmp 10.254.1.10:7184  192.168.1.240:7184 10.1.2.1:7184      10.1.2.1:7184
    icmp 10.254.1.10:11548 192.168.1.240:11548 10.1.2.11:11548   10.1.2.11:11548
    udp 10.254.1.10:38288  192.168.1.240:38288 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:53384  192.168.1.240:53384 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:58383  192.168.1.240:58383 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:58944  192.168.1.240:58944 10.1.2.1:161      10.1.2.1:161
    udp 10.254.1.10:59143  192.168.1.240:59143 10.1.2.1:161      10.1.2.1:161
    --- 10.254.1.13        192.168.1.240      ---                ---

  • EXTERNAL HDD NOW DISAPPEARS WHEN USING MY MBP IN CLOSED LID MODE

    I have an 15" MBP 2.53 running Snow Leopard, which installed fine. When I go to use it with my Apple 24" Display and my external hard drive, the external HDD disappears when I go into closed lid mode.
    The finder freezes too, and I can no longer enter into Time Machine.
    The external HDD does show up in disk utility, however.

    and please ... STOP SHOUTING!
    It doesn't make your message any more relevant or increase the motivation to help you. To be honest, it makes you look like a moron, if anything.
    Cheers,
    Jazz

  • Text "disappears" when using text box tool

    We are running Adobe Acrobat Standard vers. 7.0.9 inside Thomson Corporation's GoFileRoom vers. 6.0. When using the text box tool to add comments to a pdf, the text within the text box "takes on" the color of the background of the box, making it seem that the text has disappeared. The only way to see the text is to edit the text box and change the font color OR to view the contents of the text box in the Comments section. How do I resolve this? Would appreciate any help.

    I am having the same problem. Both with text boxes and text in the actual document. Do you think it is GoFileRoom related? I never made the connection but I wouldn't be surprised. It seems worse when different versions of Adobe are used. Some have ver 7 and other ver 8 but we are all using GFR.
    Have you had any help?

  • Stage disappears when using selection tool

    I'm using Photoshop CS6 Extended and i discover a strange problem in some documents that makes working impossible.
    When i use the normal rectangle selection tool in some documents then suddenly all the content of the stage disappears when i release the mouse
    It doesn't occur with any document just with some.
    Does anyone has discovered the same issue and has an idea how to solve it?

    Sorry, i meant canvas..."stage" was influenced by Flash
    Posting a Screenshot makes no sense, because you just cant see no content anymore. All the panels are still there, but the canvas suddenly is empty in the moment i release the mouse when i'm using the selection tool.
    I'm running Photoshop CS6 Extended on Windows 7 Professional 64Bit with 16GB RAM, 18GB of free disk space on an SSD.
    It might be a working memory problem (?!). After closing Chrome (where i had a lot of tabs) and restarting the system, noe everything works fine. The problem is, that it happened a few times with different PSD-documents...

  • Applications disappear when using external mouse

    Using windows 7 professional on a brand new T410 (2537-RZ5).
    Happens only when using an external mouse and mouse is stationary for random periods of time (seconds or minutes).
    Problem: all applications (internet explorer, office, etc) will suddenly disappear (sometimes only leaving outside border of application) to reveal desk top - does not matter which application i have open or whether there is one or multiple. Desktop color is correct but instead of solid color it has a diagonal ribbed effect to the color. Applications will reappear moment I move the mouse.
    Happens with variety of external mouse - does not happen if using laptop mousepad (i.e. no plug in). All latest windows and lenovo updates installed as far as I know but has not fixed bug.  Has happened again just while writing this message - quite frustrating.
    Please help if you can.

    I noticed a similar phenomenon and found that my mouse cursor was landing over the sensitive spot on the right side of the task bar which harbors the "Show Desktop" Aero feature.  Check it out.
    W540 20GBCTO, Ultra Dock, W520, 4270CTO, W510, 4318CTO; (2)T500, 2081CTO; Y560, 064657U, Y530, 405166U; T61p, 6465CTO, A31p, and L2461x Multi-touch Monitor, Mini Dock Plus Series 3

Maybe you are looking for

  • Please help! I need more pags in my photobook and it wont let me get anymore then 78?

    Hello, I'm trying to finish off my brothers wedding photo book and adobe wont let me do anymore then 78 pages and I need about 20 more. If you can help with this I would appreciate it a lot.

  • Commons-fileupload-1.2.1. 4 kB limit

    Hi everybody. I am using apache commons-fileupload-1.2.1.jar to upload files (multipart data). I have copy/pasted the code from their example page: [http://commons.apache.org/fileupload/streaming.html] However, I have problems. When I open the inputS

  • HP W2207H and Mac Pro (7300) portrait mode ?

    I was thinking about getting the HP W2207H monitor as a second monitor hooked to a 1st gen Mac Pro w/ 7300 card. Will this monitor work in portrait mode ? Using Tiger currently will be Leopard soon. Just curious if anyone has used this monitor ... It

  • Passing values to parameters in Documents using se61..

    Hi Experts/Gurus, Can we define parameters in SE61 under type "Document  class: General Text" for a document? If so can any one please tell the steps? Regards, Yugesh Edited by: Yugesh Reddy on Nov 6, 2009 8:39 AM

  • Accounts in PGI and Billing

    Hi Gurus, As we know, there are accounting documents generated when PGI and Billing doc created. I just like to clarify the difference between these 2 types of accounts. Am I right to say: 1. When PGI, its Inventory accounting and the postings involv