Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Double PAT Problems

Hi,

Topology:

Host -> FWSM -> Cat65K (Host Source IP PAT'ed on SVI) -> ASA 2 -> ASA 1 (Source IP again PAT'ed on outside interface -> Internet

I am not able to access the internet with the above. Only built connection logs can be seen on all the firewalls and after some wait a TCP Reset-O is seen on them. I ran a sniffer on the host and noticed that the initial SYN, SYN/ACK, ACK goes thru but then the host goes into a loop of TCP Retransmission/Dup ACK and the destination never responds.

Can dual PAT'ing on the way out to the internet can cause such problems. For some reason, the destination does not recognize any exchange after the initial TCP handshake.

Please assist.

Thanks.

1 REPLY
Hall of Fame Super Blue

Re: Double PAT Problems

There is no reason in theory why dual patting should not work. In fact from memory i believe i have done this before without issue.

What does the translation table look like on both the 6500 and the ASA ?

Jon

296
Views
0
Helpful
1
Replies
CreatePlease to create content