Solved

portmap translation creation failed - (dynamic translation to pool 191(No matching global))

Posted on 2010-09-03
5
1,312 Views
Last Modified: 2012-05-10
Hi Experts -

I am receiving a 'failed portmap translation' on the company ASA5510 when attempting to ping to a given IP on a customer site.  I can see this within the syslog viewer on the ASDM, when attempting to ping an IP on a remote partner site.  For the same IP, when running a packet trace on the ASDM, I see the following : dynamic translation to pool 191 (No matching global).  

The ping (traffic)is not supposed to go to the outside interface - it should traverse a dedicated link to a DMZ to another site who is acting as a 'pass-through' to the destination (remote partner)

The translated interface appears to be the correct one.

What do I need to change in order to allow the traffic to the partner site (ping)?  I can certainly provide more detail, if needed.

Thanks for your insight!
0
Comment
Question by:davis
  • 2
  • 2
5 Comments
 
LVL 4

Assisted Solution

by:ullas_unni
ullas_unni earned 250 total points
ID: 33603746
hi,

--looks like you have an issue with NAT
--possibly you might be having a nat (inside) 191.... without a global (dmz) 191... which might be why the error no matching global..
--a show run of your device will be much appreciated.
0
 
LVL 1

Author Comment

by:davis
ID: 33648400
I was able to find the answer to my problem - it was simply a static route which needed to be added!
0
 
LVL 4

Expert Comment

by:ullas_unni
ID: 33648597
cool!
0
 
LVL 1

Accepted Solution

by:
davis earned 0 total points
ID: 33688316
to clarify the fix, I simply added the two static routes underneath 'Routing-Static Routes' section of Device Setup in ADSM.  Appreciate the pointer!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now