Solved

How do I configure PAT/port fowarding on cisco Asa FW

Posted on 2008-10-02
4
775 Views
Last Modified: 2011-09-20
I have a setup on cisco ASA fw with an inside host with private ip, nat'd to global IP on the outside. This host needs to be accessed by 6 diferent outside hosts each on a different tcp port(non-standard ports).
How do I achieve this using translation? Thanks
0
Comment
Question by:rigour
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 26

Accepted Solution

by:
Soulja earned 250 total points
ID: 22626808
Try this:

Place your ip's in the appropriate places


static (inside,outside) outside_ip inside_ip netmask 255.255.255.255

access-list OUTSIDE extended permit tcp host HOST1 host inside_host_ip eq port1
access-list OUTSIDE extended permit tcp host HOST2 host inside_host_ip eq port2
access-list OUTSIDE extended permit tcp host HOST3 host inside_host_ip eq port3
access-list OUTSIDE extended permit tcp host HOST4 host inside_host_ip eq port4
access-list OUTSIDE extended permit tcp host HOST5 host inside_host_ip eq port5
access-list OUTSIDE extended permit tcp host HOST6 host inside_host_ip eq port6

access-group OUTSIDE in interface outside
0
 

Author Comment

by:rigour
ID: 22632194
Thanks Soulja, I am currently putting together a design solution for an urgent implementation, so cannot physically test your suggestion straightaway. Logically I believe it will work in the scenario given earlier.

What if the inside host increased to 3 or 4 hosts that need to use the one global address for nat, because of shortage of public address. How could the 6 external hosts access the 3 internal hosts, still on the different ports? Thanks
0
 

Author Comment

by:rigour
ID: 22647891
Thanks Soulja, I am currently putting together a design solution for an urgent implementation, so cannot physically test your suggestion straightaway. Logically I believe it will work in the scenario given earlier.

What if the inside host increased to 3 or 4 hosts that need to use the one global address for nat, because of shortage of public address. How could the 6 external hosts access the 3 internal hosts, still on the different ports? Thanks
0
 
LVL 26

Expert Comment

by:Soulja
ID: 22688686
It would still remain on a per port basis.
0

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question