Solved

How do I configure PAT/port fowarding on cisco Asa FW

Posted on 2008-10-02
4
776 Views
Last Modified: 2011-09-20
I have a setup on cisco ASA fw with an inside host with private ip, nat'd to global IP on the outside. This host needs to be accessed by 6 diferent outside hosts each on a different tcp port(non-standard ports).
How do I achieve this using translation? Thanks
0
Comment
Question by:rigour
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 26

Accepted Solution

by:
Soulja earned 250 total points
ID: 22626808
Try this:

Place your ip's in the appropriate places


static (inside,outside) outside_ip inside_ip netmask 255.255.255.255

access-list OUTSIDE extended permit tcp host HOST1 host inside_host_ip eq port1
access-list OUTSIDE extended permit tcp host HOST2 host inside_host_ip eq port2
access-list OUTSIDE extended permit tcp host HOST3 host inside_host_ip eq port3
access-list OUTSIDE extended permit tcp host HOST4 host inside_host_ip eq port4
access-list OUTSIDE extended permit tcp host HOST5 host inside_host_ip eq port5
access-list OUTSIDE extended permit tcp host HOST6 host inside_host_ip eq port6

access-group OUTSIDE in interface outside
0
 

Author Comment

by:rigour
ID: 22632194
Thanks Soulja, I am currently putting together a design solution for an urgent implementation, so cannot physically test your suggestion straightaway. Logically I believe it will work in the scenario given earlier.

What if the inside host increased to 3 or 4 hosts that need to use the one global address for nat, because of shortage of public address. How could the 6 external hosts access the 3 internal hosts, still on the different ports? Thanks
0
 

Author Comment

by:rigour
ID: 22647891
Thanks Soulja, I am currently putting together a design solution for an urgent implementation, so cannot physically test your suggestion straightaway. Logically I believe it will work in the scenario given earlier.

What if the inside host increased to 3 or 4 hosts that need to use the one global address for nat, because of shortage of public address. How could the 6 external hosts access the 3 internal hosts, still on the different ports? Thanks
0
 
LVL 26

Expert Comment

by:Soulja
ID: 22688686
It would still remain on a per port basis.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question