• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1003
  • Last Modified:

Cisco ASA 5505 v8.3 Port Forwarding

Hi,

I am having trouble creating a port forward using ASA Version 8.3(1) on our ASA 5505

We only have 1 external IP and I'm trying to route IAX traffic (UDP 4569) to our internal PBX (10.0.5.100)
I have created an access rule which I think is correct;
access-list outside_access_in extended permit object iax any interface outside

Open in new window


but I'm struggling with the NAT rules.

Thanks for your help.
0
skysys
Asked:
skysys
  • 2
1 Solution
 
InteraXCommented:
With 8.3, the acl should reference the internal ip of the server, not the nat'd ip of the server. It looks like the acl is using the external IP for the destination.
0
 
InteraXCommented:
See http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html for the conversion to 8.3 guide for how ACL's etc have changed in 8.3
0
 
skysysAuthor Commented:
Great, The ACL was the bit I thought I had right!

access-list outside_access_in extended permit object iax any object pbx01
nat (outside,inside) source static any any destination static interface pbx01 service iax iax
0
 
kuohCommented:
What is your NAT rule now?  Something like this should work.

access-list outside_access_in extended permit udp any host 10.0.5.100 eq 4569

nat (inside,outside) static interface service udp 4569 4569
0

Featured Post

Prepare for an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program curriculum features two internationally recognized certifications from the EC-Council at no additional time or cost.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now