Solved

Cisco ASA 5505 v8.3 Port Forwarding

Posted on 2010-09-18
4
977 Views
Last Modified: 2012-05-10
Hi,

I am having trouble creating a port forward using ASA Version 8.3(1) on our ASA 5505

We only have 1 external IP and I'm trying to route IAX traffic (UDP 4569) to our internal PBX (10.0.5.100)
I have created an access rule which I think is correct;
access-list outside_access_in extended permit object iax any interface outside

Open in new window


but I'm struggling with the NAT rules.

Thanks for your help.
0
Comment
Question by:skysys
  • 2
4 Comments
 
LVL 16

Accepted Solution

by:
InteraX earned 500 total points
ID: 33708093
With 8.3, the acl should reference the internal ip of the server, not the nat'd ip of the server. It looks like the acl is using the external IP for the destination.
0
 
LVL 16

Expert Comment

by:InteraX
ID: 33708117
See http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html for the conversion to 8.3 guide for how ACL's etc have changed in 8.3
0
 

Author Closing Comment

by:skysys
ID: 33708167
Great, The ACL was the bit I thought I had right!

access-list outside_access_in extended permit object iax any object pbx01
nat (outside,inside) source static any any destination static interface pbx01 service iax iax
0
 
LVL 6

Expert Comment

by:kuoh
ID: 33708220
What is your NAT rule now?  Something like this should work.

access-list outside_access_in extended permit udp any host 10.0.5.100 eq 4569

nat (inside,outside) static interface service udp 4569 4569
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SonicWALL SIP Transformation Problem 4 86
Cisco Switch Port Security 2 44
Cisco 3650 switch 7 32
VLAN Overused monitor 4 15
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question