Solved

Port Mapping Question

Posted on 2011-03-03
1
325 Views
Last Modified: 2013-11-05
Hello,

I have a question regarding port mappings/redirecting. I have a web application that uses port 8000. I have a private IP mapped to a Public IP, and I want to know if it's possible for users who access this application and not have to type in the ip address and then the port 8000 following or have to type domain name and then port 8000. Can I configure something on the FW or even the DNS end on Windows so that users will only have to type in the ip address or domain name (not needing to type in port 8000 afterwards) to access the application?
Thank You in advance to anyone who assists.
0
Comment
Question by:johnsink
1 Comment
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 35029389
You could do a port forward for this on the ASA/PIX.  

One thing to know is that you can not have a 1 to 1 static NAT and a 2nd port forward going to the same internal IP.  It's one or the other.  

So, you would need to configure DNS A record for webapp.domain.com to point to an IP, (for this example 10.1.1.1)  

The ASA accepts inbound traffic on 10.1.1.1 on 80 then port forwards it inside to your host on, say, 192.168.1.10 on port 8000  


It would look something like this:

static (inside,outside) tcp 10.1.1.1 80 192.168.1.10 8000
access-list outside_in extended permit tcp any host 10.1.1.1 eq http
access-group outside_in in interface outside

Here's more info:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804708b4.shtml
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Shoretel SIP Trunks failing to work after migrating internet/firewall 10 80
stacking switches 2 46
logging buffered 8 39
ASA 5510 upstream unable to exceed 20 mbps 23 28
There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now