Solved

Cisco Port mapping problem

Posted on 2011-03-04
6
736 Views
Last Modified: 2012-05-11
I am trying to do a simple Port map on my Cisco IOS.

trying to map smtp to port 2525 for a specific host 192.168.x.x where my exchange server is.

the PROBLEM i run into is my interface has an EXTENDED access rule and i can not for the LIFE of me seem to apply the port map to the extended ACL. HERE is what im looking to do:

Overriding a System-Defined Port Mapping Example

In this example, a specific host runs HTTP services on port 25, which is the system-defined port number for SMTP services. This requires a host-specific PAM entry that overrides the system-defined default port mapping for HTTP, which is port 80. ACL 15 identifies the host address (192.168.33.33), while port 25 is mapped with HTTP services.

access-list 15 permit 192.168.33.33
ip port-map smtp port 2525 list 15

problem is that example i took from a cisco site is usint a STANDARD ACL mine is extended and since you can only have 1 ACL per direction i can't apply my port map because when i do this it refuses to work

access-list 109 extended permit 192.168.33.33
ip port-map smtp port 2525 list 15
0
Comment
Question by:mxrider_420
  • 4
6 Comments
 
LVL 6

Expert Comment

by:vikrantambhore
ID: 35041602
It's verry simple please use as per below
ip nat inside source static tcp 192.168.2.2 2525 interface Dialer1 2525


192.168.2.2------> internal exchange server
Dialer1------------> WAN Interface
0
 
LVL 15

Expert Comment

by:greg ward
ID: 35042001
access-list 109 extended permit 192.168.33.33
ip port-map smtp port 2525 list 15

did you mean

access-list 109 extended permit 192.168.33.33
ip port-map smtp port 2525 list 109

Greg
0
 
LVL 1

Author Comment

by:mxrider_420
ID: 35043592
Author:vikrantambhore --> I already have that nat rule ... still not working

Greg: that is exactly what i have been trying and it pukes:

check it out:

ROUTER3A-EXCHANGE(config)#access-list 109 extended permit 192.168.1.57
                                          ^
% Invalid input detected at '^' marker.

ROUTER3A-EXCHANGE(config)#ip port-map smtp port 2525 list 109
                                                            ^
% Invalid input detected at '^' marker.
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 1

Author Comment

by:mxrider_420
ID: 35045007
this is a strange error that i cant understand. like if my interface uses a extended acl then why cant i create a port map with that?
0
 
LVL 1

Accepted Solution

by:
mxrider_420 earned 0 total points
ID: 35046374
Answer:
Modify acl to a standard, apply a port map and then add new rule to group. forward port to host.
0
 
LVL 1

Author Closing Comment

by:mxrider_420
ID: 35107024
Not a full answer but shows the steps
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

823 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question