[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Static route with port range

Posted on 2011-03-15
12
Medium Priority
?
843 Views
Last Modified: 2012-05-11
I am trying to create a static map from the outside to the inside with a port range on a Cisco 515e.  I have created and saved the access-list below.  However, the static route continues to receive an error stating Invalid Global Port Range .  I have found some solutions but they are clear as mud. From what i can understand, the pix can not do statics with port ranges.  Any ideas and I remember now why I haven't used Cisco in years.

Here are the commands:
static (inside,outside) tcp XX.XX.182.213 range 6400 8191 XXX.XXX.0.206 range 6400 8191 netmask 255.255.255.255 0 0
0
Comment
Question by:raidertech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +2
12 Comments
 
LVL 18

Accepted Solution

by:
jmeggers earned 100 total points
ID: 35142259
Maybe it's just semantics, but I suspect you understand this is not a static route, it's a static NAT statement.

Not sure you can do what you're trying to with a port range.  I've only ever done it with a single port, like translating 80 to 8080, or something similar.
0
 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 200 total points
ID: 35142276
I am afraid that isn't going to work for a static. You can only use a port range in access lists. You'll have to create every static separately :-~
Sorry for the bad news.
0
 

Author Comment

by:raidertech
ID: 35142503
that is what i was afraid of and am running into it.  and yes i meant static nat.
0
Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

 
LVL 12

Assisted Solution

by:Pugglewuggle
Pugglewuggle earned 200 total points
ID: 35142769
Hi there,

You can make a static nat rule and that covers all ports. You can also make a static pat rule, but you have to make one for each port you want to open. Beware of doing this though, as each static pat translation will consume some memory on your PIX... if you have to many it will crash because your memory will fill up. Here's a doc on how to setup PAT rules.

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_staticpat.html

These commands also work with PIXes.

Cheers!
0
 

Author Comment

by:raidertech
ID: 35152230
pugglewuggle, thanks for the link and i have read over but was able to locate anything regarding port ranges
0
 
LVL 12

Assisted Solution

by:Pugglewuggle
Pugglewuggle earned 200 total points
ID: 35152350
so where it says the protocol tcp or udp, after that it says a port... Sometimes it's a word such as smtp or http. When you need to make a port range you have to make a separate static statement for every port. It's not very fun but that's how it works. Access lists allow ranges to be opened in the firewall, but statics must be specified one by one. Again, be carefil to watch your ram if you add large numbers of statics... Hundreds or thousands can fill your memory up and crash the box. I've done that before by accident. Make sure you leave 10-15% free.

Cheers!
0
 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 200 total points
ID: 35152504
What Pugglewuggle is saying is that if you have more than one public address you can use one of them to do a 1-on-1 static. That way the public address is (exclusively) linked to the XXX.XXX.0.206 address (one on one) so you don't have to create a static for every port you want to forward through the static. You then define the ports you want to pass through in your access list, in which you can use port ranges.
But that only works if you have more than one public address available........
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 35157581
... that is indeed what I said... ;-)
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 35481564
May I propose a split between Pugglewuggle and yours truly?
0
 
LVL 33

Expert Comment

by:digitap
ID: 35714931
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question