?
Solved

Cisco ASA 5505 - Trying to configure PAT rules correctly

Posted on 2011-09-25
4
Medium Priority
?
395 Views
Last Modified: 2012-05-12
I recently hired an oDesk sub to set Access Rules and configure static PAT settings (NAT) for incoming calls to our Polycom device.  His Access Rules (firewall holes) look good, but his PAT settings look wrong.

- Image 1 shows his effort at the PAT rule.  10.20.2.21 is the private static IP of the Polycom.
- Image 2 shows my effort to correct the same PAT rule.  63.227.23.XX is the static IP of the office.  (I hid the last octet.)

I'll be candid, I'm not a network guy.  My PAT rule may be wrong-headed as well.  Please be candid in your responses.

 


oDesk-PAT-Setting.png
jdana-PAT-Setting.png
0
Comment
Question by:jdana
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 4

Accepted Solution

by:
dcj21 earned 2000 total points
ID: 36596887
Yous is correct for an Incoming connection, but from only the one IP address. If you want anyone to connect, change the 64.x.x.x to any.

If that doent work, what messages are you getting in debug or monitor?
0
 

Author Comment

by:jdana
ID: 36717048
dcj21,

64.x.x.x is the public IP of the firewall's outside interface.  This is based on a suggestion a consultant made to me about a year ago.  Your suggestion of "any" makes more sense to me.  Will they both work?

J
0
 
LVL 4

Assisted Solution

by:dcj21
dcj21 earned 2000 total points
ID: 36717270
When you say only allow 64.x.x.x you are telling the firewall to only allow traffic that originates from your outside interface. Only your ASA and any NAT'ed traffic from inside would have that address. Users on the internet will have a different IP address.

So if you want anyone on the internet to connect, use any. If there is a specific company, use their IP address.
0
 

Author Closing Comment

by:jdana
ID: 36720096
Thanks for the follow-up.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question