Solved

Cisco ASA 5510 port forward two external ip addresses to one internal ip address

Posted on 2012-03-19
9
1,643 Views
Last Modified: 2012-04-10
I'm replacing a Cyberguard SG580 with a Cisco ASA 5510.

On the SG580, I used alias IP addresses along with NAT port forwarding to forward two external ip addresses to one internal ip address.

How do I accomplish this on the ASA 5510?

When I use static routes, the ASA 5510 only allows 1 external ip address to be forwarded to 1 internal ip address.
0
Comment
Question by:Fletcher-Reinhardt
  • 4
  • 4
9 Comments
 
LVL 10

Expert Comment

by:pclinuxguru
Comment Utility
I have over 30 on my 5520...

Depends on how it is setup. Is it one line or do you have 2 physical lines for your external?
0
 
LVL 17

Assisted Solution

by:Kvistofta
Kvistofta earned 500 total points
Comment Utility
object network MyWebServer1
 host 192.168.1.10
 nat (inside,outside) static 1.2.3.10

object network MyWebServer2
 host 192.168.1.10
 nat (inside,outside) static 1.2.3.11

access-l outside permit tcp any object MyWebServer1 eq www
access-l outside permit tcp any object MyWebServer2 eq www
access-g outside in int outside

Best regards
Kvistofta
0
 
LVL 1

Author Comment

by:Fletcher-Reinhardt
Comment Utility
Kvistofta,
Your commands do not seem valid.
Can you correct or elaborate?

pclinuxguru
To answer your question, I only have one (1) physical line for my external ip address.  I want to forward both 1.2.3.10 and 1.2.3.11 to 192.168.1.10
0
 
LVL 17

Expert Comment

by:Kvistofta
Comment Utility
If my commands are not valid in your box, I guess you have an older OS-version. Up to v8.2 uses another syntax, and with that syntax you cannot achieve what you want. If you upgrade to 8.3 or 8.4 you can use my commands above.

Best regards Kvistofta
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 1

Author Comment

by:Fletcher-Reinhardt
Comment Utility
Kvistofta,
You are correct, the router we have is v8.2.  

Is it possible to do what I am trying to do on v8.2, or do I need to upgrade to v8.3?

Everything I tried will not allow two outside IP addresses to be forwarded to one inside IP address.
0
 
LVL 17

Expert Comment

by:Kvistofta
Comment Utility
It is not possible to do with 8.2, you need to upgrade to a newer version. After doing that, you can use my commands above.

Best regards
Kvistofta
0
 
LVL 1

Author Comment

by:Fletcher-Reinhardt
Comment Utility
Kvistofta,
Your solution works for the most part, except when I ping MyWebServer2, the ACA sends back the IP Address of MyWebServer1.

How do I fix that?
0
 
LVL 17

Accepted Solution

by:
Kvistofta earned 500 total points
Comment Utility
Sounds like you should add icmp inspection. "fixup protocol icmp" and then "clear xlat".

Best regards
Kvistofta
0
 
LVL 1

Author Closing Comment

by:Fletcher-Reinhardt
Comment Utility
Kvistofta knows the Cisco ASA!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now