Avatar of hexvader
hexvader
Flag for United States of America asked on

Pix 506 E Multiple Port Configuration

Experts,
I have a client who is using a pix 506e as a firewall.  They are getting a new phone system and the installing company has asked them to open the following ports:

5060 – UDP/TCP
•         5004 – UDP/TCP
•         10000-10201 - UDP

I was able to set these up in the access list by using a group-object based on this article:
https://www.experts-exchange.com/questions/23210702/Port-Forwarding-ontheCisco-ASA-5505.html

However, at the bottom of this artilce, it states I have to manually static map each of the
200 plus ports in the 10000 - 10201 range.  Here is the text from the above article:

object-group service group_1 tcp-udp
  port-object range 1717 1723
access-list outside_access_in permit tcp any interface outside object-group group_1

but then you need a static for every port!!!

static (inside,outside) tcp interface 1717 10.10.10.4 1717 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1718 10.10.10.4 1718 netmask 255.255.255.255 0 0

etc

There is no way of creating 1 static mapping - for ex>

static (inside, outside) tcp interface etc ......

to list all these ports ?

Please advise.
Thanks
John
CiscoSoftware FirewallsRouters

Avatar of undefined
Last Comment
Pete Long

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Pete Long

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck