Solved

ASA5510 to ASA 5512 upgrade - NAT help

Posted on 2013-02-04
4
1,610 Views
Last Modified: 2013-03-14
I"m trying to upgrade an ASA 5510 to an ASA 5512 and I'm struggling with the new NAT commands.  I'm creating objects and when I apply them and look in running config it doesn't have all of my entries.

For example, I input this into the asa5512:

object service 9000_Ports
service tcp source range 9000 9002
service tcp source range 9100 9110
service udp source range 9000 9002
service udp source range 9100 9110
nat (inside,outside) source static 192_168_0_5 12_189_4_179 service 9000_Ports 9000_Ports

object service MATRIX
service tcp source range 41780 41795
service tcp source eq 80
service tcp source eq 8081
nat (inside,outside) source static 192_168_0_197 12_189_4_182 service MATRIX MATRIX



And it shows up in the config as:


object service 9000_Ports
 service udp source range 9100 9110
object service MATRIX
 service tcp source eq 8081
nat (inside,outside) source static 192_168_0_5 12_189_4_179 service 9000_Ports 9000_Ports
nat (inside,outside) source static 192_168_0_197 204_xxx_xx_182 service MATRIX MATRIX


I've attached the ASA5510 config in hopes someone can offer some guidance as to what I'm doing wrong.
ASA5510.txt
ASA5512.txt
0
Comment
Question by:jplagens
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 38851221
I think you need object-group service for that:

configure mode commands/options:
  icmp-type  Specifies a group of ICMP types, such as echo
  network    Specifies a group of host or subnet IP addresses
  protocol   Specifies a group of protocols, such as TCP, etc
  service    Specifies a group of TCP/UDP ports/services


Also, did you find this: http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html
It's a nice guide for migrating.
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
ID: 38851235
0
 
LVL 4

Author Comment

by:jplagens
ID: 38851389
Thanks.  I was able to get the object-groups in:

object-group service 9000PORTS
 service-object tcp source range 9000 9002
 service-object tcp source range 9100 9110
 service-object udp source range 9000 9002
 service-object udp source range 9100 9110
object-group service MATRIX
 service-object tcp source range 41780 41795
 service-object tcp source eq www
 service-object tcp source eq 8081

Having an issue with the NAT command.  It's telling me:

ERROR: 9000PORTS is not a valid service object name
ERROR: MATRIX is not a valid service object name


This the NAt command I'm trying:

nat (inside,outside) source static 192_168_0_5 204_xxx_xx_179 service 9000PORTS 9000PORTS

nat (inside,outside) source static 192_168_0_197 204_xxx_xx_182 service MATRIX MATRIX
0
 
LVL 4

Author Comment

by:jplagens
ID: 38851650
After reading through the Cisco website I've come up with this:

nat (inside,outside) source dynamic 9000PORTS interface
nat (inside,outside) source dynamic MATRIX interface

Will this work?
0

Featured Post

Enroll in June's Course of the Month

June's Course of the Month is now available! Every 10 seconds, a consumer gets hit with ransomware. Refresh your knowledge of ransomware best practices by enrolling in this month's complimentary course for Premium Members, Team Accounts, and Qualified Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question