Solved

ASA5510 to ASA 5512 upgrade - NAT help

Posted on 2013-02-04
4
1,592 Views
Last Modified: 2013-03-14
I"m trying to upgrade an ASA 5510 to an ASA 5512 and I'm struggling with the new NAT commands.  I'm creating objects and when I apply them and look in running config it doesn't have all of my entries.

For example, I input this into the asa5512:

object service 9000_Ports
service tcp source range 9000 9002
service tcp source range 9100 9110
service udp source range 9000 9002
service udp source range 9100 9110
nat (inside,outside) source static 192_168_0_5 12_189_4_179 service 9000_Ports 9000_Ports

object service MATRIX
service tcp source range 41780 41795
service tcp source eq 80
service tcp source eq 8081
nat (inside,outside) source static 192_168_0_197 12_189_4_182 service MATRIX MATRIX



And it shows up in the config as:


object service 9000_Ports
 service udp source range 9100 9110
object service MATRIX
 service tcp source eq 8081
nat (inside,outside) source static 192_168_0_5 12_189_4_179 service 9000_Ports 9000_Ports
nat (inside,outside) source static 192_168_0_197 204_xxx_xx_182 service MATRIX MATRIX


I've attached the ASA5510 config in hopes someone can offer some guidance as to what I'm doing wrong.
ASA5510.txt
ASA5512.txt
0
Comment
Question by:jplagens
  • 2
  • 2
4 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
I think you need object-group service for that:

configure mode commands/options:
  icmp-type  Specifies a group of ICMP types, such as echo
  network    Specifies a group of host or subnet IP addresses
  protocol   Specifies a group of protocols, such as TCP, etc
  service    Specifies a group of TCP/UDP ports/services


Also, did you find this: http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html
It's a nice guide for migrating.
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
Comment Utility
0
 
LVL 4

Author Comment

by:jplagens
Comment Utility
Thanks.  I was able to get the object-groups in:

object-group service 9000PORTS
 service-object tcp source range 9000 9002
 service-object tcp source range 9100 9110
 service-object udp source range 9000 9002
 service-object udp source range 9100 9110
object-group service MATRIX
 service-object tcp source range 41780 41795
 service-object tcp source eq www
 service-object tcp source eq 8081

Having an issue with the NAT command.  It's telling me:

ERROR: 9000PORTS is not a valid service object name
ERROR: MATRIX is not a valid service object name


This the NAt command I'm trying:

nat (inside,outside) source static 192_168_0_5 204_xxx_xx_179 service 9000PORTS 9000PORTS

nat (inside,outside) source static 192_168_0_197 204_xxx_xx_182 service MATRIX MATRIX
0
 
LVL 4

Author Comment

by:jplagens
Comment Utility
After reading through the Cisco website I've come up with this:

nat (inside,outside) source dynamic 9000PORTS interface
nat (inside,outside) source dynamic MATRIX interface

Will this work?
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now