[Webinar] Streamline your web hosting managementRegister Today

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 8953
  • Last Modified:

static nat on cisco asa version 9.1

Hi

How can I configure static nat on cisco asa version 9.1?
I want to be able to access my server via rdp 3389 from external my internal ip of server is 192.168.1.10.

Interface 0/0
Nameif outside
Security-level 0
196.47.19.5

Interface 0/1
Nameif inside
Security-level 0
192.168.1.1


please give me the command to achieve this
0
ciscosupp
Asked:
ciscosupp
  • 4
  • 2
  • 2
2 Solutions
 
Pete LongTechnical ConsultantCommented:
That's not a Static NAT that's a port forward (Static PAT)

object network Server-3389
  host 192.168.1.1
  nat (inside,outside) static interface service tcp 3389 3389
access-list inbound permit tcp any object Server-3389 eq 3389
access-group inbound in interface outside


Pete
0
 
Pete LongTechnical ConsultantCommented:
0
 
ciscosuppAuthor Commented:
You mean network-object host 192.168.1.10 and not 192.168.1.1     :-)

I get error please see attached file
static-PAT.jpg
0
Get Certified for a Job in Cybersecurity

Want an exciting career in an emerging field? Earn your MS in Cybersecurity and get certified in ethical hacking or computer forensic investigation. WGU’s MSCSIA degree program was designed to meet the most recent U.S. Department of Homeland Security (DHS) and NSA guidelines.  

 
Henk van AchterbergSr. Technical ConsultantCommented:
This is the most clean solution:

object network SERVER
 host 192.168.1.10

object service rdp
 service tcp destination eq 3389

nat (outside,inside) source static any any destination static interface SERVER service rdp rdp unidirectional no-proxy-arp

access-list outside_access_in permit tcp any object SERVER eq 3389
access-group outside_access_in in interface outside
0
 
ciscosuppAuthor Commented:
okay thanks will try
must it be nat (outside,inside)  or nat (inside,outside,) bit confused please advice
0
 
Henk van AchterbergSr. Technical ConsultantCommented:
exactly as I wrote it down!
0
 
ciscosuppAuthor Commented:
I tried but get error see below and my object is created

asa(config)# show object-group id rdp
object-group service rdp
 service-object tcp destination eq 3389


asaconfig)# nat (outside,inside) source static any any destination static interface SERVER service rdp rdp

ERROR: rdp is not a valid service object name

please advice
0
 
ciscosuppAuthor Commented:
got it working
0

Featured Post

Get Certified for a Job in Cybersecurity

Want an exciting career in an emerging field? Earn your MS in Cybersecurity and get certified in ethical hacking or computer forensic investigation. WGU’s MSCSIA degree program was designed to meet the most recent U.S. Department of Homeland Security (DHS) and NSA guidelines.  

  • 4
  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now