Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 8813
  • Last Modified:

static nat on cisco asa version 9.1

Hi

How can I configure static nat on cisco asa version 9.1?
I want to be able to access my server via rdp 3389 from external my internal ip of server is 192.168.1.10.

Interface 0/0
Nameif outside
Security-level 0
196.47.19.5

Interface 0/1
Nameif inside
Security-level 0
192.168.1.1


please give me the command to achieve this
0
ciscosupp
Asked:
ciscosupp
  • 4
  • 2
  • 2
2 Solutions
 
Pete LongConsultantCommented:
That's not a Static NAT that's a port forward (Static PAT)

object network Server-3389
  host 192.168.1.1
  nat (inside,outside) static interface service tcp 3389 3389
access-list inbound permit tcp any object Server-3389 eq 3389
access-group inbound in interface outside


Pete
0
 
Pete LongConsultantCommented:
0
 
ciscosuppAuthor Commented:
You mean network-object host 192.168.1.10 and not 192.168.1.1     :-)

I get error please see attached file
static-PAT.jpg
0
Identify and Prevent Potential Cyber-threats

Become the white hat who helps safeguard our interconnected world. Transform your career future by earning your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

 
Henk van AchterbergCommented:
This is the most clean solution:

object network SERVER
 host 192.168.1.10

object service rdp
 service tcp destination eq 3389

nat (outside,inside) source static any any destination static interface SERVER service rdp rdp unidirectional no-proxy-arp

access-list outside_access_in permit tcp any object SERVER eq 3389
access-group outside_access_in in interface outside
0
 
ciscosuppAuthor Commented:
okay thanks will try
must it be nat (outside,inside)  or nat (inside,outside,) bit confused please advice
0
 
Henk van AchterbergCommented:
exactly as I wrote it down!
0
 
ciscosuppAuthor Commented:
I tried but get error see below and my object is created

asa(config)# show object-group id rdp
object-group service rdp
 service-object tcp destination eq 3389


asaconfig)# nat (outside,inside) source static any any destination static interface SERVER service rdp rdp

ERROR: rdp is not a valid service object name

please advice
0
 
ciscosuppAuthor Commented:
got it working
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 4
  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now