Solved

Object NAT with multiple ports needed?

Posted on 2014-02-20
9
426 Views
Last Modified: 2014-02-21
I have a question about Cisco Object NAT on iOS 8.3+ as it relates to machines needing more than one port PAT'd from outside to inside.  Example being an Exchange box, which needs both 25 and 443.  Object NAT only allows you to PAT one port per object.  My workaround for this is to just create multiple objects... "Exchange-smtp" and "Exchange-https" and then setup the PAT rules on each object for the respective ports, but this seems clunky. Is there a better/best practice way to set this up so that I don't need multiple objects per internal server?
0
Comment
Question by:valheru_m
  • 5
  • 2
  • 2
9 Comments
 
LVL 28

Accepted Solution

by:
mikebernhardt earned 500 total points
ID: 39874216
If you have multiple public IP addresses available, you can set up static NAT and all ports on a particular public IP will be translated to the Exchange server. If not, the way you described is the only option.
0
 
LVL 6

Expert Comment

by:insidetech
ID: 39874264
You are doing it exactly as it is designed. This offers controls on what is allowed to enter your server.
"open" public IP to the server w/o any port filtering is never a good idea.
0
 
LVL 5

Author Comment

by:valheru_m
ID: 39874287
Insidetech -

I'm not looking to fully open a public IP to an inside server, of course I agree...bad idea. I was more looking for a "cleaner" way to NAT multiple necessary ports to an inside box without having to create a separate object per port. If I want a box to have ports 25, 443, 587, and 993 open, it seems very messy to have 4 objects for the same server, and I would rather find some way to say "Object X NATs these 4 ports" instead of Having to create "Object X, 25", "Object X, 443", "Object X, 587", and "Object X, 993".
0
 
LVL 6

Expert Comment

by:insidetech
ID: 39874323
I understand, my comment was in reference to other suggestion.
Yes, you can create a custom service group and have all of your ports in one.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 6

Expert Comment

by:insidetech
ID: 39874352
And, you can also delimitate the ports with a comma.
In your access rules double click on your service and add ports manually separated by comma's.
0
 
LVL 5

Author Comment

by:valheru_m
ID: 39874357
Insidetech,

That works for access rules, but doesn't seem to work for NAT.  I created a custom service group with the ports I wanted, but in the NAT config for the object that group is not an option to select.  It wants a single TCP/UDP port and seems like nothing else.
0
 
LVL 6

Expert Comment

by:insidetech
ID: 39874365
Grrrrr.... forget what I said.
In NAT you can do only 1:1 port mapping. I had a senior moment thinking about Access rules.
0
 
LVL 6

Expert Comment

by:insidetech
ID: 39874400
For what it is worth....
If you ever want to upgrade to a much better and smarter FW, get Palo Alto Networks box and you will be able to map port ranges in a single NAT policy.
0
 
LVL 28

Assisted Solution

by:mikebernhardt
mikebernhardt earned 500 total points
ID: 39874549
Again, you can set up a static NAT if you have the IP available. This doesn't mean that you just let everyone through, but that's a security issue, not a NAT issue. The 2 should not be considered interchangeable. You need to have firewall rules or access list to limit what ports are actually available.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now