Solved

Mapping a public IP and ports to inside address

Posted on 2014-09-12
3
552 Views
Last Modified: 2014-09-14
I have what I think is a simple setup and problem.  I have many internal servers, two of them are Lync and Exchange with private IP addresses on them.  How does one setup the ASA (5512) to allow the communication for two things:
1 some internal private IPs use the same hosts - so the ASA fails when you tell it to forward the same ports?
2 with port forwarding how to handling something like Lync that has about 20,000 ports needed to map to its inside?

Currently I have things like OWA working by forwarding port 443 to the correct private IP.  Obviously this a busy port and a issue.  In some places you can reassign HTTPS to another port but there has got to be a better way.

much appreciate of any help/guidance....
0
Comment
Question by:EckoForce_1
  • 2
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 40321218
Youre going to need more than 1 public ip address and do static 1-1 nat for lync and anything else that needs same port
Ike 443
0
 

Author Comment

by:EckoForce_1
ID: 40322199
I was hoping there was a better way.....so I cant have overlapping IPs on my ASA via interfaces, subinterfaces or contexts.....so how do I setup all these public IPs (which I do have).  Create static routes on the upstream router to point many public addresses to one?  My other options is getting a ASA-5505 for each IP - but that seems wasteful.
0
 

Author Comment

by:EckoForce_1
ID: 40322234
thanks for the guidance - I am going to use static NATs  - 1 public to 1 private and then allow my ports with ACLs....much easier that trying to port map!
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
fabric 1 31
Stuck in INIT/DROTHER 2 49
how to determine subnet mask? 11 38
HP 1920 Switch -- IFNET LINK_UPDOWN Errors 3 11
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question