Solved

Need help allowing traffic through on an ASA 5510 to TCP ports that are not preconfigured

Posted on 2014-10-01
2
384 Views
Last Modified: 2014-10-23
Hello.  I do not see how to add new TCP ports that are not on the preconfigured list, to an ASA 5510, via ASDM.  I need to allow traffic through to a specific IP on ports 8000, and 10554.  I see there's an ADD function, but am not sure how to fill that screen in for these.  Looking for some guidance.  Thanks
0
Comment
Question by:Damian_Gardner
2 Comments
 
LVL 32

Accepted Solution

by:
aleghart earned 500 total points
ID: 40356288

Configuration > Firewall > Objects > Service Objects/Groups


Add > IP Service Object

Name:  Project_ABC_8000 (can't use spaces)
Service Type: tcp (usually for applications...or udp,..you should know).
Destination Port Range: 8000
Source Port Range: (default/blank)
Description: port 8000 for Project ABC http (or whatever protocol it is)

Add > IP Service Object

Name:  Project_ABC_10554
Service Type: tcp
Destination Port Range: 10554
Source Port Range: (default/blank)
Description: port 10554 for Project ABC management (or whatever protocol it is)

Hit the [Apply] button.  These new service objects will not exist until you hit [Apply].  This is the number one mistake with custom services.

Add > IP Service Group

Group Name: Project_ABC_service_group
Description: custom ports for Project ABC

Choose your two new service objects and move them to the right side (Members in Group) with the [Add>>] button.
Choose pre-defined 'ICMP 4 echo' and [Add>>].  This will let you ping the target during troubleshooting.  You can always remove it later.
[OK]
[Apply]

Choose any one of these methods to save:
Hit the floppy-disk icon.
File > Save Running Configuration to Flash.
Hit Control-S.

Now, you only need to reference this service group.  You can stack up dozens of pre-defined or custom services.  You can also nest other service groups inside of a service group.

So, if you have a group made for HTTP(s) services, and another for FTP(s) services, and a third for custom HTTP ports...you can create a service group called "Project_XYZ_public_services" that includes those other groups...plus ICMP 4 echo for ping.
0
 

Author Comment

by:Damian_Gardner
ID: 40357100
Aleghart - thanks for your help.  I will try this.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Load Balancing 3 28
Cisco switch suggestion 5 42
Help with inter-vlan routing on a Cisco SG500. 12 25
ASA 5505 not passing traffic to Netgear router 22 26
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now