Solved

Forward Port 80 in ASA 5512

Posted on 2014-12-10
4
74 Views
Last Modified: 2015-10-12
Hello,

I am having trouble forwarding a port in our ASA 5512.  As far as I know, everything is setup correctly, but I cannot access our internal webserver via our external IP.  I can however access the webserver using it's internal IP, so I know the website is available.

ASA 5512
ASA version: 8.6(1)2
ASDM version: 7.3(1)101

I have an ACL entry for the webserver: Following line is from the SHOW RUNNING-CONFIG cmd...  "Ajera" is the webserver object:
access-list Outside_access_in extended permit tcp any object Ajera object-group DM_INLINE_TCP_1

I also have a NAT entry for the Webserver object: via the SHOW RUNNING-CONFIG cmd...
object network Ajera
 nat (Inside,Outside) static interface service tcp www www

The above were configured via the ASDM.  I also ran the packet trace tool and it PASSED all the way from the External Interface to the Webserver's internal IP.  There is no firewall active on the webserver.

Any suggestions?
0
Comment
Question by:CKilmer1975
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 40494750
Is the Ajera object the private ip address of the webserver?
Is the webserver default gateway the inside ip of the asa?
0
 

Author Comment

by:CKilmer1975
ID: 40500949
Hi,

Yes, the Ajera object is the private IP address of the server, and yes the webserver's default gateway is the inside IP of the asa.

I was actually able to get this figured out, for port 80 at least.  I'm not sure what was causing the issue as my above configuration worked.

However, my current problem is I need to forward port 443 (ssl) so the site can be accessed via HTTPS.  The ASA will not allow me to do so.  It keeps telling me "NAT unable to reserve ports".  I've already changed the ASDM mgmt to use a port other than 443.  I also changed WebVPN to use a different port for SSL, so I cannot see why the ASA won't allow me to forward port 443.
0
 

Accepted Solution

by:
CKilmer1975 earned 0 total points
ID: 41029218
This was solved on my own.  I had to change the port that the Cisco ASA used for it's internal SSL use from 443 to something else before I could forward 443 for my website.
0
 

Author Closing Comment

by:CKilmer1975
ID: 41035600
No one else had any solutions.  I eventually resolved the issue on my own.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question