Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco ASA NAT rules for different port forwarding

Posted on 2016-08-30
3
Medium Priority
?
106 Views
Last Modified: 2016-10-03
We're running two servers behind a Cisco ASA which need their IIS services published. As there's only one public IP address, one of the two IIS servers needs to be reachable on outside port 444. - In other words:
1.2.3.4:443 (outside) --> 192.168.1.10:443 (inside)
1.2.3.4:444 (outside) --> 192.168.1.11:443 (inside)

What are the right NAT rules?
0
Comment
Question by:zolcer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 14

Accepted Solution

by:
SIM50 earned 2000 total points
ID: 41776718
Depends on ASA version.
8.2
static (inside,outside) tcp interface 443 192.168.1.10 443 netmask 255.255.255.255
static (inside,outside) tcp interface 444 192.168.1.11 443 netmask 255.255.255.255

8.3+
object network obj-192.168.1.10
host 192.168.1.10
nat (inside,outside) static interface service tcp 443 443

object network obj-192.168.1.11
host 192.168.1.11
nat (inside,outside) static interface service tcp 443 444

To verify: sh xlate detail
0
 
LVL 3

Author Closing Comment

by:zolcer
ID: 41776775
... exactly. Thanks!
0
 

Expert Comment

by:discuss120 discuss120
ID: 41826132
Hey,I am working within a network with DMZ and ASA Firewall with which I would like to change anyconnect VPN such that the user with AD credentials can access the servers without first logging in the DNS.Could you advise how I may do within my Firewall?
Thanks!!
0

Featured Post

Will your db performance match your db growth?

In Percona’s white paper “Performance at Scale: Keeping Your Database on Its Toes,” we take a high-level approach to what you need to think about when planning for database scalability.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Suggested Courses

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question