• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 75
  • Last Modified:

Cisco ASA 5506

I have about 60 public ip's. How can I forward a port on an ASA using a different ip other than my public?

If my public is 172.16.1.25....this is also the ip assigned to my outside interface. I would like to have 172.16.1.26 forwarded to a server on my network.

Any ideas
0
Dawin Daise
Asked:
Dawin Daise
  • 2
  • 2
1 Solution
 
Jan SpringerCommented:
Port forwarding tcp 25 (smtp):

NAT:

object network SERVER
 host 192.168.1.26
 nat (inside,outside) static 172.16.1.26


PORT FORWARD:

object network SERVER-SMTP
 host 192.168.1.26
 nat (inside,outside) static 172.16.1.26 tcp smtp smtp
0
 
Dawin DaiseSr. Windows Systems AdministratorAuthor Commented:
Do I need an ACL?
0
 
Jan SpringerCommented:
Yes, on the outside interface for any traffic permitted to that IP and port.

If you're using 8.3 and later (which you probably are with a 5506), then you refer to the object that has the inside IP address defined in your outside access list:

access-list outside extended permit tcp any object SERVER-SMTP eq 25
access group outside in interface outside
0
 
Dawin DaiseSr. Windows Systems AdministratorAuthor Commented:
Thanks for all of your help.
0

Featured Post

Managing Security & Risk at the Speed of Business

Gartner Research VP, Neil McDonald & AlgoSec CTO, Prof. Avishai Wool, discuss the business-driven approach to automated security policy management, its benefits and how to align security policy management with business processes to address today's security challenges.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now