Link to home
Start Free TrialLog in
Avatar of Greg V
Greg VFlag for United States of America

asked on

Cisco port forwarding

I have a customer that needed ports 990 and 22 open in a Cisco ASA5505 to a computer on their network. I have input the info in Access Rules and NAT but still cannot get in. Here is the config for the ASA
Config.txt
Avatar of Soulja
Soulja
Flag of United States of America image

I don't see anything that sticks out. Have you insured the actual box is listening on those requested ports?
Avatar of Greg V

ASKER

I scanned from the internet to check the ports and they are showing closed.
I meant the actual internal box. Is it listening on the ports?
Avatar of Greg V

ASKER

Yes, there is a AS400 programmer that is asking for these ports open on the firewall and he has tried to access
Try

no access-list outside_access_in extended permit tcp any object-group SFTP interface outside object-group SFTP
access-list outside_access_in extended permit tcp any interface outside object-group SFTP
clear xlate

Also remember the SFTP software might be running on random ports for response traffic, check with the software vendor.

Pete
Avatar of Greg V

ASKER

I have verified that the box is listening on all needed ports.
I have also made the line changes suggested by Pete Long.
Still can get through on those ports.
Since this is an ASA, I am assuming you are using interface overloading (using the single "outside interface" ip address to NAT to the inside)?

If so, you cannot port forward 22 on the ASA.  As this is a management port, it is reserved on all IP's for the ASA itself (it is stupid, I understand that, but that is the way it works on the ASA).

This is most likely the cause of your issue.  Are you just trying to work on the SSH/SFTP port or are you unable to reach the mail port (990) as well?
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.