Enabling access rules

Dear Experts,

I am at a client location today and they have a local server that will be accessing different sites with various ports. The client has ASA firewall and Cisco Firepower my question is do I add the access rules in Firepower or directly in ASA?

I am always not sure and the client has no preference.

Please let me know from your experience how to tackle this .

Thanks,
LVL 5
SR ZakNetwork Solutions Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Pete LongTechnical ConsultantCommented:
If its running ASA code (ie it has a command line, and an ASDM) then you do it on the ASA, if its running FTD code (eeurgh!) then you do it in the FirePOWER Device Manager Console.

Connecting to and Managing Cisco Firewalls

Or the FTD looks like this


Pete
SR ZakNetwork Solutions Author Commented:
Hi Pete,

I am using ASA with ASDM and Firepower management console, it is not FTD.
Pete LongTechnical ConsultantCommented:
OK, I'm assuming you need to access this from outside the firewall? If you have a 'spare' public IP for it to use, then simply create a 'one to one' NAT - and open the ports you require. OR if you DON'T have a spar public IP, then you will need to 'Port Forward' the ports you want opening, from the outside IP of the firewall to the internal host :)
So
Add a Static (One to One) NAT Translation to a Cisco ASA 5500 Firewall
OR
Cisco Firewall Port Forwarding

Regards,

Pete

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.