<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS FW inbound static PAT range possible? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-fw-inbound-static-pat-range-possible/m-p/3734561#M1049661</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes on asa this is possible.&lt;/P&gt;
&lt;P&gt;Let's assume your outside name is outside and acl attached to it called outside_access_in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here a config sample (sorry if there are some typos, I'm writing this down from my smartphone):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object service PABX-UDP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;service udp destination range 50000&amp;nbsp;51000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network PABX&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;host 192.168.0.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list outside_access_in extended permit object PABX-UDP any object-group PABX&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (inside,outside) source static PABX 1.1.1.1 service PABX-UDP PABX-UDP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;==&amp;gt; Replace 1.1.1.1 by your public ip or your object containing the public ip.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Afterwards, everything should work. Be sure to put the nat at the right place to not have something overlapping.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do a test and let me know.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;[EDIT]&lt;/P&gt;
&lt;P&gt;I saw in the title you were talking about udp range on ios.&lt;/P&gt;
&lt;P&gt;You can use route-map or an easier one like below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip nat pool PABX-UDP&amp;nbsp;192.168.0.50 192.168.0.10 netmask 255.255.255.0 type rotary&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list 111 permit udp any any range 50000 51000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip nat inside destination list 111 pool&amp;nbsp;PABX-UDP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You need to adapt with your actual config of any other Nat exists.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here an example with route-map:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/routing/forward-range-ports-for-few-hosts-in-isr4331/td-p/3316899" target="_blank"&gt;https://community.cisco.com/t5/routing/forward-range-ports-for-few-hosts-in-isr4331/td-p/3316899&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Oct 2018 02:23:59 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2018-10-29T02:23:59Z</dc:date>
    <item>
      <title>IOS FW inbound static PAT range possible?</title>
      <link>https://community.cisco.com/t5/network-security/ios-fw-inbound-static-pat-range-possible/m-p/3734535#M1049642</link>
      <description>&lt;P&gt;Hi I have to create connectivity for an external phone system say port 50000-51000 UDP from outside to a single host inside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to map the whole UDP port range&amp;nbsp; range from outside (hitting the external interface) to inside (pabx host 192.168.10.10) keeping udp dest ports consistent eg dest port 50000&amp;nbsp; coming in to external ios fw interface&amp;nbsp; to PAT to 192.168.10.10 dest port udp 50000&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without having to do each individual PAT statement or get a separate public IP address, is this possible?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-fw-inbound-static-pat-range-possible/m-p/3734535#M1049642</guid>
      <dc:creator>dino55088</dc:creator>
      <dc:date>2020-02-21T16:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: IOS FW inbound static PAT range possible?</title>
      <link>https://community.cisco.com/t5/network-security/ios-fw-inbound-static-pat-range-possible/m-p/3734561#M1049661</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes on asa this is possible.&lt;/P&gt;
&lt;P&gt;Let's assume your outside name is outside and acl attached to it called outside_access_in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here a config sample (sorry if there are some typos, I'm writing this down from my smartphone):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object service PABX-UDP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;service udp destination range 50000&amp;nbsp;51000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network PABX&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;host 192.168.0.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list outside_access_in extended permit object PABX-UDP any object-group PABX&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (inside,outside) source static PABX 1.1.1.1 service PABX-UDP PABX-UDP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;==&amp;gt; Replace 1.1.1.1 by your public ip or your object containing the public ip.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Afterwards, everything should work. Be sure to put the nat at the right place to not have something overlapping.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do a test and let me know.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;[EDIT]&lt;/P&gt;
&lt;P&gt;I saw in the title you were talking about udp range on ios.&lt;/P&gt;
&lt;P&gt;You can use route-map or an easier one like below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip nat pool PABX-UDP&amp;nbsp;192.168.0.50 192.168.0.10 netmask 255.255.255.0 type rotary&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list 111 permit udp any any range 50000 51000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip nat inside destination list 111 pool&amp;nbsp;PABX-UDP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You need to adapt with your actual config of any other Nat exists.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here an example with route-map:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/routing/forward-range-ports-for-few-hosts-in-isr4331/td-p/3316899" target="_blank"&gt;https://community.cisco.com/t5/routing/forward-range-ports-for-few-hosts-in-isr4331/td-p/3316899&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 02:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-fw-inbound-static-pat-range-possible/m-p/3734561#M1049661</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-10-29T02:23:59Z</dc:date>
    </item>
  </channel>
</rss>

