<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA access list problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-access-list-problem/m-p/3197776#M1065548</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to allow access for the NATTed object, it would work. Hence the mapped port is not required. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list outside_in extended permit tcp any object&amp;nbsp;outside-in-192-168-3-106 eq 3389&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Oct 2017 15:05:45 GMT</pubDate>
    <dc:creator>Kias</dc:creator>
    <dc:date>2017-10-12T15:05:45Z</dc:date>
    <item>
      <title>ASA access list problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-problem/m-p/3197695#M1065546</link>
      <description>&lt;P&gt;Hello, I have the following config on an ASA 5520 Version 9.1(7)4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network outside-in-192-168-3-106&lt;BR /&gt; host 192.168.3.106&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network outside-in-192-168-3-106&lt;BR /&gt; nat (inside2,outside) static a.b.c.d service tcp 3389 59106&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list outside_in extended permit tcp any eq 59106 host 192.168.3.106 eq 3389&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want an external user to be able to RDP to a.b.c.d port 59106 and this traffic to arrive at 192.168.3.106 port 3389&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can only get it to work if I add the access list:&lt;/P&gt;
&lt;P&gt;access-list outside_in extended permit ip any host 192.168.3.106&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What am I doing wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks, Simon&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-problem/m-p/3197695#M1065546</guid>
      <dc:creator>simon-chamberlain</dc:creator>
      <dc:date>2020-02-21T14:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA access list problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-problem/m-p/3197776#M1065548</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to allow access for the NATTed object, it would work. Hence the mapped port is not required. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list outside_in extended permit tcp any object&amp;nbsp;outside-in-192-168-3-106 eq 3389&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 15:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-problem/m-p/3197776#M1065548</guid>
      <dc:creator>Kias</dc:creator>
      <dc:date>2017-10-12T15:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA access list problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-access-list-problem/m-p/3197870#M1065552</link>
      <description>&lt;P&gt;Thanks Kias. It works!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 17:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-access-list-problem/m-p/3197870#M1065552</guid>
      <dc:creator>simon-chamberlain</dc:creator>
      <dc:date>2017-10-12T17:09:51Z</dc:date>
    </item>
  </channel>
</rss>

