<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Port Forwarding ASA 8.6 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3184686#M1066070</link>
    <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with port frowarding to my IP camera from internet. My configuration looks good, but the port forwarding doesn't working from Internet. Config is below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/0.666&lt;BR /&gt;vlan 666&lt;BR /&gt;nameif IPCAM&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.10.7.129 255.255.255.252&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address xxx.175.123.122 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network IPCAM&lt;BR /&gt;host 10.10.7.130&lt;/P&gt;&lt;P&gt;object network IPCAM&lt;BR /&gt;nat (IPCAM,outside) static interface service tcp 8090 8090&lt;BR /&gt;&lt;BR /&gt;access-list gre_allow extended permit tcp any object IPCAM eq 8090&lt;/P&gt;&lt;P&gt;access-group gre_allow in interface outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW# packet-tracer input outside tcp 111.11.50.218 8090 xxx.175.123.122 8090&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in xxx.175.123.122 255.255.255.255 identity&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version of ASA is 8.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can somebody tell me where is my&amp;nbsp;mistake?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:18:36 GMT</pubDate>
    <dc:creator>Viktor S</dc:creator>
    <dc:date>2020-02-21T14:18:36Z</dc:date>
    <item>
      <title>Port Forwarding ASA 8.6</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3184686#M1066070</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with port frowarding to my IP camera from internet. My configuration looks good, but the port forwarding doesn't working from Internet. Config is below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/0.666&lt;BR /&gt;vlan 666&lt;BR /&gt;nameif IPCAM&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.10.7.129 255.255.255.252&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address xxx.175.123.122 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network IPCAM&lt;BR /&gt;host 10.10.7.130&lt;/P&gt;&lt;P&gt;object network IPCAM&lt;BR /&gt;nat (IPCAM,outside) static interface service tcp 8090 8090&lt;BR /&gt;&lt;BR /&gt;access-list gre_allow extended permit tcp any object IPCAM eq 8090&lt;/P&gt;&lt;P&gt;access-group gre_allow in interface outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW# packet-tracer input outside tcp 111.11.50.218 8090 xxx.175.123.122 8090&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in xxx.175.123.122 255.255.255.255 identity&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: NP Identity Ifc&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version of ASA is 8.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can somebody tell me where is my&amp;nbsp;mistake?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3184686#M1066070</guid>
      <dc:creator>Viktor S</dc:creator>
      <dc:date>2020-02-21T14:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding ASA 8.6</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3184701#M1066071</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try to run the packet tracer again but does not use the Firewall IP address.&lt;/P&gt;&lt;P&gt;Try to use Camera IP address.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;packet-tracer input outside tcp 111.11.50.218 8090 &amp;nbsp;10.10.7.130 8090&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 14:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3184701#M1066071</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-09-15T14:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding ASA 8.6</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3184703#M1066072</link>
      <description>&lt;P&gt;Hi Flavio!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, for you reply. When i try to use camera's IP address, i get DROP on NAT with&amp;nbsp;rfp-check:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW1# packe input outside tcp 111.11.50.218 8090 10.10.7.130 8090&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 10.10.7.128 255.255.255.252 IPCAM&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group gre_allow in interface outside&lt;BR /&gt;access-list gre_allow extended permit tcp any host 10.10.7.130 eq 8090&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network IPCAM&lt;BR /&gt;nat (IPCAM,outside) static interface service tcp 8090 8090&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: IPCAM&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 14:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3184703#M1066072</guid>
      <dc:creator>Viktor S</dc:creator>
      <dc:date>2017-09-15T14:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding ASA 8.6</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3188810#M1066074</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The root cause of the problem was in the nat rules. My manual nat blocked my auto nat, so solve the problem is after-auto in the manual nat command.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2017 06:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-8-6/m-p/3188810#M1066074</guid>
      <dc:creator>Viktor S</dc:creator>
      <dc:date>2017-09-25T06:42:07Z</dc:date>
    </item>
  </channel>
</rss>

