<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: open port and forrwarding? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396883#M1080456</link>
    <description>&lt;P&gt;Just to clarify you looking to setup Open VPN Server inside your network need to port-forward outside to inside correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or you looking you Lan user to connect outside Open VPN Server ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the inside your environment as Open VPN Server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per the document, you need to open TCP and UDP both 1194 along with 80 and 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 May 2021 07:08:02 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-05-03T07:08:02Z</dc:date>
    <item>
      <title>open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396853#M1080449</link>
      <description>&lt;P&gt;hello&lt;BR /&gt;Please try to open on me firewall 5506-x the OpenVPN UDP port 1194, but without success.&lt;/P&gt;&lt;P&gt;Define the machine and port, also double check the udp port, no chance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 1 extended permit udp any host 192.168.16.9 eq 1194 (hitcnt=8) 0x998cb704&lt;BR /&gt;access-list outside_access_in line 1 extended permit tcp any host 192.168.16.9 eq https (hitcnt=0) 0xe13c63c8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network OpenVPN-Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 192.168.16.9&lt;BR /&gt;object service OpenVPN-Service-IN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service udp destination eq 1194&lt;BR /&gt;object service OpenVPN-Service-OUT&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service udp source eq 1194&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (inside_6,outside) source static OpenVPN-Server interface service any OpenVPN-Service-OUT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;openvpn Server settings&lt;/P&gt;&lt;P&gt;local 192.168.16.9&lt;BR /&gt;port 1194&lt;BR /&gt;proto udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for any possible update&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Mauri&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 06:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396853#M1080449</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-03T06:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396883#M1080456</link>
      <description>&lt;P&gt;Just to clarify you looking to setup Open VPN Server inside your network need to port-forward outside to inside correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or you looking you Lan user to connect outside Open VPN Server ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the inside your environment as Open VPN Server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per the document, you need to open TCP and UDP both 1194 along with 80 and 443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 07:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396883#M1080456</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-05-03T07:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396895#M1080459</link>
      <description>&lt;P&gt;thanks for your answer!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;yes i will, that all me external Users from (WAN) can connect to me internal (LAN) to connect with running openvpn server.&lt;/P&gt;&lt;P&gt;After read the openvpn document i found the following information, please see the attached picture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i the meantime founding meny near same answers/questions&lt;/P&gt;&lt;P&gt;yes access-list still create, but without success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 07:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396895#M1080459</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-03T07:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396906#M1080461</link>
      <description>&lt;P&gt;After changing the config, can you post the full config?&amp;nbsp; You can use a packet tracer to test it and post the outcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the Logs show when the connection coming in ? are you using ASDM, so you can view the real-time logs when the connection coming to ASA ? what status is this DROP or ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 08:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396906#M1080461</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-05-03T08:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396954#M1080469</link>
      <description>&lt;P&gt;now changing meny settings safe and back, restrart from configuration and restart firewall, but iam not shure it's this the right way.&lt;/P&gt;&lt;P&gt;if checking from any tools, local or online, still the port are closed. thanks for possible help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 11:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4396954#M1080469</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-03T11:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397007#M1080471</link>
      <description>&lt;P&gt;i would by happy for any more information, thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 13:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397007#M1080471</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-03T13:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397394#M1080505</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the interface whith BVI1 have the NameIf "inside"&lt;/P&gt;&lt;P&gt;interface BVI1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why i dont see this here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA(config)# nat (?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; configure mode commands/options:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current available interface(s):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any Global address space&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_1 Name of interface GigabitEthernet1/2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_2 Name of interface GigabitEthernet1/3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_3 Name of interface GigabitEthernet1/4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_4 Name of interface GigabitEthernet1/5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_5 Name of interface GigabitEthernet1/6&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_6 Name of interface GigabitEthernet1/7&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside_7 Name of interface GigabitEthernet1/8&lt;BR /&gt;outside Name of interface GigabitEthernet1/1&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;if reading the on cisco site, everytime mentioned "Inside"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA(config)# nat (inside,outside) static outside&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 07:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397394#M1080505</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-04T07:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397408#M1080506</link>
      <description>&lt;P&gt;On 5506-X BVI interfaces cannot be used for NAT translations, you have to specify the physical interface or go with "any"&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;Rick&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 08:47:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397408#M1080506</guid>
      <dc:creator>rschlayer</dc:creator>
      <dc:date>2021-05-04T08:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397423#M1080508</link>
      <description>&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Define now Inside_5, this is the VPN Server inside me LAN Network TCP-UDP are open Any Any&lt;/P&gt;&lt;P&gt;But no connection will by build!? thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if define the picture you will see &amp;lt;--&amp;gt; ASA &amp;lt;--&amp;gt; and the OpenVPN Server will run, and when i will plug&lt;/P&gt;&lt;P&gt;back to Soho this will also run.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 09:17:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397423#M1080508</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-04T09:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397478#M1080512</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry if I bother you, after check now with packet-tracer command i see "Phase 5" that will by drop,&lt;BR /&gt;its possible here to receive any information?&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: CP-PUNT&lt;BR /&gt;Subtype: l2-selective&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7efc6c2dfcc0, priority=13, domain=punt, deny=false&lt;BR /&gt;hits=295678, user_data=0x7efc68213520, cs_id=0x0, l3_type=0x8&lt;BR /&gt;src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt;dst mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7efc6ca10e30, priority=1, domain=permit, deny=false&lt;BR /&gt;hits=8576488, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;BR /&gt;src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt;dst mac=0000.0000.0000, mask=0100.0000.0000&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: No ECMP load balancing&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Destination is locally connected. No ECMP load balancing.&lt;BR /&gt;Found next-hop 192.168.1.9 using egress ifc inside&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7efc6b7a83e0, priority=0, domain=nat-per-session, deny=false&lt;BR /&gt;hits=753111, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, protocol=6&lt;BR /&gt;src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=any, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7efc6ca12260, priority=0, domain=permit, deny=true&lt;BR /&gt;hits=55455, user_data=0xa, cs_id=0x0, use_real_addr, flags=0x1000, protocol=0&lt;BR /&gt;src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x0000560b7ecd294d flow (NA)/NA&lt;/P&gt;&lt;P&gt;ASA#&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 11:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397478#M1080512</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-04T11:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: open port and forrwarding?</title>
      <link>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397896#M1080526</link>
      <description>&lt;P&gt;iam using both, ADSM and CLI&lt;/P&gt;&lt;P&gt;Phase 5, its drop, but i dont see why. the Log are here, please scroll down.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 06:11:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-port-and-forrwarding/m-p/4397896#M1080526</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-05-05T06:11:40Z</dc:date>
    </item>
  </channel>
</rss>

