<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot open RDP port on FPR1120 from FDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797593#M1098797</link>
    <description>&lt;P&gt;creat two ACL. the one you already define outside to inside the other ACL you have to define Inside to outside and test again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you also share your nat rules please. when you do packet tracer you using outside IP address?&lt;/P&gt;</description>
    <pubDate>Mon, 20 Mar 2023 09:51:05 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2023-03-20T09:51:05Z</dc:date>
    <item>
      <title>Cannot open RDP port on FPR1120 from FDM</title>
      <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797517#M1098796</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;My client wants to open remote desktop port 3389 on the fpr1120.&lt;/P&gt;
&lt;P&gt;I created static nat with port forward from outside to inside to forward incoming request on port 1616 to ip 192.168.**.** on port 3389 windows RDP&amp;nbsp;and an acl to allow the connection from outside.&lt;/P&gt;
&lt;P&gt;Configuration are below.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i do packet tracer connection i being drop by acl.&lt;/P&gt;
&lt;P&gt;I cant figure out the problem.&lt;/P&gt;
&lt;P&gt;Any help is appreciated.&lt;/P&gt;
&lt;P&gt;*********NAT****&lt;BR /&gt;Flags: D - DNS, e - extended, I - identity, i - dynamic, r - portmap,&lt;BR /&gt;s - static, T - twice, N - net-to-ne&lt;BR /&gt;&lt;BR /&gt;TCP PAT from outside:0.0.0.0/0 1616-1616 to ether2:192.168.**.** 3389-3389&lt;BR /&gt;flags srT idle 0:01:07 timeout 0:00:00&lt;/P&gt;
&lt;P&gt;*ether2 port is part of bridge interface*&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;*****ACL*******&lt;/P&gt;
&lt;P&gt;Action : Allow&lt;BR /&gt;Intrusion Policy : Source ISE Metadata :Source Zones : outside_zone&lt;BR /&gt;Destination Zones : inside_zone&lt;BR /&gt;Destination Networks : juli_pc (192.168.**.**)&lt;BR /&gt;Source Ports : 1616 (protocol 6, port 1616)&lt;BR /&gt;Destination Ports : 3389 (protocol 6, port 3389)&lt;BR /&gt;Users&lt;BR /&gt;URLs&lt;BR /&gt;Logging Configuration &lt;BR /&gt;DC : Enabled&lt;BR /&gt;Beginning : Enabled&lt;BR /&gt;End : Enabled&lt;BR /&gt;Files : Enabled&lt;BR /&gt;Safe Search : No&lt;BR /&gt;Rule Hits : 0&lt;BR /&gt;File Policy : Block Malware All&lt;BR /&gt;Variable Set : Default-Set&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;***************&lt;BR /&gt;&amp;gt; packet-tracer input outside icmp 80.90.**.** 8 0 192.168.**.**&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: No ECMP load balancing&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Destination is locally connected. No ECMP load balancing.&lt;BR /&gt;Found next-hop 192.168.**.** using egress ifc inside(vrfid:0)&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside(vrfid:0)&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x00005651f5cc91fa flow (NA)/NA&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 08:30:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797517#M1098796</guid>
      <dc:creator>Rigels002</dc:creator>
      <dc:date>2023-03-20T08:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot open RDP port on FPR1120 from FDM</title>
      <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797593#M1098797</link>
      <description>&lt;P&gt;creat two ACL. the one you already define outside to inside the other ACL you have to define Inside to outside and test again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you also share your nat rules please. when you do packet tracer you using outside IP address?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 09:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797593#M1098797</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2023-03-20T09:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot open RDP port on FPR1120 from FDM</title>
      <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797642#M1098798</link>
      <description>&lt;P&gt;i did that but still not working.&lt;/P&gt;
&lt;P&gt;i need only to for remote host&amp;nbsp;port 1616 to connect via remote desktop on port 3389.&lt;/P&gt;
&lt;P&gt;Static manual nat is bidirectional so should work both directions.&lt;/P&gt;
&lt;P&gt;dont understand why cant figure it out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 10:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797642#M1098798</guid>
      <dc:creator>Rigels002</dc:creator>
      <dc:date>2023-03-20T10:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot open RDP port on FPR1120 from FDM</title>
      <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797647#M1098799</link>
      <description />
      <pubDate>Mon, 20 Mar 2023 10:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797647#M1098799</guid>
      <dc:creator>Rigels002</dc:creator>
      <dc:date>2023-03-20T10:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot open RDP port on FPR1120 from FDM</title>
      <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797658#M1098800</link>
      <description>&lt;P&gt;do packet-trace please&lt;/P&gt;
&lt;P&gt;packet-tracer interface outside tcp 8.8.8.8 1234 X.X.X.X 3389&lt;/P&gt;
&lt;P&gt;x.x.x.x is your FTD outside ip address (are you using public ip or Private IP address?)&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 10:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797658#M1098800</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2023-03-20T10:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot open RDP port on FPR1120 from FDM</title>
      <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797796#M1098806</link>
      <description>&lt;P&gt;yes,&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;x.x.x.x is my FTD outside ip address.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;i fixed it, tried everything but just had to change the placement of the NAT -&amp;nbsp; above a specific rule - above inside_outside dynamic nat rule.&lt;/P&gt;
&lt;P&gt;Static nat should be place above dynamic nat.&lt;/P&gt;
&lt;P&gt;i was able to get hits on acl and connect via rdp.&lt;/P&gt;
&lt;P&gt;Attached pics&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 11:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797796#M1098806</guid>
      <dc:creator>Rigels002</dc:creator>
      <dc:date>2023-03-20T11:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot open RDP port on FPR1120 from FDM</title>
      <link>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797801#M1098807</link>
      <description>&lt;P&gt;That correct you have to place the static nat rule on top if you have configured a dynmaic rule.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 11:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-open-rdp-port-on-fpr1120-from-fdm/m-p/4797801#M1098807</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2023-03-20T11:42:50Z</dc:date>
    </item>
  </channel>
</rss>

