<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA ACL and NAT for RDP through subinterface allow any in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143402#M1114206</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We have a static IP assigned by the ISP, and every time, we get the same static IP on Subinterface via PPPoE&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2024 07:51:14 GMT</pubDate>
    <dc:creator>GoldTipu</dc:creator>
    <dc:date>2024-07-11T07:51:14Z</dc:date>
    <item>
      <title>Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143150#M1114189</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;Need help to create first ACL and NAT for our LAB testing .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have connected my subinterface with internet using PPPoE -&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to create ACL and NAT to allow everyone from internet to connect to the RDP on my inside host through my &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Subinterface_outside&lt;/STRONG&gt; &lt;/FONT&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currenlty we are testing so allow all is fine for me and rest i will configure myself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GoldTipu_0-1720651557085.png" style="width: 857px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223116i1036931CD0BEAF44/image-dimensions/857x317?v=v2" width="857" height="317" role="button" title="GoldTipu_0-1720651557085.png" alt="GoldTipu_0-1720651557085.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Could you please send me the command lines please ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gold&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 23:11:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143150#M1114189</guid>
      <dc:creator>GoldTipu</dc:creator>
      <dc:date>2024-07-10T23:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143176#M1114191</link>
      <description>&lt;P&gt;take a look at this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0001680" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0001680&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 01:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143176#M1114191</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-11T01:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143178#M1114192</link>
      <description>&lt;P&gt;One issue here pppoe interface get IP from SP so it IP is change always&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How outer cleint can know the new IP?&lt;/P&gt;
&lt;P&gt;Ypu need to ask SP to provide one additional public IP and this IP not change and use it for NAT.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 01:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143178#M1114192</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-11T01:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143188#M1114193</link>
      <description>&lt;P&gt;use DDNS to find new ip &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I think its a lab test..&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 01:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143188#M1114193</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-11T01:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143189#M1114194</link>
      <description>&lt;P&gt;I think ASA not support DDNS for &lt;STRONG&gt;pppoe&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 02:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143189#M1114194</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-11T02:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143200#M1114195</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa915/configuration/general/asa-915-general-config/basic-dhcp-ddns.html#task_176A466D16D7497694EEE7F1E01D39CC" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa915/configuration/general/asa-915-general-config/basic-dhcp-ddns.html#task_176A466D16D7497694EEE7F1E01D39CC&lt;/A&gt;&amp;nbsp; It has for a long while&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 02:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143200#M1114195</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-11T02:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143209#M1114196</link>
      <description>&lt;P&gt;If you sure guide him to run ddns in asa&lt;/P&gt;
&lt;P&gt;Goodluck&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 02:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143209#M1114196</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-11T02:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143401#M1114205</link>
      <description>&lt;P&gt;We have a static IP assigned by the ISP, and every time, we get the same static IP on Subinterface via PPPoE&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 07:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143401#M1114205</guid>
      <dc:creator>GoldTipu</dc:creator>
      <dc:date>2024-07-11T07:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143402#M1114206</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have a static IP assigned by the ISP, and every time, we get the same static IP on Subinterface via PPPoE&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 07:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143402#M1114206</guid>
      <dc:creator>GoldTipu</dc:creator>
      <dc:date>2024-07-11T07:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143408#M1114207</link>
      <description>&lt;P&gt;Please try the sample here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0001680" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0001680&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 07:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143408#M1114207</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-11T07:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143698#M1114219</link>
      <description>&lt;P&gt;I have ASDM -&amp;nbsp;&lt;BR /&gt;Can we have either CLI commands or ASDM KB for this please ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 15:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143698#M1114219</guid>
      <dc:creator>GoldTipu</dc:creator>
      <dc:date>2024-07-11T15:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143715#M1114225</link>
      <description>&lt;P&gt;&lt;A href="https://www.packet-forwarding.net/posts/asa-lessons-static-pat/" target="_blank"&gt;https://www.packet-forwarding.net/posts/asa-lessons-static-pat/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check this link' ypu need to config&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Object service for ports&amp;nbsp; and object network for host (real server IP)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then use PAT to interface with using object service'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This allow ypu to use interface and specific port in PAT&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 17:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143715#M1114225</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-11T17:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143824#M1114228</link>
      <description>&lt;P&gt;After spending several hours on it and we are&amp;nbsp; stuck.&lt;/P&gt;&lt;P&gt;Unfortunately, I am unable to connect remotely (RDP) from outside, and I cannot see any traffic being terminated from the sub-interface to the inside host.&lt;/P&gt;&lt;P&gt;Point # 1&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand why I'm not seeing any hits on the ACL for the outside subinterface for RDP and HTTP,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the NAT ACL&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;5 (inside) to (SubInterface_OutSide) source static inside_host_05 interface service any RDP&lt;BR /&gt;translate_hits = 90, untranslate_hits = 90&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;access-list SubInterface_OutSide_access_in extended permit object RDP any any&lt;BR /&gt;access-list SubInterface_OutSide_access_in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit tcp any any eq www&lt;BR /&gt;access-list outside_acl extended permit icmp any any&lt;BR /&gt;access-list outside_acl extended permit tcp any any eq 3389&lt;BR /&gt;access-list outside_acl extended deny ip any any&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GoldTipu_0-1720730527164.png" style="width: 906px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223276i6D121B80FC6468BF/image-dimensions/906x179?v=v2" width="906" height="179" role="button" title="GoldTipu_0-1720730527164.png" alt="GoldTipu_0-1720730527164.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GoldTipu_2-1720731123494.png" style="width: 633px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223278i7A9262DAAB6117CF/image-dimensions/633x554?v=v2" width="633" height="554" role="button" title="GoldTipu_2-1720731123494.png" alt="GoldTipu_2-1720731123494.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;NAT&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GoldTipu_1-1720730696459.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223277i6C61427075EB408C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="GoldTipu_1-1720730696459.png" alt="GoldTipu_1-1720730696459.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Could you please guide me if i am doing something wrong ? we need assistance to get this resolved as we are unable to access inside network .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Gold&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 21:01:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143824#M1114228</guid>
      <dc:creator>GoldTipu</dc:creator>
      <dc:date>2024-07-11T21:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143826#M1114229</link>
      <description>&lt;P&gt;&lt;SPAN&gt;5 (inside) to (SubInterface_OutSide) source static inside_host_05 interface service &lt;STRONG&gt;RDP&lt;/STRONG&gt; RDP&amp;lt;&amp;lt;- this must be RDP RDP&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list SubInterface_OutSide_access_in extended permit object RDP any any &amp;lt;&amp;lt;- how you config object RDP which you use in ACL?&lt;BR /&gt;this need to be&amp;nbsp;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;access-list SubInterface_OutSide_access_in extended permit tcp any any eq rdp&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 21:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5143826#M1114229</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-11T21:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA ACL and NAT for RDP through subinterface allow any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5144375#M1114252</link>
      <description>&lt;P&gt;This worked for me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;object service RDP&lt;BR /&gt;service tcp destination eq 3389&lt;BR /&gt;description RDP-Service&lt;BR /&gt;object service RDP-Service&lt;BR /&gt;service tcp source eq 3389&lt;BR /&gt;nat (inside,SubInterface_OutSide) source static inside_host_05 interface service RDP RDP-Service&lt;BR /&gt;access-list SubInterface_OutSide_access_in extended permit object RDP any any&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Able to RDP now .&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; So much for helping me .&amp;nbsp;&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 21:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-and-nat-for-rdp-through-subinterface-allow-any/m-p/5144375#M1114252</guid>
      <dc:creator>GoldTipu</dc:creator>
      <dc:date>2024-07-12T21:17:13Z</dc:date>
    </item>
  </channel>
</rss>

