<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inbound NAT on FDM help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352140#M1123728</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1446300"&gt;@Ash Roberts&lt;/a&gt;&amp;nbsp;the source and destination port of the original/translated packet won't both be tcp/1433. Have a look at the example at the "inbound access" section of &lt;A href="https://integratingit.wordpress.com/2020/02/08/ftd-configuration-using-fdm/" target="_self"&gt;this post&lt;/A&gt;. If you still have a problem, please run packet-tracer from the CLI and provide the output.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Dec 2025 18:47:18 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2025-12-03T18:47:18Z</dc:date>
    <item>
      <title>Inbound NAT on FDM help</title>
      <link>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352137#M1123727</link>
      <description>&lt;P&gt;Hi all we are trying to allow external access inbound to a SQL server on port 1433. Can't seem to get this to work and i think its clearly my understanding but the NAT rule is as follows:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Outside -&amp;gt; Inside&lt;BR /&gt;Original Packet:&lt;BR /&gt;Source &amp;lt;Public IP&amp;gt;&amp;nbsp; Port 1433&lt;BR /&gt;destination &amp;lt;SQL Server Internal IP&amp;gt; port 1433&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Translated Packet&lt;BR /&gt;Source &amp;lt;Public IP&amp;gt; port 1433&lt;BR /&gt;Destination &amp;lt;SQL Server Internal IP&amp;gt; port 1433&lt;BR /&gt;&lt;BR /&gt;I then have an ACL to allow traffic through. this is not working. Examples of inbound seem limited but ones i am reading are saying NAT the inside to public IP first so it works in other direction also (bi-directional). Then control the flow with the ACL?&lt;/P&gt;
&lt;P&gt;Any help or advice on theory would be great thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 18:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352137#M1123727</guid>
      <dc:creator>Ash Roberts</dc:creator>
      <dc:date>2025-12-03T18:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound NAT on FDM help</title>
      <link>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352140#M1123728</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1446300"&gt;@Ash Roberts&lt;/a&gt;&amp;nbsp;the source and destination port of the original/translated packet won't both be tcp/1433. Have a look at the example at the "inbound access" section of &lt;A href="https://integratingit.wordpress.com/2020/02/08/ftd-configuration-using-fdm/" target="_self"&gt;this post&lt;/A&gt;. If you still have a problem, please run packet-tracer from the CLI and provide the output.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 18:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352140#M1123728</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-12-03T18:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound NAT on FDM help</title>
      <link>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352141#M1123729</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thank you finally a decent example!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;If i want to lock this down from a specific public IP do i do this part in the ACL and leave the NAT rule as per the example?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 18:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352141#M1123729</guid>
      <dc:creator>Ash Roberts</dc:creator>
      <dc:date>2025-12-03T18:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound NAT on FDM help</title>
      <link>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352142#M1123730</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1446300"&gt;@Ash Roberts&lt;/a&gt;&amp;nbsp;yes, I would restrict the source in the Access Control (ACL) rule.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 19:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inbound-nat-on-fdm-help/m-p/5352142#M1123730</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-12-03T19:00:06Z</dc:date>
    </item>
  </channel>
</rss>

