<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ttpHi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087311#M133499</link>
    <description>&lt;P&gt;&lt;G class="gr_ gr_100 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="100" data-gr-id="100"&gt;ttpHi&lt;/G&gt;,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you add this NAT and test :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object network obj_192.168.0.3&lt;/P&gt;
&lt;P&gt;host 1&lt;SPAN&gt;92.168.0.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;nat (inside,outside) static interface service &lt;G class="gr_ gr_85 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" id="85" data-gr-id="85"&gt;tcp&lt;/G&gt; &lt;G class="gr_ gr_83 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="83" data-gr-id="83"&gt;http&lt;/G&gt;&amp;nbsp;&lt;G class="gr_ gr_108 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="108" data-gr-id="108"&gt;http&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 05 Aug 2017 08:01:47 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2017-08-05T08:01:47Z</dc:date>
    <item>
      <title>Port forwarding Asa5506</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087306#M133494</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm configuring an Asa5506 and i have a problem with port forwarding.&lt;/P&gt;
&lt;P&gt;My configuration is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;2 internet access &amp;gt; Peplink Balance 20 &lt;EM&gt;(load balancer) &amp;gt;&lt;/EM&gt; Asa5506 &amp;gt; lan networks&lt;/LI&gt;
&lt;LI&gt;In the peplink, i have setup a dmz for the Asa &lt;EM&gt;(working because i can use ASDM remotely)&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Asa Outside: 192.168.2.2 / 29&lt;/LI&gt;
&lt;LI&gt;Asa Inside: 192.168.0.0 /24&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I want to redirect port 80 to the host 192.168.0.3, so i have used these commands:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;access-list outside extended permit tcp any host 192.168.0.3 eq www&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-group outside in interface outside&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;When i try to connect from outside, i got this error in the ASA log:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;Aug 05 2017&lt;/TD&gt;
&lt;TD&gt;08:55:22&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;my remote ip&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;56141&lt;/TD&gt;
&lt;TD&gt;192.168.12.2&lt;/TD&gt;
&lt;TD&gt;80&lt;/TD&gt;
&lt;TD&gt;TCP access denied by ACL from my remote ip/56141 to outside:192.168.12.2/80&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Can you help me to solve it?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087306#M133494</guid>
      <dc:creator>Julien Paleni</dc:creator>
      <dc:date>2019-03-12T09:46:52Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087307#M133495</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please share the packet tracer output&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input outside &lt;G class="gr_ gr_52 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="52" data-gr-id="52"&gt;tcp&lt;/G&gt;&amp;nbsp;4.2.2.2 7676 &amp;lt;mapped ip&amp;gt; 80 det&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What is the IP&amp;nbsp;&lt;SPAN&gt;192.168.12.2/80?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 07:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087307#M133495</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-05T07:27:23Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya, </title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087308#M133496</link>
      <description>&lt;P&gt;Hi Aditya,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the result of:&amp;nbsp;packet-tracer input outside tcp 4.2.2.2 7676 my_remote_ip&amp;nbsp;80 det&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in id=0x7f2cb8d17950, priority=1, domain=permit, deny=false&lt;BR /&gt; hits=19263822, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;BR /&gt; src mac=0000.0000.0000, mask=0000.0000.0000&lt;BR /&gt; dst mac=0000.0000.0000, mask=0100.0000.0000&lt;BR /&gt; input_ifc=outside, output_ifc=any&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 192.168.12.1 using egress ifc outside&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in id=0x7f2cba69d620, priority=11, domain=permit, deny=true&lt;BR /&gt; hits=0, user_data=0x6, cs_id=0x0, use_real_addr, flags=0x0, protocol=0&lt;BR /&gt; src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt; input_ifc=outside, output_ifc=any&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;192.168.12.2 is the ip of the ASA outside interface.&lt;/P&gt;
&lt;P&gt;I have attached to this post a schematic of the network.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 07:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087308#M133496</guid>
      <dc:creator>Julien Paleni</dc:creator>
      <dc:date>2017-08-05T07:43:49Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087309#M133497</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I checked this:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;i&lt;STRONG&gt;nput-interface: outside&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;input-status: up&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;input-line-status: up&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;output-interface: outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Why is it taking this path?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you share the NAT statement for this traffic?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 07:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087309#M133497</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-05T07:46:21Z</dc:date>
    </item>
    <item>
      <title>This is the result of "show</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087310#M133498</link>
      <description>&lt;P&gt;This is the NAT Statement which DROP the packet.&lt;/P&gt;
&lt;P&gt;obj_any1 is 0.0.0.0/0.0.0.0&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;object network obj_any1&lt;BR /&gt; nat (any,outside) dynamic interface&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Show nat results&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (any) to (outside) source dynamic obj_any1 interface &lt;BR /&gt; translate_hits = 30140, untranslate_hits = 692&lt;BR /&gt;2 (inside_3) to (outside) source dynamic obj_any3 interface &lt;BR /&gt; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;3 (inside_4) to (outside) source dynamic obj_any4 interface &lt;BR /&gt; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;4 (inside_5) to (outside) source dynamic obj_any5 interface &lt;BR /&gt; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;5 (inside_6) to (outside) source dynamic obj_any6 interface &lt;BR /&gt; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;6 (inside_7) to (outside) source dynamic obj_any7 interface &lt;BR /&gt; translate_hits = 5958, untranslate_hits = 1&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 08:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087310#M133498</guid>
      <dc:creator>Julien Paleni</dc:creator>
      <dc:date>2017-08-05T08:00:29Z</dc:date>
    </item>
    <item>
      <title>ttpHi,</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087311#M133499</link>
      <description>&lt;P&gt;&lt;G class="gr_ gr_100 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="100" data-gr-id="100"&gt;ttpHi&lt;/G&gt;,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you add this NAT and test :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object network obj_192.168.0.3&lt;/P&gt;
&lt;P&gt;host 1&lt;SPAN&gt;92.168.0.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;nat (inside,outside) static interface service &lt;G class="gr_ gr_85 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" id="85" data-gr-id="85"&gt;tcp&lt;/G&gt; &lt;G class="gr_ gr_83 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="83" data-gr-id="83"&gt;http&lt;/G&gt;&amp;nbsp;&lt;G class="gr_ gr_108 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="108" data-gr-id="108"&gt;http&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 08:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087311#M133499</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-05T08:01:47Z</dc:date>
    </item>
    <item>
      <title>I got an error with:</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087312#M133500</link>
      <description>&lt;P&gt;I got an error with:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;nat (inside,outside) static interface service tcp http http&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;In attachment a view of the interfaces.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 08:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087312#M133500</guid>
      <dc:creator>Julien Paleni</dc:creator>
      <dc:date>2017-08-05T08:09:28Z</dc:date>
    </item>
    <item>
      <title>Thanks to you Aditya, i solve</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087313#M133501</link>
      <description>&lt;P&gt;Thanks to you Aditya, i solve the problem.&lt;/P&gt;
&lt;P&gt;I have to use:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;object network obj_192.168.0.3&lt;/P&gt;
&lt;P&gt;host 1&lt;SPAN&gt;92.168.0.3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;nat (&lt;STRONG&gt;inside_1&lt;/STRONG&gt;,outside) static interface service tcp http&amp;nbsp;http&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 08:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087313#M133501</guid>
      <dc:creator>Julien Paleni</dc:creator>
      <dc:date>2017-08-05T08:26:40Z</dc:date>
    </item>
    <item>
      <title>Happy to help :)</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087314#M133502</link>
      <description>&lt;P&gt;Happy to help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2017 08:32:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa5506/m-p/3087314#M133502</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-05T08:32:29Z</dc:date>
    </item>
  </channel>
</rss>

