<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I am wondering if you need  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884820#M157341</link>
    <description>&lt;P&gt;I am wondering if you need "no-proxy-arp" in your nat statements&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;!
object network SERVER-41-RDP
 nat (DMZ,outside) static 17x.x.xx.XX &amp;nbsp;&lt;STRONG&gt;no-proxy-arp&lt;/STRONG&gt; service tcp 3389 7900 
object network SERVER-41-HTTP
 nat (DMZ,outside) static 17x.x.xx.xx &amp;nbsp;&lt;STRONG&gt;no-proxy-arp&lt;/STRONG&gt; service tcp www www 
object network SERVER-41-HTTPS
 nat (DMZ,outside) static 17x.x.xx.xx &amp;nbsp;&lt;STRONG&gt;no-proxy-arp&lt;/STRONG&gt; service tcp https https
! &lt;/PRE&gt;</description>
    <pubDate>Thu, 23 Jun 2016 07:18:35 GMT</pubDate>
    <dc:creator>Richard Bradfield</dc:creator>
    <dc:date>2016-06-23T07:18:35Z</dc:date>
    <item>
      <title>Cisco ASA 5515: Outside RDP to Server in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884817#M157338</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have a Cisco ASA 5515 configured and in production today. We recently just added a DMZ and we have one server and a WLAN controller for guest Wifi internet access.&amp;nbsp; Internet access from the server and guest wifi is up and working.&lt;/P&gt;
&lt;P&gt;There is a need to allow RDP temporarily on the server and I have configured the ASA and cannot seem to get this to work. We have configured port forwarding before, so pretty familiar with the configuration. But I may be missing something here in the configurations on the ASA for the DMZ.&lt;/P&gt;
&lt;P&gt;See attached pertinent configuration. I would think all this is right, but when i run a packet tracer I get this:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;FLDC-VPN# packet-tracer input outside tcp 8.8.8.8 65000 17x.x.xx.xx 3389 det$&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 17x.x.xx.xx using egress ifc&amp;nbsp; outside&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (nat-no-xlate-to-pat-pool) Connection to PAT address without pre-existing xlate&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I would appreciate any help in isolating this issue and let me know if I missed something in the configuration that needs to be verified.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Again, this is a production device and everything is working in the but the RDP from outside at the moment.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Brandon&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884817#M157338</guid>
      <dc:creator>nsateam01</dc:creator>
      <dc:date>2019-03-12T07:55:47Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884818#M157339</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Not sure what is the ASA version but can you check match the following bug symptoms:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuc28796/?reffering_site=dumpcr&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 00:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884818#M157339</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-22T00:25:18Z</dc:date>
    </item>
    <item>
      <title>Hello Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884819#M157340</link>
      <description>&lt;P&gt;Hello Aditya,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for the info. It looks like this bug does not apply as we have upgraded to 9.4 in our ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-Brandon&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 15:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884819#M157340</guid>
      <dc:creator>nsateam01</dc:creator>
      <dc:date>2016-06-22T15:04:33Z</dc:date>
    </item>
    <item>
      <title>I am wondering if you need</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884820#M157341</link>
      <description>&lt;P&gt;I am wondering if you need "no-proxy-arp" in your nat statements&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;!
object network SERVER-41-RDP
 nat (DMZ,outside) static 17x.x.xx.XX &amp;nbsp;&lt;STRONG&gt;no-proxy-arp&lt;/STRONG&gt; service tcp 3389 7900 
object network SERVER-41-HTTP
 nat (DMZ,outside) static 17x.x.xx.xx &amp;nbsp;&lt;STRONG&gt;no-proxy-arp&lt;/STRONG&gt; service tcp www www 
object network SERVER-41-HTTPS
 nat (DMZ,outside) static 17x.x.xx.xx &amp;nbsp;&lt;STRONG&gt;no-proxy-arp&lt;/STRONG&gt; service tcp https https
! &lt;/PRE&gt;</description>
      <pubDate>Thu, 23 Jun 2016 07:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884820#M157341</guid>
      <dc:creator>Richard Bradfield</dc:creator>
      <dc:date>2016-06-23T07:18:35Z</dc:date>
    </item>
    <item>
      <title>I had this same issue. The</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884821#M157342</link>
      <description>&lt;P&gt;I had this same issue. The problem was 2 different mapped IP addresses for the same inside host.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: terminal,monaco,monospace;"&gt;Internet &amp;lt;-&amp;gt; 1.1.1.1:25 &amp;lt;-&amp;gt; inside 10.10.10.10 port 25&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: terminal,monaco,monospace;"&gt;Internet &amp;lt;-&amp;gt; 1.1.1.2:80 &amp;lt;-&amp;gt; inside 10.10.10.10 port 80&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: terminal,monaco,monospace;"&gt;Internet &amp;lt;-&amp;gt; 1.1.1.2:443 &amp;lt;-&amp;gt; inside 10.10.10.10 port 443&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: terminal,monaco,monospace;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;object network DMZ_Proxy_SMTP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;host 10.10.10.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;nat (DMZ1,Outside) static 1.1.1.1 service tcp 1025 smtp&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE class="prettyprint" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;object network DMZ_Proxy_HTTP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;host 10.10.10.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;nat (DMZ1,Outside) static 1.1.1.2 service tcp www www&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE class="prettyprint" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;object network DMZ_Proxy_HTTPS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;host 10.10.10.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;nat (DMZ1,Outside) static 1.1.1.2 service tcp https https&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;PRE class="prettyprint" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;nat (Inside,Outside) after-auto source dynamic REAL_IP Public_IP_1.1.1.2&lt;BR /&gt;nat (any,Outside) after-auto source dynamic any interface&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;The first static worked as expected. The reason being the bi-directional operation of the static NAT. The second, because it was a different outside mapped IP was not getting NAT'd to the same IP going out. That is where the statement :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;nat (Inside,Outside) after-auto source dynamic REAL_IP Public_IP_1.1.1.2&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;comes in. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 16:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884821#M157342</guid>
      <dc:creator>jdsmith999</dc:creator>
      <dc:date>2016-06-23T16:04:02Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884822#M157343</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Apologies as I missed this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you try using a manual NAT statement on line 1 and test this connection:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (dmZ,out) 1 source static SERVER-41 SERVER-NAT service obj-3389 obj-7900 route-lookup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 17:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5515-outside-rdp-to-server-in-dmz/m-p/2884822#M157343</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-06-23T17:05:58Z</dc:date>
    </item>
  </channel>
</rss>

