<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 SQL Ports in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893465#M167617</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My company is currently running a Cisco ASA 5510. &amp;nbsp;We have been told by our 3rd party point of sale vendor that they are having issues syncing their database and server because they need TCP port 1433 &amp;amp; UDP port 1434 opened on the firewall. &amp;nbsp;I have been staring at this for a few days now - I have attempted to create Access Rules to open those ports but it doesn't seem to change anything. &amp;nbsp;I apologize in advance, as I am a novice with these firewalls.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The server and machines attempting to sync up are all on the same domain, so I thought my access rules should be "Inside". &amp;nbsp;I have tried multiple variations of setups, including having incoming and outgoing rules and using "any" for both IP Addresses and ports. &amp;nbsp;I have reloaded the device after each change to make sure it was current, but nothing seems to fix the issue. &amp;nbsp;I understand the device is old and outdated, but they can't afford to upgrade anytime soon.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:27:25 GMT</pubDate>
    <dc:creator>j_patykow</dc:creator>
    <dc:date>2019-03-12T07:27:25Z</dc:date>
    <item>
      <title>ASA 5510 SQL Ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893465#M167617</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My company is currently running a Cisco ASA 5510. &amp;nbsp;We have been told by our 3rd party point of sale vendor that they are having issues syncing their database and server because they need TCP port 1433 &amp;amp; UDP port 1434 opened on the firewall. &amp;nbsp;I have been staring at this for a few days now - I have attempted to create Access Rules to open those ports but it doesn't seem to change anything. &amp;nbsp;I apologize in advance, as I am a novice with these firewalls.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The server and machines attempting to sync up are all on the same domain, so I thought my access rules should be "Inside". &amp;nbsp;I have tried multiple variations of setups, including having incoming and outgoing rules and using "any" for both IP Addresses and ports. &amp;nbsp;I have reloaded the device after each change to make sure it was current, but nothing seems to fix the issue. &amp;nbsp;I understand the device is old and outdated, but they can't afford to upgrade anytime soon.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893465#M167617</guid>
      <dc:creator>j_patykow</dc:creator>
      <dc:date>2019-03-12T07:27:25Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893466#M167620</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Since you have allowed &lt;G class="gr_ gr_63 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="63" data-gr-id="63"&gt;any any&lt;/G&gt; it should have worked.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Before we move ahead I would request you to test with this config:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The SQL server is listening on UDP/TCP port &lt;G class="gr_ gr_125 gr-alert gr_gramm undefined Punctuation multiReplace" id="125" data-gr-id="125"&gt;1434 ,&lt;/G&gt; so the client will initiate a connection from a random port above 1025.&lt;BR /&gt;So you need to have an ACL to allow the access from Any with random UDP/TCP port going to SQL server on port 1434, so you need to have the command &lt;BR /&gt;" range 1 &lt;G class="gr_ gr_130 gr-alert gr_gramm undefined Punctuation multiReplace" id="130" data-gr-id="130"&gt;65353 " ,&lt;/G&gt; and for the returning traffic you need to have an ACL from source port 1434 going to the random destination port.&lt;BR /&gt;Since you are accessing the Server from outside to &lt;G class="gr_ gr_129 gr-alert gr_gramm undefined Punctuation multiReplace" id="129" data-gr-id="129"&gt;inside ,&lt;/G&gt; then you need to open the Access on the outside for the incoming traffic&lt;BR /&gt;So if you try and remove the ACL that &lt;G class="gr_ gr_127 gr-alert gr_gramm undefined Grammar multiReplace" id="127" data-gr-id="127"&gt;permit&lt;/G&gt; the traffic from the SQL server on port 1434 going to the client on random &lt;G class="gr_ gr_128 gr-alert gr_gramm undefined Punctuation replaceWithoutSep" id="128" data-gr-id="128"&gt;port ,then&lt;/G&gt; it should &lt;BR /&gt;be &lt;G class="gr_ gr_126 gr-alert gr_gramm undefined Punctuation multiReplace" id="126" data-gr-id="126"&gt;fine .&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;Please check the below &lt;G class="gr_ gr_122 gr-alert gr_gramm undefined Punctuation multiReplace" id="122" data-gr-id="122"&gt;link :&lt;/G&gt;&lt;BR /&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080862017.shtml#open&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 03:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893466#M167620</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-09T03:41:23Z</dc:date>
    </item>
    <item>
      <title>I'm sorry I should have been</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893467#M167623</link>
      <description>&lt;P&gt;I'm sorry I should have been more clear earlier. &amp;nbsp;These two machines are on the same domain, so I believe they are both using the "inside" interface. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just found some material on enabling u-turn / hairpinning since they are using the same interface.&lt;/P&gt;
&lt;P&gt;I enabled this option and received a different error:&lt;/P&gt;
&lt;P&gt;_______________________________________________________&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;Type - NAT &amp;nbsp; &amp;nbsp; Action - DROP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Config&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 access-list inside_nat0_outbound_1 outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;match ip inside any inside any&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;dynamic translation to pool 1 (no matching global)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;translate_hits = 1, untranslate_hits = 0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;_______________________________________________________&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am very new to this, and am not knowledgeable about the commands. &amp;nbsp;I am attempting to do all of this from the ASDM. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am assuming I need to set something up in the NAT, but am not sure on how to go about this correctly. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, is there a way to configure it so that it only allows the hairpinning from specific IP's, so it doesn't congest the ASA?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am grateful for any help!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 17:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893467#M167623</guid>
      <dc:creator>j_patykow</dc:creator>
      <dc:date>2016-03-09T17:23:03Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893468#M167626</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No worries. You need to add two commands on the CLI:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;global (inside) 1 interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 18:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893468#M167626</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-09T18:29:37Z</dc:date>
    </item>
    <item>
      <title>Getting closer.  But now I am</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893469#M167629</link>
      <description>&lt;P&gt;Getting closer. &amp;nbsp;But now I am seeing this:&lt;/P&gt;
&lt;P&gt;________________________________________________________&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;Type - NAT &amp;nbsp; &amp;nbsp; Subtype - rpf-check &amp;nbsp; &amp;nbsp; Action - DROP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 access-list inside_nat0_outbound_1 outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;match ip inside any inside any&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;dynamic translation to pool 1 (10.1.2.2 [Interface PAT])&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;translate_hits = 2, untranslate_hits = 0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;________________________________________________________&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And I see this in the ASDM Syslog:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;No translation group found for tcp src inside: ......&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 20:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-sql-ports/m-p/2893469#M167629</guid>
      <dc:creator>j_patykow</dc:creator>
      <dc:date>2016-03-09T20:18:23Z</dc:date>
    </item>
  </channel>
</rss>

