<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Forwarding in ASA for SSH service in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3836116#M28597</link>
    <description>&lt;P&gt;Hello Francesco,&lt;/P&gt;&lt;P&gt;I moved the dynamic nat rule after the specific objects ones.&lt;/P&gt;&lt;P&gt;The syntax is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;object network Server-Arq&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;nat (inside,WAN_INTERNET_If) static interface service tcp ssh 8022&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;nat (inside,WAN_INTERNET_If) after-auto source dynamic any interface&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" color="#000000"&gt;Regarding the PacketTracer, I have attached the output to this message. Last night, trying to do something different, I changed the 22022 port to tcp 8022, so the packet tracer command I ran was:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;packet-tracer input WAN_INTERNET_if tcp 8.8.8.8 12345 190.151.47.10 8022 detail&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" color="#000000"&gt;Hector M.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 15:30:32 GMT</pubDate>
    <dc:creator>hectormiranda</dc:creator>
    <dc:date>2019-04-10T15:30:32Z</dc:date>
    <item>
      <title>Port Forwarding in ASA for SSH service</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3835527#M28594</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;My scenario is as follows:&lt;/P&gt;&lt;P&gt;- Internal LAN subnet: &lt;STRONG&gt;192.168.20.0/24&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Cisco ASA5516-X external Public IP: &lt;STRONG&gt;190.151.47.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- inside interface name: inside&lt;/P&gt;&lt;P&gt;- outside interface name: &lt;STRONG&gt;WAN_INTERNET_If&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;There is a server in the internal LAN with IP address &lt;STRONG&gt;192.168.20.36&lt;/STRONG&gt;. There is an network object named &lt;STRONG&gt;Server-Arq&lt;/STRONG&gt; defined in the ASA.&lt;/P&gt;&lt;P&gt;I need to access that server &lt;STRONG&gt;&lt;EM&gt;from the outside&lt;/EM&gt;&lt;/STRONG&gt; through SSH but using &lt;STRONG&gt;tcp port 22022&lt;/STRONG&gt; as &lt;STRONG&gt;&lt;EM&gt;"external" port&lt;/EM&gt;&lt;/STRONG&gt;, then mapping it to port 22 in the server's address.&lt;/P&gt;&lt;P&gt;So, if a user&amp;nbsp;from the outside runs PuTTY pointing SSH to &lt;STRONG&gt;190.151.47.10 port 22022&lt;/STRONG&gt;, then that traffic goes to internal &lt;STRONG&gt;192.168.20.36 port 22&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;I wrote the following instructions in the ASA for the port forwarding:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;STRONG&gt;object network Server-Arq&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;STRONG&gt;nat (inside,WAN_INTERNET_If) static interface service tcp ssh 22022&lt;/STRONG&gt; &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Then I added the following ACL:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;STRONG&gt;access-list WAN_Internet_access_in extended permit tcp any object Server-Arq eq ssh&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the port tcp 22022 remains closed.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;&lt;STRONG&gt;What is missing in my configuration?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Attached current ASA config file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hector M.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 00:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3835527#M28594</guid>
      <dc:creator>hectormiranda</dc:creator>
      <dc:date>2019-04-10T00:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding in ASA for SSH service</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3835567#M28595</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You access-list should be for port 22022 and not ssh&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;STRONG&gt;"access-list WAN_Internet_access_in extended permit tcp any object Server-Arq eq 22022"&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 01:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3835567#M28595</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2019-04-10T01:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding in ASA for SSH service</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3835569#M28596</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you move your dynamic nat at the end like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;object network obj_any
 nat (any,WAN_INTERNET_If) after-auto dynamic interface&lt;/PRE&gt;
&lt;P&gt;Also can you run the following command and paste the result please in a text file:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;packet-tracer input WAN_INTERNET_if tcp 8.8.8.8 12345 190.151.47.10 22022 detail&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 01:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3835569#M28596</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-04-10T01:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding in ASA for SSH service</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3836116#M28597</link>
      <description>&lt;P&gt;Hello Francesco,&lt;/P&gt;&lt;P&gt;I moved the dynamic nat rule after the specific objects ones.&lt;/P&gt;&lt;P&gt;The syntax is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;object network Server-Arq&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;nat (inside,WAN_INTERNET_If) static interface service tcp ssh 8022&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;nat (inside,WAN_INTERNET_If) after-auto source dynamic any interface&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" color="#000000"&gt;Regarding the PacketTracer, I have attached the output to this message. Last night, trying to do something different, I changed the 22022 port to tcp 8022, so the packet tracer command I ran was:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#3366FF"&gt;&lt;STRONG&gt;packet-tracer input WAN_INTERNET_if tcp 8.8.8.8 12345 190.151.47.10 8022 detail&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif" color="#000000"&gt;Hector M.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 15:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3836116#M28597</guid>
      <dc:creator>hectormiranda</dc:creator>
      <dc:date>2019-04-10T15:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding in ASA for SSH service</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3836191#M28598</link>
      <description>&lt;P&gt;Than you John.&lt;/P&gt;&lt;P&gt;I tried it, but that's not the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hector M.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 17:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3836191#M28598</guid>
      <dc:creator>hectormiranda</dc:creator>
      <dc:date>2019-04-10T17:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding in ASA for SSH service</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3836491#M28599</link>
      <description>Did you removed this nat:&lt;BR /&gt;&lt;BR /&gt;object network obj_any&lt;BR /&gt; nat (any,WAN_INTERNET_If) dynamic interface&lt;BR /&gt;&lt;BR /&gt;You should have only your ssh nat first and then the dynamic at the end.&lt;BR /&gt;Do a clear xlate, test again and re-run the packet-tracer command please.</description>
      <pubDate>Thu, 11 Apr 2019 04:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3836491#M28599</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-04-11T04:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Port Forwarding in ASA for SSH service</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3837701#M28600</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I did two different tests:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Used an access switch in the LAN to forward port 22 to port 8201. External access (SSH to public ip + port 8201) worked ok&lt;/LI&gt;&lt;LI&gt;Used an internal PC (Windows) and installed FreeSSH server. Mapped port 22 to 22134 and external SSH worked ok.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;So, I asked the server's guy what was happenning with his machine. He changed the machine and the initial problem disappeared!&lt;/P&gt;&lt;P&gt;Anyway, I thank you guys for your great help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hector M.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 15:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-in-asa-for-ssh-service/m-p/3837701#M28600</guid>
      <dc:creator>hectormiranda</dc:creator>
      <dc:date>2019-04-12T15:49:36Z</dc:date>
    </item>
  </channel>
</rss>

