<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 NAT Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4004777#M30761</link>
    <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;, But I don't have PT installed. SSH Port is still closed for my Public IP address.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Dec 2019 14:44:43 GMT</pubDate>
    <dc:creator>nescody</dc:creator>
    <dc:date>2019-12-30T14:44:43Z</dc:date>
    <item>
      <title>ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4003428#M30675</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to allow ssh to my internal sever.&lt;/P&gt;&lt;P&gt;I basically used the same configuration which was configured for port 80 or 443 on ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network linux&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;host 192.168.1.123&lt;BR /&gt;object service sshlinux&lt;BR /&gt;&amp;nbsp; &amp;nbsp; service tcp source eq ssh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit tcp any host 192.168.1.123 eq ssh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static linux interface service sshlinux sshlinux&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-group Outside-in in interface outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest where the issue:&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 19:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4003428#M30675</guid>
      <dc:creator>nescody</dc:creator>
      <dc:date>2019-12-25T19:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4003438#M30681</link>
      <description>&lt;P&gt;your configuraton look good.&lt;/P&gt;&lt;P&gt;run a packet tracer&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 8.8.8.8 12345 (firewall outside ip address) ssh&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 21:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4003438#M30681</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-12-25T21:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4004777#M30761</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;, But I don't have PT installed. SSH Port is still closed for my Public IP address.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 14:44:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4004777#M30761</guid>
      <dc:creator>nescody</dc:creator>
      <dc:date>2019-12-30T14:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4004890#M30762</link>
      <description>&lt;P&gt;I am not talking about Packet Tracer software for cisco student network learning. I am talking Packet Tracer utility in ASA software code.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is a link&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/p1.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/I-R/cmdref2/p1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 20:11:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4004890#M30762</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-12-30T20:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4005182#M30763</link>
      <description>&lt;P&gt;Thanks for providing the link. I am very new for Cisco devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the output:&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 8.8.8.8 12345 XXX.XXX.XXX.XXX ssh&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside,outside) source static linux interface service sshlinux sshlinux&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface inside&lt;BR /&gt;Untranslate XXX.XXX.XXX.XXX/22 to 192.168.1.123/22&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;packets are dropping becuase of acl,&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is my acl:&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit tcp any host 192.168.1.123 eq ssh&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 13:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4005182#M30763</guid>
      <dc:creator>nescody</dc:creator>
      <dc:date>2020-01-03T13:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4005234#M30765</link>
      <description>&lt;P&gt;could you share your firewall configuration?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 19:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4005234#M30765</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-12-31T19:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4005734#M30766</link>
      <description>I think your problem is that you can't use port 22 on the outside unless you reassign the port that the ASA itself uses for SSH. You can do SSH on the outside on a different port, but translate it to 22 on the inside. That would look like this using port 922 on the outside. object network insidehost-ssh host 10.10.10.8 object network insidehost-ssh nat (inside,outside) static interface service tcp ssh 922 access-list internet-in extended permit tcp any object insidehost-ssh eq ssh access-group internet-in in interface outside</description>
      <pubDate>Thu, 02 Jan 2020 19:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4005734#M30766</guid>
      <dc:creator>Elliot Dierksen</dc:creator>
      <dc:date>2020-01-02T19:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4006041#M30769</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319015"&gt;@Elliot Dierksen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just trying to understand, as per packet tracer, packets were dropped becuase of acl configuration.&amp;nbsp; And another thing, I am not able to ssh into router which tells me router is not configured to login via ssh. So ssh port was not configured so why it wasn't allowing me to use port 22. Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is working now with assigning diferent port on outside and translate to ssh inside.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 14:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4006041#M30769</guid>
      <dc:creator>nescody</dc:creator>
      <dc:date>2020-01-03T14:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 NAT Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4006047#M30772</link>
      <description>&lt;P&gt;As it pertains to SSH, I think that port is allocated whether it is configured or not. That is not true for HTTP and HTTPS as I have been able to pass those ports through. If you look in the logs, I doubt you will see an ACL deny. SSH going to the ASA itself would be permitted or denied by the "ssh" directives (if any) in the config.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 14:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-nat-issue/m-p/4006047#M30772</guid>
      <dc:creator>Elliot Dierksen</dc:creator>
      <dc:date>2020-01-03T14:14:22Z</dc:date>
    </item>
  </channel>
</rss>

