<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Port to application mapping on asa in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421591#M309554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The connection should work if you are connecting from R2 to R1 with the destination IP 192.168.1.1 and port TCP/8080. Or that is how I understood the original request below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Now i want to configure ASA to port map 80 to 8080,&amp;nbsp; telnet from R2 to R1 ( telnet 192.168.1.1 8080) , how can i do it ?&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your above example seems to be you connecting from the R1 to itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;R1#telnet 192.168.1.1 8080&lt;/P&gt;&lt;P&gt;Trying 192.168.1.1, 8080 ...&lt;/P&gt;&lt;P&gt;% Connection refused by remote host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So test this from R2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Nov 2013 14:11:50 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-11-05T14:11:50Z</dc:date>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421582#M309520</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have cisco asa 8.4, i am using simple topology on gns3:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R1&amp;nbsp; ----------------------------------(inisde) ASA (outside) ------------------------------ R2&lt;/P&gt;&lt;P&gt;192.168.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.1&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have enabled http on R1, telnet from R2 to R1 (telnet 192.168.1.1 80) , it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i want to configure ASA to port map 80 to 8080,&amp;nbsp; telnet from R2 to R1 ( telnet 192.168.1.1 8080) , how can i do it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thankssss&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:00:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421582#M309520</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2019-03-12T03:00:34Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421583#M309525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This depends on your software level used. The NAT configuration format is different for software levels 8.2 (and below) compared to levels 8.3 (and above)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example of both&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Software 8.2 and below&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,outside) tcp 192.168.1.1 8080 192.168.1.1 80 netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list &lt;OUTSIDE acl="" name=""&gt; permit tcp any host 192.168.1.1 8080&lt;/OUTSIDE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Software 8.3 and above&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network R1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,outside) static 192.168.1.1 service tcp 80 8080&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list &lt;OUTSIDE acl="" name=""&gt; permit tcp any object R1 eq 80&lt;/OUTSIDE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it works for you. If not then will have to look more into the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421583#M309525</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T13:17:45Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421584#M309530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It did not work, i tried to write same command, it did not accept &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh ver&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.4(2)&lt;/P&gt;&lt;P&gt;Compiled on Wed 15-Jun-11 18:17 by builders&lt;BR /&gt;System image file is "Unknown, monitor mode tftp booted image"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object service 80&lt;/P&gt;&lt;P&gt; service tcp destination eq www&lt;/P&gt;&lt;P&gt;object service 8080&lt;/P&gt;&lt;P&gt; service tcp source eq 8080&lt;/P&gt;&lt;P&gt;object network R1&lt;/P&gt;&lt;P&gt; host 192.168.2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# nat (inside,ouside) source static ?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; WORD&amp;nbsp; Specify object or object-group name for real source&lt;BR /&gt;&amp;nbsp; any&amp;nbsp;&amp;nbsp; Abbreviation for source address and mask of 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# nat (inside,ouside) source static R1 ?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; WORD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Specify object or object-group name for mapped source&lt;BR /&gt;&amp;nbsp; interface&amp;nbsp; Specify interface NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to write it ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421584#M309530</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T13:35:42Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421585#M309535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You did not enter the commands I suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT configuration should be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network R1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,outside) static 192.168.1.1 service tcp 80 8080&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are trying to add the &lt;STRONG&gt;"nat"&lt;/STRONG&gt; configuration in the global configuration space and not under the &lt;STRONG&gt;"object network R1"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So enter these in order wihtout entering any other command in between&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network R1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,outside) static 192.168.1.1 service tcp 80 8080&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first one will create the &lt;STRONG&gt;"object"&lt;/STRONG&gt; and move under its configuration space. The next one will add the &lt;STRONG&gt;"host"&lt;/STRONG&gt; address under the &lt;STRONG&gt;"object"&lt;/STRONG&gt;. The last command will add the actual &lt;STRONG&gt;"nat"&lt;/STRONG&gt; command under the &lt;STRONG&gt;"object"&lt;/STRONG&gt; we created&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you need the ACL to allow the traffic as described in my first reply. Naturally you will have to use an ACL that is attached with the &lt;STRONG&gt;"access-group"&lt;/STRONG&gt; to your &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:39:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421585#M309535</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T13:39:58Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421586#M309537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi, i manage to write command, but i am getting &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R1#telnet 192.168.1.1 8080&lt;/P&gt;&lt;P&gt;Trying 192.168.1.1, 8080 ...&lt;/P&gt;&lt;P&gt;% Connection refused by remote host&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421586#M309537</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T13:48:26Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421587#M309541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post your ACL configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run access-list&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run access-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have no ACL configured you could add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list OUTSIDE-IN permit tcp any object R1 eq 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-group OUTSIDE-IN in interface outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I presume you have an existing ACL attached to interface &lt;STRONG&gt;"outside"&lt;/STRONG&gt; like in my above example so you could use that ACL to allow what I have allowed above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it works. Otherwise post the configurations so I can check what is needed &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421587#M309541</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T14:00:09Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421588#M309545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&amp;nbsp; sh run access-list&lt;BR /&gt;access-list l extended permit tcp any object R1 eq www&lt;BR /&gt;access-list l extended permit ip any any&lt;/P&gt;&lt;P&gt;ciscoasa# sh run access-group&lt;BR /&gt;access-group l in interface ouside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421588#M309545</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T14:08:52Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421589#M309548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;%ASA-6-302013: Built outbound TCP connection 44 for ouside:192.168.2.1/8080 (192.168.2.1/8080) to inside:192.168.1.1/29489 (192.168.1.1/29489)&lt;/P&gt;&lt;P&gt;%ASA-6-302014: Teardown TCP connection 44 for ouside:192.168.2.1/8080 to inside:192.168.1.1/29489 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421589#M309548</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T14:11:00Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421590#M309551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;%ASA-6-302013: Built inbound TCP connection 46 for ouside:192.168.2.1/42377 (192.168.2.1/42377) to inside:192.168.1.1/8080 (192.168.1.1/8080)&lt;/P&gt;&lt;P&gt;%ASA-6-302014: Teardown TCP connection 46 for ouside:192.168.2.1/42377 to inside:192.168.1.1/8080 duration 0:00:00 bytes 0 TCP Reset-I&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421590#M309551</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T14:11:44Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421591#M309554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The connection should work if you are connecting from R2 to R1 with the destination IP 192.168.1.1 and port TCP/8080. Or that is how I understood the original request below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Now i want to configure ASA to port map 80 to 8080,&amp;nbsp; telnet from R2 to R1 ( telnet 192.168.1.1 8080) , how can i do it ?&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your above example seems to be you connecting from the R1 to itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;R1#telnet 192.168.1.1 8080&lt;/P&gt;&lt;P&gt;Trying 192.168.1.1, 8080 ...&lt;/P&gt;&lt;P&gt;% Connection refused by remote host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So test this from R2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421591#M309554</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T14:11:50Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421592#M309557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, same thing i am getting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R2#telnet 192.168.1.1 8080&lt;/P&gt;&lt;P&gt;Trying 192.168.1.1, 8080 ...&lt;/P&gt;&lt;P&gt;% Connection refused by remote host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-302013: Built outbound TCP connection 53 for ouside:192.168.1.1/8080 (192.168.1.1/8080) to inside:192.168.2.1/55789 (192.168.2.1/55789)&lt;/P&gt;&lt;P&gt;%ASA-6-302014: Teardown TCP connection 53 for ouside:192.168.1.1/8080 to inside:192.168.2.1/55789 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;P&gt;%ASA-7-609002: Teardown local-host inside:192.168.2.1 duration 0:00:00&lt;/P&gt;&lt;P&gt;%ASA-7-609002: Teardown local-host ouside:192.168.1.1 duration 0:00:00&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421592#M309557</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T14:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421593#M309561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs dont match your original posts topology at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log says R1 192.168.1.1 is located &lt;STRONG&gt;"outside"&lt;/STRONG&gt; and the R2 192.168.2.1 is located &lt;STRONG&gt;"inside"&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the complete firewall configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually seems your other interface is called&lt;STRONG&gt; "ouside" &lt;/STRONG&gt;and not &lt;STRONG&gt;"outside"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421593#M309561</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T14:24:45Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421594#M309564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ciscoasa# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.2.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;object network out&lt;/P&gt;&lt;P&gt; host 192.168.2.1&lt;/P&gt;&lt;P&gt;object network in&lt;/P&gt;&lt;P&gt; host 192.168.1.1&lt;/P&gt;&lt;P&gt;object service 80&lt;/P&gt;&lt;P&gt; service tcp destination eq www&lt;/P&gt;&lt;P&gt;object service 8080&lt;/P&gt;&lt;P&gt; service tcp source eq 8080&lt;/P&gt;&lt;P&gt;object network R1&lt;/P&gt;&lt;P&gt; host 192.168.2.1&lt;/P&gt;&lt;P&gt;access-list l extended permit ip any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network R1&lt;/P&gt;&lt;P&gt; nat (outside,inside) static 192.168.2.1 service tcp www 8080&lt;/P&gt;&lt;P&gt;access-group l in interface outside&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421594#M309564</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T14:34:03Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421595#M309567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is different IP address used in the NAT configuration? The IP address of R2 even though you wanted to do the NAT for R1 IP address 192.168.1.1 to my understanding so that R2 could connec to 192.168.1.1 port TCP/8080 to reach the actual port TCP/80 on the R1 192.168.1.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so then you would need to issue these commands which I suggested originally&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network R1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,outside) static 192.168.1.1 service tcp 80 8080&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:38:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421595#M309567</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T14:38:03Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421596#M309571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thx Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can u share good tutorial for such config ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:40:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421596#M309571</guid>
      <dc:creator>alkabeer80</dc:creator>
      <dc:date>2013-11-05T14:40:51Z</dc:date>
    </item>
    <item>
      <title>Port to application mapping on asa</title>
      <link>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421597#M309573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could take a look at the document I have made here on the forums. It contains some examples of basic NAT configurations. It still work in progress&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-31116"&gt;https://supportforums.cisco.com/docs/DOC-31116&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-to-application-mapping-on-asa/m-p/2421597#M309573</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T14:42:28Z</dc:date>
    </item>
  </channel>
</rss>

