<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you port forward a port range on asa5505 version 8.3 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284882#M332197</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were you able to test this with the above mention correct configuration? I had mistakenly put &lt;STRONG&gt;"object network"&lt;/STRONG&gt; in the original reply instead of &lt;STRONG&gt;"object service"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Sep 2013 06:49:09 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-09-30T06:49:09Z</dc:date>
    <item>
      <title>Can you port forward a port range on asa5505 version 8.3</title>
      <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284878#M332185</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to port forward a range of ports on the asa, I can't do it via the GUI, is it possible via the cli ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Carl&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284878#M332185</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2019-03-12T02:44:54Z</dc:date>
    </item>
    <item>
      <title>Can you port forward a port range on asa5505 version 8.3</title>
      <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284879#M332189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to forward a range of ports to a host without changing the actual port you should be able to do it the following way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PORT-RANGE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source range 1000 2000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network HOST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static HOST interface service PORT-RANGE PORT-RANGE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above should map the internal host 10.10.10.10 to the interface IP address of &lt;STRONG&gt;"outside"&lt;/STRONG&gt; for ports 1000-2000.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do remember to mark a reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Sep 2013 20:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284879#M332189</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-29T20:35:46Z</dc:date>
    </item>
    <item>
      <title>Can you port forward a port range on asa5505 version 8.3</title>
      <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284880#M332192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried that and it didn't like the nat command, it would only allow me to do, static (inside,outside) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I tried the nat command it didn't seem to work, are you sure about this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Sep 2013 20:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284880#M332192</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2013-09-29T20:49:16Z</dc:date>
    </item>
    <item>
      <title>Can you port forward a port range on asa5505 version 8.3</title>
      <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284881#M332195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a typo in the above configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"object"&lt;/STRONG&gt; is of wrong type. In the above its &lt;STRONG&gt;"network"&lt;/STRONG&gt; even though it should be &lt;STRONG&gt;"service"&lt;/STRONG&gt; to be able to hold the protocol/port. If the &lt;STRONG&gt;"object network PORT-RANGE"&lt;/STRONG&gt; is still configured on the ASA, it will have to be removed if you want to create an &lt;STRONG&gt;"object service PORT-RANGE"&lt;/STRONG&gt; on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no object network PORT-RANGE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object service PORT-RANGE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; service tcp source range 1000 2000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network HOST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 10.10.10.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static HOST interface service PORT-RANGE PORT-RANGE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the above it should accept the &lt;STRONG&gt;"nat"&lt;/STRONG&gt; command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Sep 2013 21:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284881#M332195</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-29T21:14:27Z</dc:date>
    </item>
    <item>
      <title>Can you port forward a port range on asa5505 version 8.3</title>
      <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284882#M332197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were you able to test this with the above mention correct configuration? I had mistakenly put &lt;STRONG&gt;"object network"&lt;/STRONG&gt; in the original reply instead of &lt;STRONG&gt;"object service"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 06:49:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284882#M332197</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-30T06:49:09Z</dc:date>
    </item>
    <item>
      <title>Can you port forward a port range on asa5505 version 8.3</title>
      <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284883#M332200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried this, its doesnt work, when I do &amp;gt;nat (inside,outside) it comes up with an error, it lets me do nat (inside) then expects a number,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the way to do this is static (inside,outside) tcp etc etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EURUS-MOS-FW1(config)# nat (inside,outside) ?&lt;/P&gt;&lt;P&gt;ERROR: % Unrecognized command&lt;/P&gt;&lt;P&gt;EURUS-MOS-FW1(config)# nat (inside,outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EURUS-MOS-FW1(config)# static (inside,outside) ?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; Hostname or A.B.C.D&amp;nbsp; Global or mapped address&lt;BR /&gt;&amp;nbsp; interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Global address overload from interface&lt;BR /&gt;&amp;nbsp; tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP to be used as transport protocol&lt;BR /&gt;&amp;nbsp; udp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP to be used as transport protocol&lt;BR /&gt;EURUS-MOS-FW1(config)# static (inside,outside) tcp ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 08:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284883#M332200</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2013-09-30T08:03:34Z</dc:date>
    </item>
    <item>
      <title>Can you port forward a port range on asa5505 version 8.3</title>
      <link>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284884#M332202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would seem to me that your original post asked for a Static PAT for a range of ports for ASA software level 8.3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your above output would indicate that your firewall is NOT running 8.3 or above software therefore my suggested NAT configuration format is not supported on your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In software levels 8.2 and below there is no way to forward a range of ports with few commands. You will need a &lt;STRONG&gt;"static"&lt;/STRONG&gt; command for each port which depending on the amount of ports needed might generate quite a bit of configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,outside) tcp interface 1000 &lt;INTERNAL ip=""&gt; 1000 netmask 255.255.255.255&lt;/INTERNAL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,outside) udp interface 1000 &lt;INTERNAL ip=""&gt; 1000 netmask 255.255.255.255&lt;/INTERNAL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check your software level with command &lt;STRONG&gt;"show version"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 09:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-port-forward-a-port-range-on-asa5505-version-8-3/m-p/2284884#M332202</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-30T09:40:22Z</dc:date>
    </item>
  </channel>
</rss>

