<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic port forwarding asa 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279885#M345932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are definetly running and old version but that is not the cause of the issue right now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the captures you are not getting any packets so it's not a problem with the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u share :&lt;/P&gt;&lt;P&gt;show route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Networking Posts check my blog at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.laguiadelnetworking.com/category/english/"&gt;http://www.laguiadelnetworking.com/category/english/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Jul 2013 16:37:57 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-07-24T16:37:57Z</dc:date>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279880#M345926</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;guys,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;i need your assisance to double or triple check my port forwarding, basically i want to have 1 public ip for muliple rdp connections.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;configuration as follow&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;access-list 100 extended permit tcp any host x.x.51.126 eq 3393&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;static (inside,outside) tcp x.x.51.126 3393 192.168.1.13 3389 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;global (outside) 1 interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;global (backup) 1 interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;access-group 100 in interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;sh ver&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Cisco Adaptive Security Appliance Software Version 7.0(7)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 12pt;"&gt;Device Manager Version 5.0(7)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;i looked the documentation and other resources, and somehow it's not working. but if i don't do port forwarding, it works fine. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;i am not where to look at this point. let me know if someone can guide me to the right place.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;thanks in advanced.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279880#M345926</guid>
      <dc:creator>TY08</dc:creator>
      <dc:date>2019-03-12T02:16:08Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279881#M345927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks good &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the thing is that if you are using the backup interface is not gonna work as the static and ACL are only applied on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you run the packet-tracer command:&lt;/P&gt;&lt;P&gt;Follow this documment and leave your comments &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; :&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.laguiadelnetworking.com/the-usage-of-the-packet-tracer-feature-on-the-asa/"&gt;http://www.laguiadelnetworking.com/the-usage-of-the-packet-tracer-feature-on-the-asa/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN&gt;For Networking Posts check my blog at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.laguiadelnetworking.com/category/english/"&gt;http://www.laguiadelnetworking.com/category/english/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 00:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279881#M345927</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-24T00:55:35Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279882#M345928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the reply. i tried to remove my backup interface and that didn't seem do the trick. packet-tracer isn't available on the firewall, it's currently still running on v 7.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any other thoughts that might have caused this issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i use clear xlate command each time i setup static(inside,outside) command, and rebooted for 2 times. still no luck. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am not too sure where the problem is. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 01:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279882#M345928</guid>
      <dc:creator>TY08</dc:creator>
      <dc:date>2013-07-24T01:55:08Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279883#M345929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Blue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never said remove the backup interface &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;, I just said if you plan to use the backup you still need a NAT statement for the backup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ups I did not pay attention to the ASA version (Just as a note : Dude you have a 5510. That's an amazing box.. Take full usage of it and use the newer versions otherwise how much for that ? just kidding but really try to upgrade to a latest version as you are definetly missing a lot of fun).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okey, time to do captures( as we do not have the &lt;SPAN style="font-size: 10pt;"&gt;almighty &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;packet-tracer)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;access-list capout permit tcp host Outside_Client_IP_address host &lt;SPAN style="font-size: 10pt;"&gt;x.x.51.126 eq 3393&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;access-list capout permit tcp host x.x51.126 eq 3393 host Outside_Client_IP_address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capin permit tcp host Outside_Client_IP_address host &lt;SPAN style="font-size: 10pt;"&gt;192.168.1.13 eq 3389&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;access-list capin permit tcp host 192.168.1.13 eq 3389 host Outside_Client_IP_address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capout access-list capout interface outside&lt;/P&gt;&lt;P&gt;capture capin access-list capin interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try to connect once and share&lt;/P&gt;&lt;P&gt;show cap capin&lt;/P&gt;&lt;P&gt;show cap capout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Remember to rate all of my posts, I definetly take my time to help here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Networking Posts check my blog at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.laguiadelnetworking.com/category/english/"&gt;http://www.laguiadelnetworking.com/category/english/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 02:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279883#M345929</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-24T02:49:45Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279884#M345930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i know you didn't but i just went ahead to disable it for another possibility. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tried your approach as follow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capout extended permit tcp any host x.x.51.126 eq 3393&lt;/P&gt;&lt;P&gt;access-list capout extended permit tcp host x.x.51.126 eq 3393 any&lt;/P&gt;&lt;P&gt;access-list capin extended permit tcp any host 192.168.1.13 eq 3393&lt;/P&gt;&lt;P&gt;access-list capin extended permit tcp host 192.168.1.13 eq 3393 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa5510# capture capout access-list capout interface outside&lt;/P&gt;&lt;P&gt;asa5510# capture capin access-list capin interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa5510# sh cap capin&lt;/P&gt;&lt;P&gt;0 packet captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa5510# sh cap capout&lt;/P&gt;&lt;P&gt;0 packet captured&lt;/P&gt;&lt;P&gt;0 packet shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this firmware too old? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks...&lt;/P&gt;&lt;P&gt;tedy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 03:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279884#M345930</guid>
      <dc:creator>TY08</dc:creator>
      <dc:date>2013-07-24T03:21:02Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279885#M345932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are definetly running and old version but that is not the cause of the issue right now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the captures you are not getting any packets so it's not a problem with the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u share :&lt;/P&gt;&lt;P&gt;show route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Networking Posts check my blog at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.laguiadelnetworking.com/category/english/"&gt;http://www.laguiadelnetworking.com/category/english/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 16:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279885#M345932</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-24T16:37:57Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279886#M345935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the show route output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa5510# sh route&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via x.x.51.121, outside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; x.x.51.120 255.255.255.248 is directly connected, outside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 is directly connected, inside&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;i have others mapping done on the access list for email server, and that seems to be working fine and rdp, port 3389, works as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my plan is to upgrade this box to the newer version. if you any other thoughts, please let me know. i have looked few links about my settings and also cisco docs for port forwarding, and i don't see anything wrong on the command line configuration. &lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; width: 1px; height: 1px; overflow: hidden; top: 0px; left: -10000px;"&gt;﻿&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 23:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279886#M345935</guid>
      <dc:creator>TY08</dc:creator>
      <dc:date>2013-07-24T23:58:33Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279887#M345936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you share the entire configuration please,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean right now base on the outputs you have provided I would blame something outside the ASA as we are not seeing any packets,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please send me the config in private if required&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Networking Posts check my blog at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.laguiadelnetworking.com/category/english/"&gt;http://www.laguiadelnetworking.com/category/english/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 06:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279887#M345936</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-25T06:45:11Z</dc:date>
    </item>
    <item>
      <title>port forwarding asa 5510</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279888#M345938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just sent you the config to your private message. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 13:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-asa-5510/m-p/2279888#M345938</guid>
      <dc:creator>TY08</dc:creator>
      <dc:date>2013-07-25T13:29:31Z</dc:date>
    </item>
  </channel>
</rss>

