<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 DMZ config question - CLI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911153#M420750</link>
    <description>&lt;P&gt;I have recently inherited a network with an ASA 5505 at a remote office.  Users there have a server that needs to be accessible from the outside.  I would like to put this server in a DMZ and use port forwarding (I have the security plus license already installed).  I can only find the ASDM instructions for this - there has to be CLI commands for this.  Can someone please respond with either the instuctions or the link where I can find them?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:47:13 GMT</pubDate>
    <dc:creator>kwhitley1</dc:creator>
    <dc:date>2020-02-21T09:47:13Z</dc:date>
    <item>
      <title>ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911153#M420750</link>
      <description>&lt;P&gt;I have recently inherited a network with an ASA 5505 at a remote office.  Users there have a server that needs to be accessible from the outside.  I would like to put this server in a DMZ and use port forwarding (I have the security plus license already installed).  I can only find the ASDM instructions for this - there has to be CLI commands for this.  Can someone please respond with either the instuctions or the link where I can find them?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911153#M420750</guid>
      <dc:creator>kwhitley1</dc:creator>
      <dc:date>2020-02-21T09:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911154#M420752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will you be using the ASA outside interface IP?  if so this thread should get you up and running for port forwarding ,  replace your static entry to reflect DMZ interface , static(DMZ,outside)  etc..  , come back if any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddfc9dc" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddfc9dc&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2007 17:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911154#M420752</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-11-12T17:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911155#M420753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example of the configuration guide for PIX and ASA version 7.2, check it out and use for further reference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2007 17:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911155#M420753</guid>
      <dc:creator>msosabar</dc:creator>
      <dc:date>2007-11-12T17:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911156#M420754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ups!!! sorry, here is the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/cfgnat.html#wp1043281" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/cfgnat.html#wp1043281&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2007 17:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911156#M420754</guid>
      <dc:creator>msosabar</dc:creator>
      <dc:date>2007-11-12T17:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911157#M420755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all - thank you - both for your response.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes - the ASA outside interface IP will be used for the server as well.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I have created so far&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An Object-group: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object-group service SERVER tcp &lt;/P&gt;&lt;P&gt;description TCP Passthrough Ports &lt;/P&gt;&lt;P&gt;Port-object range XXXX-XXXX &lt;/P&gt;&lt;P&gt;Port-object range xxxx-xxxx &lt;/P&gt;&lt;P&gt;Port-object range eq xxxxx &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An access list outside_access_in: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host (outside IP) object-group SERVER &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And applied this access list to the outside interface: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would the static look like this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,outside) (outside IP) (DMZ server IP) netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need a global (outside) statement?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2007 02:59:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911157#M420755</guid>
      <dc:creator>kwhitley1</dc:creator>
      <dc:date>2007-11-13T02:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911158#M420756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your static should look as :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,outside) interface &lt;WEB.SERVER.IP&gt; netmask 255.255.255.255 &lt;/WEB.SERVER.IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for global leave as is if Im not mistaken it should already have statement as " global (outside) 1 interface "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2007 13:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911158#M420756</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-11-13T13:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911159#M420757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This worked!  Thank you much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2007 23:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911159#M420757</guid>
      <dc:creator>kwhitley1</dc:creator>
      <dc:date>2007-11-14T23:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 DMZ config question - CLI</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911160#M420758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you - I have been looking for this without luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2007 23:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dmz-config-question-cli/m-p/911160#M420758</guid>
      <dc:creator>kwhitley1</dc:creator>
      <dc:date>2007-11-14T23:23:58Z</dc:date>
    </item>
  </channel>
</rss>

