<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic port forwarding not working , possible ACL issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007634#M435118</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sh run object &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network mailserver&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;object network webmail&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;object network securewebmail&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;object network webserverpop3&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network mailserver&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp smtp smtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have not configured access-group... could this be it? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jun 2012 18:16:01 GMT</pubDate>
    <dc:creator>Alex Mendez</dc:creator>
    <dc:date>2012-06-01T18:16:01Z</dc:date>
    <item>
      <title>port forwarding not working , possible ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007632#M435116</link>
      <description>&lt;P&gt;Greetins All - hopefullly you can help me. I'm trying to port forward some ports to my internal mail server, namely smtp , www and http/https.&amp;nbsp; It looks like nat does work but its possible the firewall blocks it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-cus-fw-01(config)# s&lt;STRONG&gt;how nat&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;/P&gt;&lt;P&gt;1 (inside) to (outside) source static mailserver interface&amp;nbsp;&amp;nbsp; service tcp smtp smtp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1, untranslate_hits = 6&amp;nbsp;&amp;nbsp; &amp;lt;-------&amp;nbsp; this happens when i try to telnet&amp;nbsp; &amp;lt;mydomain.com&amp;gt;&amp;nbsp; 25 , from an outside host&lt;/P&gt;&lt;P&gt;2 (inside) to (outside) source dynamic obj-10.10.10.0 interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 8435, untranslate_hits = 673&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;my access list &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;elg-cus-fw-01(config)# show access-list&lt;/P&gt;&lt;P&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alert-interval 300&lt;/P&gt;&lt;P&gt;access-list outside_access_in; 4 elements; name hash: 0x6892a938&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 1 extended permit tcp any object mailserver eq smtp (hitcnt=0) 0x029b8a79&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list outside_access_in line 1 extended permit tcp any host 10.10.10.31 eq smtp (hitcnt=0) 0x029b8a79&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 2 extended permit tcp any object securewebmail eq https (hitcnt=0) 0xc7e21171&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list outside_access_in line 2 extended permit tcp any host 10.10.10.31 eq https (hitcnt=0) 0xc7e21171&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 3 extended permit tcp any object webmail eq www (hitcnt=0) 0xa3e2340f&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list outside_access_in line 3 extended permit tcp any host 10.10.10.31 eq www (hitcnt=0) 0xa3e2340f&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 4 extended permit tcp any object webserverpop3 eq pop3 (hitcnt=0) 0x5386a581&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list outside_access_in line 4 extended permit tcp any host 10.10.10.31 eq pop3 (hitcnt=0) 0x5386a581&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;my packet tracer &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;lg-cus-fw-01(config)# packet-tracer input&amp;nbsp; outside tcp fqdn google.com smtp 1$&lt;/P&gt;&lt;P&gt;Mapping FQDN google.com to IP address 74.125.225.72&lt;/P&gt;&lt;P&gt;(More IP addresses resolved. Please run "show dns-host" to check.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.10.10.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does anyone know where is the rule? Is this something by defautl? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007632#M435116</guid>
      <dc:creator>Alex Mendez</dc:creator>
      <dc:date>2019-03-11T23:14:34Z</dc:date>
    </item>
    <item>
      <title>port forwarding not working , possible ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007633#M435117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide us the following information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sh run object network ( Want to see the one for that host)&lt;/P&gt;&lt;P&gt;Sh run nat ( the one used by that host)&lt;/P&gt;&lt;P&gt;Sh run access-group&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 18:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007633#M435117</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-06-01T18:03:48Z</dc:date>
    </item>
    <item>
      <title>port forwarding not working , possible ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007634#M435118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sh run object &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network mailserver&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;object network webmail&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;object network securewebmail&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;object network webserverpop3&lt;/P&gt;&lt;P&gt; host 10.10.10.31&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network mailserver&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp smtp smtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have not configured access-group... could this be it? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 18:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007634#M435118</guid>
      <dc:creator>Alex Mendez</dc:creator>
      <dc:date>2012-06-01T18:16:01Z</dc:date>
    </item>
    <item>
      <title>port forwarding not working , possible ACL issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007635#M435119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alex.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-group&amp;nbsp; outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 19:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-not-working-possible-acl-issue/m-p/2007635#M435119</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-06-01T19:02:49Z</dc:date>
    </item>
  </channel>
</rss>

