<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forwarding a single port in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849003#M456330</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; object network INSIDE_HOST&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 10.100.130.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (INSIDE,OUTSIDE) static &lt;STRONG&gt;interface/ip&lt;/STRONG&gt; service 26883 26883 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You need to do this way .use IP if you have static IP else go for interface -this will use your outside interface IP for port forwarding.&lt;/P&gt;&lt;P&gt;&amp;nbsp; For multiple port repeat the sameprocess or configure another object group for next real IP adsress.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Do not forget to configured outside ACL for real IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks&lt;/P&gt;&lt;P&gt; Ajay &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Jan 2012 20:42:27 GMT</pubDate>
    <dc:creator>ajay chauhan</dc:creator>
    <dc:date>2012-01-23T20:42:27Z</dc:date>
    <item>
      <title>Forwarding a single port</title>
      <link>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849002#M456327</link>
      <description>&lt;P&gt;Is there a way to forward a single port, while leaving the others alone?&amp;nbsp; For instance I want to forward all https traffic on a public IP to an internal server on port 4443. At the same time traffic on all other ports for this IP needs to be forwarded on the original port.&amp;nbsp; It looks like creating a Network Object will allow a single port to be forwarded, but what happens to the remaining traffic?&amp;nbsp; I attempted to create Service Objects that I then assigned to NAT statements. For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object service HTTPS_Translation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; service tcp source eq https destination eq 4443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (any,any) source static [External IP] [Internal IP] service HTTPS_Translation HTTPS_Translation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically I just want to do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;443-&amp;gt;firewall-&amp;gt;4443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;80-&amp;gt;firewall-&amp;gt;80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;25-&amp;gt;firewall-&amp;gt;25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to do what I'm attempting and if so how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I have an ASA 5510 with version 8.4(1) software.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849002#M456327</guid>
      <dc:creator>greggeesaman</dc:creator>
      <dc:date>2019-03-11T22:18:08Z</dc:date>
    </item>
    <item>
      <title>Forwarding a single port</title>
      <link>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849003#M456330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; object network INSIDE_HOST&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 10.100.130.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (INSIDE,OUTSIDE) static &lt;STRONG&gt;interface/ip&lt;/STRONG&gt; service 26883 26883 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You need to do this way .use IP if you have static IP else go for interface -this will use your outside interface IP for port forwarding.&lt;/P&gt;&lt;P&gt;&amp;nbsp; For multiple port repeat the sameprocess or configure another object group for next real IP adsress.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Do not forget to configured outside ACL for real IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks&lt;/P&gt;&lt;P&gt; Ajay &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 20:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849003#M456330</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2012-01-23T20:42:27Z</dc:date>
    </item>
    <item>
      <title>Forwarding a single port</title>
      <link>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849004#M456332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I'm entering:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network NAT_TEST&lt;/P&gt;&lt;P&gt;host 192.168.1.101&lt;/P&gt;&lt;P&gt;nat (inside,outside) static 204.x.x.185 service tcp 443 4443&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 204.x.x.185 service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second NAT statement overwrites the first.&amp;nbsp; I think I'm missing something.&amp;nbsp; I have a service group with multiple service object that relate to all the ports I need to forward.&amp;nbsp; Should I be relying on that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 21:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849004#M456332</guid>
      <dc:creator>greggeesaman</dc:creator>
      <dc:date>2012-01-23T21:42:41Z</dc:date>
    </item>
    <item>
      <title>Forwarding a single port</title>
      <link>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849005#M456333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would do it like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object service HTTPS_real&lt;/P&gt;&lt;P&gt;service tcp source eq https &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object service HTTPS_fake&lt;/P&gt;&lt;P&gt;service tcp source eq 4443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt; object network inside_host&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;host 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; object network outside_host&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;host 4.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nat (inside,outside) source static inside_host outside_host service HTTPS_real HTTPS_fake&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need the ACL pointing to 10.1.1.1 on port 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is all you need!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate helpful posts!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 01:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849005#M456333</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-24T01:40:05Z</dc:date>
    </item>
    <item>
      <title>Forwarding a single port</title>
      <link>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849006#M456334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Please follow what Julio said-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be your configuration- Considered your real server is part of Inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj-204.x.x.185&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 204.x.x.185&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;BR /&gt;object network NAT_TEST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 192.168.1.101&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;BR /&gt;object service tcp-443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service tcp source eq 443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;BR /&gt;object service tcp-80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service tcp source eq 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;BR /&gt;object service tcp-25&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service tcp source eq 25&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;BR /&gt;object service tcp-4443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service tcp source eq 4443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;BR /&gt; &lt;BR /&gt;nat (inside,outside) source static NAT_TEST obj-204.x.x.185 service tcp-4443 tcp-443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static NAT_TEST obj-204.x.x.185 service tcp-80 tcp-80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside,outside) source static NAT_TEST obj-204.x.x.185 service tcp-25 tcp-25&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Ofcourse ACL as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 12:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849006#M456334</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2012-01-24T12:26:40Z</dc:date>
    </item>
    <item>
      <title>Forwarding a single port</title>
      <link>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849007#M456335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you both for the help; it is working great. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 17:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwarding-a-single-port/m-p/1849007#M456335</guid>
      <dc:creator>greggeesaman</dc:creator>
      <dc:date>2012-01-24T17:59:52Z</dc:date>
    </item>
  </channel>
</rss>

