<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Redirecting all IP to a services on a different host in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779762#M495829</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of IOS are you running??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Oct 2011 23:17:44 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2011-10-15T23:17:44Z</dc:date>
    <item>
      <title>Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779759#M495825</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose I want to redirect all connections from INSIDE(10.0.0.0/24) to OUTSIDE(any) on tcp port 80 to a server 172.2.2.2 in DMZ on port 3128, note that this port is not important as Linux can receive connexion on port 80 and redirect them to 3128 easily...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is called transparent proxy i know this can be done with WCCP commands, BUT i d like to know if ASA was able to redirect destination connections this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can also be very useful, imagine one of your MYSQL server is not accessible and you want to redirect all the connections to another server through the firewall without client re-configuration... (this is a good example as wccp won't be acceptable)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779759#M495825</guid>
      <dc:creator>davcommunay</dc:creator>
      <dc:date>2019-03-11T21:36:58Z</dc:date>
    </item>
    <item>
      <title>Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779760#M495826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could do that as you can create a NAT to look at the source and destination IP's as well as the service, you can either then change none, one, two or all three of those in the NAT rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A better solution, use DNS.&amp;nbsp; All of the clients should be pointed towards a name and not an IP.&amp;nbsp; Then if the server fails, you update the DNS record and all of the clients will continue to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Oct 2011 19:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779760#M495826</guid>
      <dc:creator>lance_brown</dc:creator>
      <dc:date>2011-10-13T19:56:06Z</dc:date>
    </item>
    <item>
      <title>Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779761#M495827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I trust you when you say it is possible &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i would ike to know how ??? a practical example of a nat rule of that kind...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise i am agree that using DNS for this is better but i am more interested by the technical aspect of that NAT rules in ASA as it is so easy to do with iptables ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have the solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Oct 2011 11:26:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779761#M495827</guid>
      <dc:creator>davcommunay</dc:creator>
      <dc:date>2011-10-15T11:26:42Z</dc:date>
    </item>
    <item>
      <title>Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779762#M495829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of IOS are you running??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Oct 2011 23:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779762#M495829</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-10-15T23:17:44Z</dc:date>
    </item>
    <item>
      <title>Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779763#M495831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nat (Inside, Outside) 1 source static 10.0.0.0 [ip address to NAT source address to] destination static [ip address/subnet of destination] 172.2.2.2 service HTTP HTTP no-proxy-arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want truly any service rather than just HTTP as the original service, then it would look like this:&lt;/P&gt;&lt;P&gt;nat (Inside, Outside) 1 source static 10.0.0.0 (ip address to NAT source address to) destination static (ip address/subnet of destination) 172.2.2.2 service any HTTP no-proxy-arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now while you are not going to ANY address as the original [the first set of brackets], you are able to do a subnet.&amp;nbsp; Since you said you wanted to do this so you didn't have to change client settings, then you obviously know what the address being used is.&amp;nbsp; Oh, the 1 after the "nat (Inside, Outside)" is the position of the NAT rule, so in your case, it may not be 1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 14:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779763#M495831</guid>
      <dc:creator>lance_brown</dc:creator>
      <dc:date>2011-10-18T14:32:37Z</dc:date>
    </item>
    <item>
      <title>Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779764#M495833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for this i will try &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 10:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779764#M495833</guid>
      <dc:creator>davcommunay</dc:creator>
      <dc:date>2011-10-24T10:27:52Z</dc:date>
    </item>
    <item>
      <title>Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779765#M495837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, this does not work at all &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# show version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.3(1) &lt;/P&gt;&lt;P&gt;Device Manager Version 6.3(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These commands where not sucessfull, and even if i try to modify them at least 12 times).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what i tried to do at first was redirecting all connections coming from my_computer to an IP called website going to port 80 being redirected to database on port mysql. OUF! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,any) source static my_computer my_computer destination static website database service http mysql&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;now if i try a telnet on the website on port 80 i should be redirected to database:3306 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet THE.IP.OF.WEBSITE 80&lt;/P&gt;&lt;P&gt;Trying THE.IP.OF.WEBSITE...&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And nothing more...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i check the logs during this time i can see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Bult outbound TCP connection 321212121 for outside:database_ip/3306 (website_ip/80) to inside:my_computer/50087 (mycomputer/50087)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now i am COMPLETELY lost &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Database IP is on INSIDE interface&lt;/P&gt;&lt;P&gt;2) website_IP is OUTSIDE (on the internet)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just trying to do DNAT but i can't figure out to find the solution..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 11:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779765#M495837</guid>
      <dc:creator>davcommunay</dc:creator>
      <dc:date>2011-10-24T11:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Redirecting all IP to a services on a different host</title>
      <link>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779766#M495840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have three options.&lt;/P&gt;&lt;P&gt;1) Use packet-tracer and see why it fails or if it does really pass.&lt;/P&gt;&lt;P&gt;2) Create the NAT using ASDM and let it figure out the syntax for you.&lt;/P&gt;&lt;P&gt;3) Use DNS as this is what it was designed for.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 17:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirecting-all-ip-to-a-services-on-a-different-host/m-p/1779766#M495840</guid>
      <dc:creator>lance_brown</dc:creator>
      <dc:date>2011-10-24T17:06:13Z</dc:date>
    </item>
  </channel>
</rss>

