<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Thats it: too stupid to configure port forwarding on IOS FW  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449189#M613810</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;some screenshots... i am totally lost &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Aug 2010 22:39:45 GMT</pubDate>
    <dc:creator>kmmehlkmmehl</dc:creator>
    <dc:date>2010-08-20T22:39:45Z</dc:date>
    <item>
      <title>Thats it: too stupid to configure port forwarding on IOS FW DMZ</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449185#M613806</link>
      <description>&lt;P&gt;Ok thats it. I am now 6 hours overtime in the office and i cannot get it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SG-BN001#sh zone security&lt;/P&gt;&lt;P&gt;zone self&lt;/P&gt;&lt;P&gt;&amp;nbsp; Description: System defined zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone out-zone&lt;/P&gt;&lt;P&gt;&amp;nbsp; Member Interfaces:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet0/1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet0/1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone in-zone&lt;/P&gt;&lt;P&gt;&amp;nbsp; Member Interfaces:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet0/0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet0/0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet0/0.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Virtual-Template1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLVPN-VIF0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone dmz-zone&lt;/P&gt;&lt;P&gt;&amp;nbsp; Member Interfaces:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet0/0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have in the DMZ a Server. I want to access Port 8080 and Port 8443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant get it to work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have some other servers in the DMZ working with port forwarding&lt;/P&gt;&lt;P&gt;I use CCP -&amp;gt; i create&amp;nbsp; rule on the OUT to DMZ Zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use an object group, add this server, create custom ports for it add them and... no it isnt working!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even when i allow IP for ALL DMZ Machine, i can only connect to port 8080. I never could connect ever to the second port the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it me? am i too stupid?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using 2800x with 12.4&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449185#M613806</guid>
      <dc:creator>kmmehlkmmehl</dc:creator>
      <dc:date>2019-03-11T18:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Thats it: too stupid to configure port forwarding on IOS FW</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449186#M613807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your NAT config look ok? for port 8443 to this server in the dmz.&lt;/P&gt;&lt;P&gt;Unfortunatley is section of the config that you posted is not enough to find out what might be going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;issue&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;ip inspect log drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then try the connection and see what the logs says.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 21:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449186#M613807</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-20T21:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Thats it: too stupid to configure port forwarding on IOS FW</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449187#M613808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm i did but my connection doesnt show up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;well i just added IP to inspect ANY ANY on the OUT - TO - DMZ ZONE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then 8080 is working&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8443 not&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i cant understand this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my dmz interfaces are NAT INSIDE&lt;/P&gt;&lt;P&gt;but removing NAT doesnt change anything&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 22:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449187#M613808</guid>
      <dc:creator>kmmehlkmmehl</dc:creator>
      <dc:date>2010-08-20T22:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Thats it: too stupid to configure port forwarding on IOS FW</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449188#M613809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what does your "sh run | i nat" output look like?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have translation for 8443?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 22:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449188#M613809</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-20T22:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Thats it: too stupid to configure port forwarding on IOS FW</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449189#M613810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;some screenshots... i am totally lost &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 22:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449189#M613810</guid>
      <dc:creator>kmmehlkmmehl</dc:creator>
      <dc:date>2010-08-20T22:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Thats it: too stupid to configure port forwarding on IOS FW</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449190#M613811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no translation. also when i try 8081 8082 etc this is ALSO not working!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8080 is the only one that works..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 22:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449190#M613811</guid>
      <dc:creator>kmmehlkmmehl</dc:creator>
      <dc:date>2010-08-20T22:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Thats it: too stupid to configure port forwarding on IOS FW</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449191#M613812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you sure this works internally? Meaning if you load the page from the inside or on a compuer on the dmz does it work? I just want to make sure that the dmz host is listening on these ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://x.x.xx:8443"&gt;http://x.x.xx:8443&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://x.x.xx:8081"&gt;http://x.x.xx:8081&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://x.x.xx:8082"&gt;http://x.x.xx:8082&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Aug 2010 23:36:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449191#M613812</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-21T23:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Thats it: too stupid to configure port forwarding on IOS FW</title>
      <link>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449192#M613813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well thanks for your help kusan..... actually i fixed it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THe Problem was i think that there was no access-group on the interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i made access lists ip any any and applied them to the interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AFTER THAT everything worked like i configured it in CCP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have no idea why.. but now its working!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Aug 2010 15:20:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/thats-it-too-stupid-to-configure-port-forwarding-on-ios-fw-dmz/m-p/1449192#M613813</guid>
      <dc:creator>kmmehlkmmehl</dc:creator>
      <dc:date>2010-08-22T15:20:14Z</dc:date>
    </item>
  </channel>
</rss>

