<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Redirection issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572571#M615563</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because they wanted to do port redirection for 8000 to 80.&amp;nbsp; Normally I would just do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside, outside) 1.1.1.2 10.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then write an ACL allowing port access to 1.1.1.2 and apply it to the outside interface.&amp;nbsp; I couldn't do that because I need a port redirection NAT statement of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 8000 10.1.1.1 80 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't write:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside, outside) 1.1.1.2 10.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 8000 10.1.1.1 80 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;because it will give me an error, won't it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Dec 2010 16:01:27 GMT</pubDate>
    <dc:creator>qbakies11</dc:creator>
    <dc:date>2010-12-03T16:01:27Z</dc:date>
    <item>
      <title>Port Redirection issue</title>
      <link>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572567#M615556</link>
      <description>&lt;P&gt;I have a client who wants to make changes to a PIX 501.&amp;nbsp; They have a single server exposed to the world and want to have specific traffic sent to it.&amp;nbsp; I was going to set up static NAT for the server and then create a simple ACL to allow the ports they want but then they stated they wanted to do port redirection also.&amp;nbsp; So this is my issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.1.1.2=external IP&lt;/P&gt;&lt;P&gt;10.1.1.1=internal IP&lt;/P&gt;&lt;P&gt;Allow ports 443, 3389, 9090, 1010, and 80&lt;/P&gt;&lt;P&gt;Also, redirect traffic from 8000 to 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created port forwarding NAT statements:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 443 10.1.1.1 443 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) tcp 1.1.1.2 9090 10.1.1.1 9090 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 1010 10.1.1.1 1010 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 3389 10.1.1.1 3389 netmask 255.255.255.255 0 0 &lt;BR /&gt;static (inside,outside) tcp 1.1.1.2 8000 10.1.1.1 www netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I try to do 'static (inside,outside) tcp 1.1.1.2 80 10.1.1.1 80 netmask 255.255.255.255 0 0' i GET:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: duplicate of existing static&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp from inside:10.1.1.1/80 to outside:1.1.1.2/8000 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I allow port 80 traffic to 10.1.1.1 and redirect 8000 to 80 for the same server?&amp;nbsp; Is this even possible?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572567#M615556</guid>
      <dc:creator>qbakies11</dc:creator>
      <dc:date>2019-03-11T19:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Port Redirection issue</title>
      <link>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572568#M615558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I'm not mistaken you cannot do this unless you're running 8.3 (ASA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason it wont' work is because the PIX can redirect the traffic to the internal server but when the reply comes back it has no way of knowing which of the two static statements to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;static (inside,outside) tcp 1.1.1.2 8000 10.1.1.1 www netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 80 10.1.1.1 80 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When traffic comes from source IP 10.1.1.1 and source port 80, the PIX has no way of knowing which statement to use for outbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2010 15:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572568#M615558</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-03T15:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: Port Redirection issue</title>
      <link>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572569#M615559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So there is no way for me to make this work?&amp;nbsp; If they want port 80 open they have to have it mapped to only one port (80 or 8000)?&amp;nbsp; How can this be done on ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2010 15:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572569#M615559</guid>
      <dc:creator>qbakies11</dc:creator>
      <dc:date>2010-12-03T15:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Port Redirection issue</title>
      <link>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572570#M615561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the static statements above uses the same mapped IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using that IP for something else? I mean what prevents you from replacing the above statements for this one:&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.2 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2010 15:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572570#M615561</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-03T15:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Port Redirection issue</title>
      <link>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572571#M615563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because they wanted to do port redirection for 8000 to 80.&amp;nbsp; Normally I would just do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside, outside) 1.1.1.2 10.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then write an ACL allowing port access to 1.1.1.2 and apply it to the outside interface.&amp;nbsp; I couldn't do that because I need a port redirection NAT statement of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 8000 10.1.1.1 80 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't write:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside, outside) 1.1.1.2 10.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1.1.1.2 8000 10.1.1.1 80 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;because it will give me an error, won't it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2010 16:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572571#M615563</guid>
      <dc:creator>qbakies11</dc:creator>
      <dc:date>2010-12-03T16:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Port Redirection issue</title>
      <link>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572572#M615564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you cannot do that unless you run 8.3 because it won't allow the mapping of the same combination (internal IP/internal port) with different port redirection statements.&lt;/P&gt;&lt;P&gt;I will try some tests and get back to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2010 16:21:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-redirection-issue/m-p/1572572#M615564</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-12-03T16:21:38Z</dc:date>
    </item>
  </channel>
</rss>

