<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwading port 8008 to an webserver in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455440#M708448</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have added the lines at the router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.17.0 0.0.0.255&lt;/FA0&gt;&lt;/FA0&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the remote site witch configuration do I need?&lt;/P&gt;&lt;P&gt;info the access-list also 170!&lt;/P&gt;&lt;P&gt;1.?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.17.0 0.0.0.255&lt;/FA0&gt;&lt;/FA0&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or 2.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address from the main router&lt;/EM&gt;&amp;gt; 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address&amp;nbsp; from the main router&lt;/EM&gt;&amp;gt; 192.168.17.0 0.0.0.255&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or 3.?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address from the main router&lt;/EM&gt;&amp;gt; 192.168.1.0 0.0.255.255 - IPs from the main site?&lt;BR /&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address&amp;nbsp; from the main router&lt;/EM&gt;&amp;gt; 192.168.16.0 0.0.0.255 - IPs from the main site?&lt;BR /&gt;--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or 4.?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.1.0 0.0.255.255 - IPs from the main site?&lt;BR /&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.16.0 0.0.0.255 - IPs from the main site?&lt;BR /&gt;--&lt;/FA0&gt;&lt;/FA0&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Sep 2010 12:28:35 GMT</pubDate>
    <dc:creator>it-interschalt</dc:creator>
    <dc:date>2010-09-07T12:28:35Z</dc:date>
    <item>
      <title>forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455432#M708432</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use some cisco 2811 router and I have forward some websites witch will be use via port 8008 but it dos not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try it with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.1.24 8008 interface FastEthernet0/1 8008&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can someone tell me what is wrong? and maybe can someone tell me how can I debug the traffic with should pass port 8008?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455432#M708432</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2019-03-11T18:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455433#M708434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume that fa0/1 is the external interface (pls make sure that you configured "ip nat outside"), and the interface of 192.168.1.x subnet has "ip nat inside" configured. Also, do you have access-list configured on the external interface? if you do, you would need to allow traffic to fa0/1 interface on port 8008.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the config if the above has been checked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 10:30:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455433#M708434</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-21T10:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455434#M708436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello halijenn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for your anwser - and sorry for delay!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the moment the port 8008 is doing fine but only if I try to reach the server via port 8008 from the internet. If I try to reach them from a ather site office it doese not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the access-list allows all trafic from the site office (connected via VPN), and I can ping the server and I can also connect them via share.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can it be that the ip nat inside source static tcp 192.168.1.24 8008 interface FastEthernet0/1 8008 is only for connection from the internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes! - what can I do that we can connect the server from our site office?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best wishes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 06:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455434#M708436</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-09-01T06:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455435#M708438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are right. Those are for the internet because on VPN you normally do not specify the public subnet/ip address in the crypto ACL.&lt;/P&gt;&lt;P&gt;You would need to add crypto ACL for your VPN tunnel between the&amp;nbsp; FastEthernet0/1 interface IP towards&amp;nbsp; remote LAN and vice versa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 06:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455435#M708438</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-01T06:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455436#M708440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can I add a crypto ACL - sorry for this question but I'm not so firm in configuring spezial thinks at the cisco router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have an short how to for me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best wishes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 07:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455436#M708440</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-09-01T07:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455437#M708442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the specific vpn configuration and the corresponding crypto ACL?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Sep 2010 01:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455437#M708442</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-02T01:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455438#M708444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello halijenn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I have the right thing's you like to know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;crypto map SDM_CMAP_1 4 ipsec-isakmp &lt;BR /&gt; set peer &lt;EM&gt;public IP&lt;/EM&gt;&lt;BR /&gt; set transform-set ESP-AES-256-SHA &lt;BR /&gt; match address 170&lt;BR /&gt; &lt;BR /&gt;access-list 170 permit ip 192.168.16.0 0.0.0.255 192.168.17.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.16.0 0.0.0.255 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.255.255 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.255.255 192.168.17.0 0.0.0.255&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need any more - please let me know that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best wishes&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 05:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455438#M708444</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-09-07T05:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455439#M708446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what you would need to add:&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.17.0 0.0.0.255&lt;/FA0&gt;&lt;/FA0&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would also need to configure mirror image ACL on the other side of the VPN tunnel device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455439#M708446</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-07T11:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455440#M708448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have added the lines at the router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.17.0 0.0.0.255&lt;/FA0&gt;&lt;/FA0&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the remote site witch configuration do I need?&lt;/P&gt;&lt;P&gt;info the access-list also 170!&lt;/P&gt;&lt;P&gt;1.?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.17.0 0.0.0.255&lt;/FA0&gt;&lt;/FA0&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or 2.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address from the main router&lt;/EM&gt;&amp;gt; 192.168.2.0 0.0.255.255&lt;BR /&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address&amp;nbsp; from the main router&lt;/EM&gt;&amp;gt; 192.168.17.0 0.0.0.255&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or 3.?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address from the main router&lt;/EM&gt;&amp;gt; 192.168.1.0 0.0.255.255 - IPs from the main site?&lt;BR /&gt;access-list 170 permit ip host &amp;lt;&lt;EM&gt;fa0/1 interface ip address&amp;nbsp; from the main router&lt;/EM&gt;&amp;gt; 192.168.16.0 0.0.0.255 - IPs from the main site?&lt;BR /&gt;--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or 4.?&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.1.0 0.0.255.255 - IPs from the main site?&lt;BR /&gt;access-list 170 permit ip host &lt;FA0&gt; 192.168.16.0 0.0.0.255 - IPs from the main site?&lt;BR /&gt;--&lt;/FA0&gt;&lt;/FA0&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455440#M708448</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-09-07T12:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455441#M708450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the remote site, you would need to configure mirror image ACL as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list 170 permit ip &lt;/EM&gt;&lt;EM&gt;192.168.2.0 0.0.255.255 &lt;/EM&gt;&lt;EM&gt;host &lt;FA0&gt;&lt;BR /&gt;access-list 170 permit ip &lt;/FA0&gt;&lt;/EM&gt;&lt;EM&gt;192.168.17.0 0.0.0.255 &lt;/EM&gt;&lt;EM&gt;host &lt;FA0&gt;&lt;/FA0&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to also clear the IPSEC SA on both ends after the configuration (clear cry sa).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455441#M708450</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-07T12:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455442#M708451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so here are the actual access lists fron the running config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site 1 (main were the porp 8008 should be reachable)&lt;BR /&gt;access-list 170 permit ip 192.168.16.0 0.0.0.255 192.168.17.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.0.255 192.168.17.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip host 192.168.16.1 192.168.17.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip host 192.168.16.1 192.168.2.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site 2 (remote were I try to connect form via port 8008)&lt;BR /&gt;access-list 170 permit ip 192.168.17.0 0.0.0.255 192.168.16.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.2.0 0.0.0.255 192.168.16.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.17.0 0.0.0.255 192.168.1.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.17.0 0.0.0.255 host 192.168.16.1&lt;BR /&gt;access-list 170 permit ip 192.168.2.0 0.0.0.255 host 192.168.16.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and this is not working!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what did I do wrong?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455442#M708451</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-09-07T12:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455443#M708452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume that fa0/1 should be a public IP Address, right? since you have configured port forwarding for that via the NAT statement:&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.1.24 8008 interface FastEthernet0/1 8008&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the output of:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run int fa0/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this webserver accessible from the Internet?&lt;/P&gt;&lt;P&gt;I assume that you would like access to the webserver from both the Internet as well as the VPN, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 13:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455443#M708452</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-07T13:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455444#M708453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you are right!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the fa0/1 is public - sorry I din't read correctly&lt;/P&gt;&lt;P&gt;and I like to connect the webserver from both sites (Internet andVPN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I correct the mistake but it din't work again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the webserver . I can reach a website (port 80) but I can't reach the website witch scould be reachable via Port 8008&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 06:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455444#M708453</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-09-08T06:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455445#M708454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it working from the internet and failing from the VPN? or it's not working from both VPN and Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's not working from the VPN, can you please make sure that you have exactly the mirror image ACL on both sides, and have also clear the crypto tunnels (clear crypto sa).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 06:38:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455445#M708454</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-08T06:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455446#M708455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it is working from the internet - and do not work from the vpn site&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my actual config are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site 1 (main were the porp 8008 should be reachable)&lt;BR /&gt;access-list 170 permit ip 192.168.16.0 0.0.0.255 192.168.17.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.1.0 0.0.0.255 192.168.17.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip host&lt;STRONG&gt; public IP from this router&lt;/STRONG&gt; 192.168.17.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip host &lt;STRONG&gt;public IP from this router&lt;/STRONG&gt; 192.168.2.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site 2 (remote were I try to connect form via port 8008)&lt;BR /&gt;access-list 170 permit ip 192.168.17.0 0.0.0.255 192.168.16.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.2.0 0.0.0.255 192.168.16.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.17.0 0.0.0.255 192.168.1.0 0.0.0.255&lt;BR /&gt;access-list 170 permit ip 192.168.17.0 0.0.0.255 host &lt;STRONG&gt;public IP from the router Site 1&lt;/STRONG&gt;&lt;BR /&gt;access-list 170 permit ip 192.168.2.0 0.0.0.255 host &lt;STRONG&gt;public IP from the router Site 1,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and now I send the command clear &lt;STRONG&gt;crypto sa&lt;/STRONG&gt; at both router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the website is corrently still not reachable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 06:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455446#M708455</guid>
      <dc:creator>it-interschalt</dc:creator>
      <dc:date>2010-09-08T06:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455447#M708456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you share the output of "show cry ipsec sa" from both routers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 06:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455447#M708456</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-08T06:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: forwading port 8008 to an webserver</title>
      <link>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455448#M708457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;and also, you might want to check the NAT exemption on the remote router.&lt;/P&gt;&lt;P&gt;Can you share the NAT statement, and the corresponding ACL on the remote router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 06:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/forwading-port-8008-to-an-webserver/m-p/1455448#M708457</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-08T06:59:19Z</dc:date>
    </item>
  </channel>
</rss>

