<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port forwarding Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080915#M913768</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure if you cn create a custom inspect or not (certainly would make sense that you can), but you could also use FTP inspection and change the inspection to port 5858. Here's a link on how to do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807ee585.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807ee585.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Aug 2008 14:21:27 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2008-08-29T14:21:27Z</dc:date>
    <item>
      <title>Port forwarding Issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080914#M913767</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a customer who purchased a GE IP Camera / DVR for one of their remote sites and we're having problems accessing it from behind our ASA 5520s 7.2(4).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I've discovered is that when any user connects to the DVR's external IP, the webpage loads and then the DVR creates a seperate inbound connection on port 5858 (TCP or UDP are selectable)which carries the video stream.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outbound users are PAT'd to a single external IP, so as you can see... we have an issue.&lt;/P&gt;&lt;P&gt;GE is saying that port 5858 needs to be forwarded, but I don't see the feasibility of this in an environment where there are multiple users that would need this port forwarded without assigning them a static external IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an inspect statement I can enter to make this work? This scenario is very similar to how a PPTP VPN works... TCP connection on port 1723 and then the server initiates an inbound GRE tunnel, The "inspect PPTP" command allows this to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've found the connection will work if I statically map a host to an external IP and then put an explicit ACL statement in allowing the DVR IP to the external IP on TCP port 5858.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can I do at this point to make it work? Can I create a custom "Inspect"? The IP of the DVR is static if that makes any difference.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080914#M913767</guid>
      <dc:creator>rtjensen4</dc:creator>
      <dc:date>2019-03-11T13:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding Issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080915#M913768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure if you cn create a custom inspect or not (certainly would make sense that you can), but you could also use FTP inspection and change the inspection to port 5858. Here's a link on how to do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807ee585.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807ee585.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 14:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080915#M913768</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-08-29T14:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding Issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080916#M913770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. We are already using the FTP inspection with it's default settings. Is it possible to create another "Instance" of it? Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 14:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080916#M913770</guid>
      <dc:creator>rtjensen4</dc:creator>
      <dc:date>2008-08-29T14:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Port forwarding Issue</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080917#M913772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can. See the above link from collin_clark and scroll down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure FTP protocol inspection on non standard TCP port &lt;/P&gt;&lt;P&gt;You can configure the FTP Protocol Inspection for non standard TCP ports with these configuration lines (replace XXXX with the new port number):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ftp-list extended permit tcp any any eq XXXX&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map ftp-class&lt;/P&gt;&lt;P&gt;  match access-list ftp-list&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;  class ftp-class&lt;/P&gt;&lt;P&gt;   inspect ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Sep 2008 11:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-issue/m-p/1080917#M913772</guid>
      <dc:creator>ofwegen</dc:creator>
      <dc:date>2008-09-03T11:56:48Z</dc:date>
    </item>
  </channel>
</rss>

