<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: enable telnet redirection on the outside ASA Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928649#M941169</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;also use "interface outside" instead of the IP in your ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and make sure your firewall can ping the loopback IP's yo'ure trying to connect to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Mar 2008 19:41:17 GMT</pubDate>
    <dc:creator>srue</dc:creator>
    <dc:date>2008-03-11T19:41:17Z</dc:date>
    <item>
      <title>enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928647#M941165</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; I have &lt;/P&gt;&lt;P&gt;1- Firewall configure with outside IP 201.100.100.1&lt;/P&gt;&lt;P&gt;2- Router 1 with loop back 10.1.1.1 (inside network)&lt;/P&gt;&lt;P&gt;3- Router 2 with loop back 10.2.2.2 (inside network)&lt;/P&gt;&lt;P&gt;I configure the following on ASA&lt;/P&gt;&lt;P&gt; Static (inside,outside) tcp 201.100.100.1 1100 10.1.1.1 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 1200 201.100.100.1 1200 10.2.2.2 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;I configure outside access list which allow access from any to host 201.100.100.1 using ports 1100 &amp;amp; 1200.&lt;/P&gt;&lt;P&gt;I need to do telnet to outside to the inside routers using the same outside interface. This configuration is not work. When I tried the same configuration using different outside ip (not outside interface ip) it will work fine. So could you please advice how i can do this using the same outside ip address. This scenario was asked on Internetwork expert scenarios for CCIE labs but It didn't work with me.&lt;/P&gt;&lt;P&gt;Please advice if i miss something&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928647#M941165</guid>
      <dc:creator>abdullah-asi</dc:creator>
      <dc:date>2019-03-11T12:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928648#M941167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using the outside interface address for translation then use the word interface instead of the address in the static command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove:&lt;/P&gt;&lt;P&gt;no Static (inside,outside) tcp 201.100.100.1 1100 10.1.1.1 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add:&lt;/P&gt;&lt;P&gt;Static (inside,outside) tcp interface 1100 10.1.1.1 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928648#M941167</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-03-11T19:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928649#M941169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;also use "interface outside" instead of the IP in your ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and make sure your firewall can ping the loopback IP's yo'ure trying to connect to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:41:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928649#M941169</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-03-11T19:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928650#M941170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using interface in place of address should take care of his problem as he stated he was able to connect to the inside router using a different outside address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:49:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928650#M941170</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-03-11T19:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928651#M941171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks. It works for R1 which is located at inside but not for R2 which is located at DMZ!!!!!&lt;/P&gt;&lt;P&gt;ip applied the below commands:&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit tcp any interface outside eq 2223&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit tcp any interface outside eq 1123&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 1123 10.1.1.1 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 2223 10.1.2.2 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;telnet working for 10.1.1.1 but not for 10.1.2.2 while i can ping all of them &lt;/P&gt;&lt;P&gt;please advice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928651#M941171</guid>
      <dc:creator>abdullah-asi</dc:creator>
      <dc:date>2008-03-11T19:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928652#M941174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, and best practice is to also use "interface outside" in the acl, if you're using the IP of the interface for PAT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928652#M941174</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-03-11T19:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928653#M941176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no static (inside,outside) tcp interface 2223 10.1.2.2 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp interface 2223 10.1.2.2 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this assumes "dmz" is the name of your dmz interface (as defined w/ the nameif command)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928653#M941176</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-03-11T19:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928654#M941177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For DMZ reconfigure your static for translation between DMZ and outside address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,outside) tcp interface 2223 10.1.2.2 telnet netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just noticed Steven had responded to this post as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abdullah, if nat-control is enabled in the firewall nat rule is required between a pair of interfaces and that's the reason why you have to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928654#M941177</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-03-11T19:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: enable telnet redirection on the outside ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928655#M941179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks alot. Iam sitting from morning on lab.It seems i should leave it becasue i cannot distinguish between DMZ and inside now .lol. &lt;/P&gt;&lt;P&gt;thanks alot .it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 19:58:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-telnet-redirection-on-the-outside-asa-firewall/m-p/928655#M941179</guid>
      <dc:creator>abdullah-asi</dc:creator>
      <dc:date>2008-03-11T19:58:50Z</dc:date>
    </item>
  </channel>
</rss>

