<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 9.9 Port forward problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3384042#M957884</link>
    <description>&lt;P&gt;Couple things before we dive into your issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;1. Update your original post and hide the public IP you're using for the&amp;nbsp;&lt;SPAN&gt;object network SSH-pi-ext-ip&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;2. With ASA using port 22 on the outside interface it might happen that you cannot use it for a port-forward as you need. I am not 100% it's not possible, some tricks might help but I would just use any other external port like 2222 and map it to my internal server on port 22.&lt;/P&gt;
&lt;P&gt;Here's PF config as I see it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network SSH-pi-ext-ip&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;host x.x.x.220&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network SSH-pi&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;host 10.10.50.65&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group service ssh_2222 tcp&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;port-object eq 2222&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group service&amp;nbsp;ssh_22 tcp&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;port-object eq 22&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;nat (outside,inside) after-auto source static any any destination static SSH-pi-ext-ip object network SSH-p service ssh_2222 ssh_22 unidirectional&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 May 2018 09:25:19 GMT</pubDate>
    <dc:creator>Florin Barhala</dc:creator>
    <dc:date>2018-05-16T09:25:19Z</dc:date>
    <item>
      <title>ASA 9.9 Port forward problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3383998#M957883</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I cannot get this to work.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What I want to do.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Host on Internet (any) --&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;FW (xx.xx.24.220:22) --&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;SSH-pi (10.10.50.65:22)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Host on&amp;nbsp;internet connects with&amp;nbsp;ssh to&amp;nbsp;FW port tcp/22 and&amp;nbsp;&amp;nbsp;will then be forwarded to SSH-pi on port tcp/22.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet1/1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;nameif outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;security-level 0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip address dhcp setroute &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;(DHCP ip = xx.xx.24.220)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet1/8.5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;vlan 5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;nameif FW-VL5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;security-level 100&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip address 10.10.50.1 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SSH-pi-ext-ip&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;host 77.53.24.220&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SSH-pi&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;host 10.10.50.65&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list outside_access_in extended permit tcp any object SSH-pi-ext-ip eq ssh log notifications&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network obj_any&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;nat (any,outside) dynamic interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network SSH-pi&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;nat (FW-VL5,outside) dynamic interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-group outside_access_in in interface outside&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3383998#M957883</guid>
      <dc:creator>pwanderoy</dc:creator>
      <dc:date>2020-02-21T15:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.9 Port forward problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3384042#M957884</link>
      <description>&lt;P&gt;Couple things before we dive into your issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;1. Update your original post and hide the public IP you're using for the&amp;nbsp;&lt;SPAN&gt;object network SSH-pi-ext-ip&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;2. With ASA using port 22 on the outside interface it might happen that you cannot use it for a port-forward as you need. I am not 100% it's not possible, some tricks might help but I would just use any other external port like 2222 and map it to my internal server on port 22.&lt;/P&gt;
&lt;P&gt;Here's PF config as I see it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network SSH-pi-ext-ip&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;host x.x.x.220&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object network SSH-pi&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;host 10.10.50.65&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group service ssh_2222 tcp&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;port-object eq 2222&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;object-group service&amp;nbsp;ssh_22 tcp&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;port-object eq 22&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;nat (outside,inside) after-auto source static any any destination static SSH-pi-ext-ip object network SSH-p service ssh_2222 ssh_22 unidirectional&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 09:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3384042#M957884</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-16T09:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.9 Port forward problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3384043#M957885</link>
      <description>&lt;P&gt;your NAT is wrong for port 22, you need to nat the outside ntercface on port 22 to inside pi 22, from outside to inside&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 09:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3384043#M957885</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-05-16T09:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.9 Port forward problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3384048#M957886</link>
      <description>Out of curiosity, what happens with this DNAT on 22 if the user adds:&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside</description>
      <pubDate>Wed, 16 May 2018 09:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-9-port-forward-problem/m-p/3384048#M957886</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-16T09:34:36Z</dc:date>
    </item>
  </channel>
</rss>

