cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6566
Views
0
Helpful
29
Replies

Allowing External Traffic on Cisco ASA

jweier_elys
Beginner
Beginner

Hi - I have a Cisco ASA and I'm really struggling with something very simple. I have an outside interface and I would like to allow traffic to hit the outside interface on TCP Port 81 and get NAT'd to a private IP on a webserver. I believe I have the NAT piece of the equation solved but the ACL is processed first and I can't figure out the ACL for the life of me. Here's what I have:

 

On the outside interface, I created an incoming rule with any source, any destination and a service of TCP Port 81. However, when I run a Packet Tracer from any public IP to the IP of the outside interface on Port 81 the packet is dropped via an implicit rule. 

 

I'm running ASA 9.9, thoughts?PacketTracer.png

 

Rule.pngInterfaces.pngPacketTracer.png

29 Replies 29

can you test this.

 

object network SERVER
 host 10.1.1.79
!
nat (inside,outside) 1 source static SERVER interface service Port80 Port81

!

no access-list outside_access_in extended permit tcp any host 10.1.1.79 range 81 81
no nat (inside,outside) source static any interface service Port80 Port81

!

access-list outside_access_in extended permit tcp any object SERVER eq 80

access-group outside_access_in in interface outside

!

 

(OR)

as i stated in my earlier post

object network SERVER
 host 10.1.1.79
 nat (inside,outside) static interface service tcp 80 81
!
access-list outside_in permit tcp any host 10.1.1.79 eq 80
access-group outside_in in interface outside

!

no access-list outside_access_in extended permit tcp any host 10.1.1.79 range 81 81
no nat (inside,outside) source static any interface service Port80 Port81

please do not forget to rate.

 

object network SERVER
 host 10.1.1.79
!
nat (inside,outside) 1 source static SERVER interface service Port80 Port81

!

no access-list outside_access_in extended permit tcp any host 10.1.1.79 range 81 81
no nat (inside,outside) source static any interface service Port80 Port81

 

 

Apply these config as mentioned above it will work

please do not forget to rate.