cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1345
Views
0
Helpful
1
Replies

ASA 5505 SIP trunk NAT configuration from only one outside public IP of SIP provider

blaz.zupanc
Level 1
Level 1

Hi :-)

 

I am new to cisco network devices and i need a little help. I would like to configure my asa to NAT SIP traffic from my PBX provider. I would like to do it very tight, so that only SIP connection from my PBX provider will be allowed to get trough to my trixbox server.

I use these ports :

5060

5036

and range for RTP from 10000:20000

 

asa os is at version 7.2(3) 

 

Please advise me what would be the right rules for this to function ?

 

Thank you 

1 Reply 1

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

I would recommend you to use a Static NAT i.e. map all the ports for the Public Adrress to the internal PBX and then restrict the ports as per your requirement using the ACL.

Refer:-

http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/inspect.html#wp1204403

http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/cfgnat.html

Thanks and Regards,

Vibhor Amrodia

Review Cisco Networking for a $25 gift card