10-21-2012 09:02 AM - edited 03-11-2019 05:12 PM
ASA5505 port 3306
I have been fighting for days to open the port 3306 on my appliance, I have read carefully all the forums and no success.
I allways get the message :
7 | Oct 21 2012 | 17:29:32 | 90.27.181.120 | 54655 | 212.147.49.18 | 3306 | TCP request discarded from 90.27.181.120/54655 to outside:212.147.49.18/3306 |
I have attached m y configuration
thanks for any help
Solved! Go to Solution.
10-23-2012 09:30 AM
Hello Jean,
Just checked the config, the problem is that you did not follow the object service configuration I sent you.
Mine:
object service SQL
service tcp source eq 3306
Yours:
object service SQL
service tcp destination eq 3306
Please change that and let me know,
Remember to rate all of the helpful posts, that is as important as a thanks for the community ( if you need to know how to rate a post, just let me know, I will be more than glad to let you know )
10-21-2012 12:03 PM
Hello Jean,
Okay lets say the SQL server is 192.168.10.10
so please configure the following
object network Inside_server
host 192.168.10.10
object service SQL
service tcp source eq 3306
nat (inside,outside) 2 source static Inside_server interface service SQL SQL
access-list outside_access_in permit tcp any host 192.168.10.10 31 3306
packet-tracer input outside tcp 4.2.2.2 1025 212.147.49.18 3306
Let me know, if this does not work please post the configuration updated
10-22-2012 08:22 AM
10-22-2012 09:57 AM
Missing the outside acl
access-group outside_access_in in interface outside
Regards
10-22-2012 11:15 AM
added the line, same problem
regards
10-22-2012 11:29 AM
Packet-tracer please ( the complete output)
10-23-2012 03:58 AM
10-23-2012 09:30 AM
Hello Jean,
Just checked the config, the problem is that you did not follow the object service configuration I sent you.
Mine:
object service SQL
service tcp source eq 3306
Yours:
object service SQL
service tcp destination eq 3306
Please change that and let me know,
Remember to rate all of the helpful posts, that is as important as a thanks for the community ( if you need to know how to rate a post, just let me know, I will be more than glad to let you know )
10-25-2012 06:19 AM
hello,
I changed the object as mentionned, the packet tracer is now allowing the flow. I will conductreal tests.
thanks a lot for your help.
please tell me how to rate the post
10-25-2012 09:56 AM
Hello Jean,
It should be working now We finally did it
Now in order to rate a post, go to each of my replies and mark or select the 5 stars at the bottom of each reply,
Regards,
Julio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide