cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1301
Views
0
Helpful
10
Replies
Highlighted
Beginner

Help with Port Forwarding from Outside Address

Can someone point me to info on port forwarding from an external address to an internal address. This firewall has a DMZ, but the machine I want to port forward to does not sit in the DMZ. All attempts to solve have lead to my machines in the DMZ not working.

Everyone's tags (2)
2 ACCEPTED SOLUTIONS

Accepted Solutions
Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Hi,

Be aware that an ACL must allow the traffic comes from Internet to DMZ servers.

Br,

View solution in original post

Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Ok, have you already checked all ACLs for inside and outside directions?

View solution in original post

10 REPLIES 10
Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Hi,

Try this command below:

static (inside,outside) tcp 1.1.1.1 www 2.2.2.2 www netmask 255.255.255.255

where 1.1.1.1 = it is your public ip address and 2.2.2.2 it is your internal one ( RFC 1918 ). In this example, the firewall is performing a static PAT for HTTP service. In this case, the reachable ip address for the Internet will be 2.2.2.2

Br,

Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Sorry, the ip will be 1.1.1.1 to be reachable by Internet

Highlighted
Beginner

Re: Help with Port Forwarding from Outside Address

So are you saying:

static (inside,outside) tcp External-IP www Internal-IP www netmask 255.255.255.255

Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

That's correct.

Br

Highlighted
Beginner

Re: Help with Port Forwarding from Outside Address

Thanks for the reply, but it didn't work.

Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Hi,

Be aware that an ACL must allow the traffic comes from Internet to DMZ servers.

Br,

View solution in original post

Highlighted
Beginner

Re: Help with Port Forwarding from Outside Address

Yes,  realize that. But, this is not a DMZ host, it is one that sits on the inside network.

Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Ok, have you already checked all ACLs for inside and outside directions?

View solution in original post

Highlighted
Beginner

Re: Help with Port Forwarding from Outside Address

Got it. I added:

access-list Inside_access_out extended permit tcp any host 192.168.14.252 eq www

access-list Inside_access_out extended permit tcp host 192.168.14.252 eq www any

and everything finally worked.

Thanks again for your help.

Chuck

Highlighted
Cisco Employee

Re: Help with Port Forwarding from Outside Address

You are welcome.

Best regards,

Renato Saraiva