cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
679
Views
0
Helpful
1
Replies

NAT and perimeter firewall

Network Pro
Level 1
Level 1

Hi,

I am trying to access my work network on ports 5246 and ports 5247 but cant seem to.

this is the setup

AP (5246, 5247) -----Internet-------ISP router---permiter firewall----internal firewall

I have nat'd a static ip on my firewall to a internal address and nat'd the internal address to the internal address on the Internal firewall. so

66.11.22.33 Nat'd 192.168.10.1  ----Permter firewall

192.168.10.1 Nat'd 192.168.10.1 --- Internal Firewall

i have a statc route of 192.168.10.x subnet to the inside of hte perimiter (this is directlu connected to the internal firewall). I have ACL to allow 5246 and 5247 on both internal and perimeter firewall.

when i do sh nat on permiter firewall, i can see untranslated hits on permiter firewall for the ports 5246 (which is what its supposed to use) but translated hits is 0.

This setup has been used for a another port and that seems to work fine

so any thoughs on this ?

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello,

Is this an ASA?

Regards,

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking products for a $25 gift card