cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1072
Views
0
Helpful
1
Replies

NAT on FPR-1010 using ASA Image

Timothy Patrick
Level 1
Level 1

Hello, I am trying to figure out why NATing with certain ports on the ASA is failing. It seems when I try to NAT ports 22 or 443 on the inside of my network I do not get successful connections but if I take and modify the NAT to a different port that typically does expect encrypted traffic it works

 

Here I am NATing an internal host to my outside internet IP address

 

OUTSIDE x.x.x.x:8000 <-> x.x.x.x:22 INSIDE

TimothyPatrick_0-1631057085714.jpeg

 

I am using a basic python web server listening on port 22Port 22Port 22

 

When I try to connect, I see the session being built but then see SYS timeouts shortly after.

05_10_11.jpg

If I change the internal port from 22 to 8422 or any non-encrypted port it works with no issues. 

05_10_22.jpg

Port 8422Port 8422

 

I  am using the same python webserver for each test only changing what port it's listening on.

 

Any ideas on why this would be happening? The external port never changes only the internal port. Any help would be appreciated 

 

1 Accepted Solution

Accepted Solutions

Timothy Patrick
Level 1
Level 1

Sorry guys it turned out to be an access-list on an upstream router blocking ports 443 and 22.

View solution in original post

1 Reply 1

Timothy Patrick
Level 1
Level 1

Sorry guys it turned out to be an access-list on an upstream router blocking ports 443 and 22.

Review Cisco Networking for a $25 gift card