11-21-2019 03:59 AM - edited 02-21-2020 09:42 AM
Hi Experts,
We've a requirement of rules to be allowed for penetration testing from Outside Public IP to scan all entire Internal networks on port 'any'.
Typically, we've seen PAT from Inside to Outside, is there any configuration to be done to accomplish this..?. if yes, could you please give overview on NAT and Access rules...
Thanks for your time and support
Source: 1.1.1.1 (For example)
Destination: 10.0.0.0/8 and 192.168.0.0/24
Port: Any
11-21-2019 04:39 AM
11-22-2019 06:03 AM
Hi Thanks RJI for the reply. Since they are non-domain users, is there anything we need to configure extra @ firewall or AD level...?
11-22-2019 06:36 AM
Well if you provide them remote access, you would need to configure anyconnect remote access vpn on the ASA/FTD, example here. You could just create them an AD account to authenticate to the VPN.
HTH
11-21-2019 08:26 AM
the requirement isnt too smart, if this is only for pentest, you could allow vpn access to those internal networks, if you dont have the license to deploy anyconnect, you could request trial ones from cisco.com/go/license.
regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide