cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
557
Views
0
Helpful
1
Replies

Question regarding object service source and object service destination.

mdr.ahamedb
Community Member

Hi All,

 

In have a question regarding object service source and object service destination.

 

We are trying to configure port re-direction in ASA 9.2 i.e outside port will be 4032 and actually service will be running port 1433.

When the user hits on port 4032 it should get re-directed to 1433. If I am not wrong the below syntax should be correct.

 

Now I am confused regarding the object service source and object service destination.

In the below config it is mentioned as object service source. Will the below config works for bi-directional as well or it will work only for SQL_ASP->LL

 

Want to know how exactly it works, when do we use object service source and object service destination.

 

object-group network remote-replication-hosts

  host 1.1.1.12

  host 1.1.1.13

 

object service sql_1433

service tcp source eq 1433

 

object service sql_4032

service tcp source eq 4032

exit

 

nat (SQL_ASP,LL) source static obj-10.0.5.1 obj-10.1.8.2 destination static remote-replication-hosts remote-replication-hosts service sql_1433 sql_4032

 

access-list LL extended permit tcp host 1.1.1.12 host obj-10.1.8.2 eq 1433

 

Thanks in Advance..............

1 Accepted Solution

Accepted Solutions

joseoroz
Cisco Employee
Cisco Employee

Hello  

On the rule that you included you are doing NAT for the source and destination. If you want to do a normal port forwarding and just do the port redirection to a different port you don't require to NAT the source. 

nat (SQL_ASP,LL) source static Private_IP Public_IP  service  sql_1433 sql_4032 

If you need to hide the source with another IP then the rule that you created should accomplish both task at once. 

Once you have the configuration in you can use the show xlate | i x.x.x.x to see the port assignment and confirm that the ports and IP's are on the correct place. 

Kind regards,

Jose Orozco.

View solution in original post

1 Reply 1

joseoroz
Cisco Employee
Cisco Employee

Hello  

On the rule that you included you are doing NAT for the source and destination. If you want to do a normal port forwarding and just do the port redirection to a different port you don't require to NAT the source. 

nat (SQL_ASP,LL) source static Private_IP Public_IP  service  sql_1433 sql_4032 

If you need to hide the source with another IP then the rule that you created should accomplish both task at once. 

Once you have the configuration in you can use the show xlate | i x.x.x.x to see the port assignment and confirm that the ports and IP's are on the correct place. 

Kind regards,

Jose Orozco.

Review Cisco Networking for a $25 gift card