08-18-2015 05:18 AM - edited 03-11-2019 11:26 PM
Hi All,
In have a question regarding object service source and object service destination.
We are trying to configure port re-direction in ASA 9.2 i.e outside port will be 4032 and actually service will be running port 1433.
When the user hits on port 4032 it should get re-directed to 1433. If I am not wrong the below syntax should be correct.
Now I am confused regarding the object service source and object service destination.
In the below config it is mentioned as object service source. Will the below config works for bi-directional as well or it will work only for SQL_ASP->LL
Want to know how exactly it works, when do we use object service source and object service destination.
object-group network remote-replication-hosts
host 1.1.1.12
host 1.1.1.13
object service sql_1433
service tcp source eq 1433
object service sql_4032
service tcp source eq 4032
exit
nat (SQL_ASP,LL) source static obj-10.0.5.1 obj-10.1.8.2 destination static remote-replication-hosts remote-replication-hosts service sql_1433 sql_4032
access-list LL extended permit tcp host 1.1.1.12 host obj-10.1.8.2 eq 1433
Thanks in Advance..............
Solved! Go to Solution.
08-18-2015 04:34 PM
Hello mdr.ahamedb,
On the rule that you included you are doing NAT for the source and destination. If you want to do a normal port forwarding and just do the port redirection to a different port you don't require to NAT the source.
nat (SQL_ASP,LL) source static Private_IP Public_IP service sql_1433 sql_4032
If you need to hide the source with another IP then the rule that you created should accomplish both task at once.
Once you have the configuration in you can use the show xlate | i x.x.x.x to see the port assignment and confirm that the ports and IP's are on the correct place.
Kind regards,
Jose Orozco.
08-18-2015 04:34 PM
Hello mdr.ahamedb,
On the rule that you included you are doing NAT for the source and destination. If you want to do a normal port forwarding and just do the port redirection to a different port you don't require to NAT the source.
nat (SQL_ASP,LL) source static Private_IP Public_IP service sql_1433 sql_4032
If you need to hide the source with another IP then the rule that you created should accomplish both task at once.
Once you have the configuration in you can use the show xlate | i x.x.x.x to see the port assignment and confirm that the ports and IP's are on the correct place.
Kind regards,
Jose Orozco.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide