cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1990
Views
5
Helpful
5
Replies

NAT FDM Configuration Outside - Inside

S3C
Level 1
Level 1

Hello!

I cant seem to get my NAT to work and i cant figure out what im doing wrong...

I want to be able from the internet to access a server. Internet -> FDM (outside) -> Esxi (inside) -> Specific Server (so any to any dont work) and i want to specify the servers IP so its only natting to that specific server and not the everything on that interface.

Also i can ping the specific server.

 

Original packet

--------------

Source Interface: outside

Source address: outside_internet (host, IP of ISP)

Source Port: Any (supposed to be http & https)

Destination Address: Any

Destination Port: Any

 

Translated Packet

--------------

Source Interface: inside

Source address: Server (host)

Source Port: Any (supposed to be http & https)

Destination Address: Any

Destination Port: Any

 

ACL

-------

ACL is correct, from internet to the host with any on ports.

 

Events

--------

No connection is coming in to the specific server to there´s no ACL blocking

 

---------------

Feels like ive tried all combinations and checked other peoples guides and setups, which none work. So I just wanna make sure NAT is 100 % correct before troubleshooting elsewhere.

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

we use most cases FMC to that but its near by same :

 

check the below guide to help you:

https://www.petenetlive.com/KB/Article/0001680

https://integratingit.wordpress.com/2020/02/08/ftd-configuration-using-fdm/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Yeah, ive done exactly like those guides above and still dont work. Ive also tried it outside to inside as it should be but still wont work . Therefore im questioning if above is really correct then my problem is elsewhere maybe at my ISP.

Hello,

 

as far as I recall, the packet tracer command equivalent is something like 'show packet-capture number trace detail', if you can get to that output, that usually tells you where the problem is...

If you configured correctly, then you need to Logs first is the packet reaching outside interface of Firewall, before it can translate ?

 

If you have external different access, try to use Pc with External IP try telnet XXXXX 443 (XXX  external IP) - see is that packet reach firewall ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

S3C
Level 1
Level 1

I forgot to mention that it is a Cisco FTD 1120 with FDM.

Ill try above and see what output i get.

also followed https://www.cisco.com/c/en/us/td/docs/security/firepower/610/fdm/fptd-fdm-config-guide-610/fptd-fdm-nat.html#task_AB7424D043054D71B35CE33F7AC0CA96