cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
355
Views
0
Helpful
2
Replies

Trying to lock down RDS on asa 8.2

n1fcc
Level 1
Level 1

I currently have a asa 8.2 where I have port forwarded RDS .  It currently works correctly, however I need to stop allowing RDS from any address to only allow it from a single address.

access-list mail_server extended permit tcp any interface outside eq 50004
static (inside,outside) tcp interface 50004 10.1.1.73 3389 netmask 255.255.255.255

 

This works fine however if i try to lock it down I lose access to rds

static (inside,outside) tcp 88.88.88.88 50004 10.1.1.73 3389 netmask 255.255.255.255

did not work at all

 

Im confused

 

Dave

2 Replies 2

n1fcc
Level 1
Level 1

Can I get any help out there.  My customer is afraid of leaving the RDS port open

 

Is the IP address you want to allow access from 88.88.88.88 ? 

 

If so you do not modify the NAT statement you need to modify your acl eg. - 

 

 access-list mail_server extended permit tcp host 88.88.88.88 interface outside eq 50004

 

Jon

Review Cisco Networking for a $25 gift card