06-01-2018 03:56 PM - edited 03-05-2019 10:32 AM
I currently have a asa 8.2 where I have port forwarded RDS . It currently works correctly, however I need to stop allowing RDS from any address to only allow it from a single address.
access-list mail_server extended permit tcp any interface outside eq 50004
static (inside,outside) tcp interface 50004 10.1.1.73 3389 netmask 255.255.255.255
This works fine however if i try to lock it down I lose access to rds
static (inside,outside) tcp 88.88.88.88 50004 10.1.1.73 3389 netmask 255.255.255.255
did not work at all
Im confused
Dave
06-04-2018 03:51 AM
Can I get any help out there. My customer is afraid of leaving the RDS port open
06-04-2018 03:59 AM - edited 06-04-2018 03:59 AM
Is the IP address you want to allow access from 88.88.88.88 ?
If so you do not modify the NAT statement you need to modify your acl eg. -
access-list mail_server extended permit tcp host 88.88.88.88 interface outside eq 50004
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide