Showing results for 
Search instead for 
Did you mean: 

Configure static NAT for range of ports

Austin Rivet
Level 1
Level 1


I have a 2911 with a 3CX IP PBX behind it that needs to have a static NAT to the 3CX server for TCP/UDP 5060 and UDP 9000-9049. Do I have to create a static NAT entry for every single port in order for this to work, or can a range be defined in the NAT entries?

As an example, say my 3CX server has an internal IP of and my external IP is Would I have to create an entry for each port?

ip nat inside source static tcp 5060 5060
ip nat inside source static udp 5060 5060
ip nat inside source static udp 9000 9000
ip nat inside source static udp 9001 9001

and so on...

Is this the correct way to do it, or is there another better way?

Also, I only have one public IP to work with, and there are multiple other hosts on this network that need to have access to the internet. Right now I have NAT setup with overload so that the other hosts can get to the Internet. Here's my config for that:

ip nat pool PATPOOL netmask
ip nat inside source list NAT_ACL pool PATPOOL overload     

ip access-list standard NAT_ACL
 remark PAT to outside

My question with this is will the static NAT work if I already have NAT overload configured as above?

Thanks for the help in advance.


PS here is 3CX documentation on this subject

1 Reply 1

Austin Rivet
Level 1
Level 1

I ended up creating a static NAT entry for each individual port mapping. This worked just as it was supposed to. 

I have seen examples of people using route maps and ACLs to accomplish forwarding a range ports. I have yet to see official documentation from Cisco on this, and in some cases those examples did not seem to work correctly.

ASAs with the latest code have the ability to forward a range of ports, but based on my research IOS lacks this feature.

In my case, forwarding 50 ports wasn't so bad. However, if you have hundreds or thousands of ports to forward you may want to try the route map/ACL approach.

Hopefully this information useful to others. 


Review Cisco Networking for a $25 gift card