<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Config] ASA Port Forwarding Help in Cisco</title>
<link>http://www.dslreports.com/forum/r22636279</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 00:46:34 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 00:46:34 EDT</lastBuildDate>

<item>
<title>Re: [Config] ASA Port Forwarding Help</title>
<link>http://www.dslreports.com/forum/remark,22636473</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Okay I believe I got it...<br><br>Entered in the following and now it appears to be working.<br><br>access-list inbound permit tcp any interface outside eq https<br><br>access-group inbound in interface outside<br><br>static (inside,outside) tcp interface https 192.168.10.87 https netmask 255.255.255.255 ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22636473</guid>
<pubDate>Tue, 30 Jun 2009 19:18:41 EDT</pubDate>
</item>

<item>
<title>Re: [Config] ASA Port Forwarding Help</title>
<link>http://www.dslreports.com/forum/remark,22636358</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Okay here are the commands I believe I should enter but I'm just not sure...Again, any help would be appreciated.<br><br>access-list outside-entry extended permit tcp any host 72.150.82.66 eq https<br><br>global (outside) 1 interface<br>nat (inside) 1 192.168.10.0 255.255.255.0<br><br>static (inside,outside) tcp 72.150.82.66 https 192.168.10.87 https netmask 255.255.255.255]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22636358</guid>
<pubDate>Tue, 30 Jun 2009 18:52:34 EDT</pubDate>
</item>

<item>
<title>[Config] ASA Port Forwarding Help</title>
<link>http://www.dslreports.com/forum/remark,22636279</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I'm having a heck of a time trying to port forward with an ASA.  Keep in mind, I am in no way a Cisco guy but I'm forced to try at my current position.<br><br>My situation is this:  Need to Port Forward HTTPS Traffic through my ASA to a server on the inside network at 192.168.10.87.  Every time I create a rule inside of the ASDM nothing happens and it doesn't forward at all.  <br><br>If anyone could PLEASE write this rule for me, I would really appreciate it.  Here is my config:<br><br>User Access Verification<br><br>Username: ********<br>Password: *********<br>Type help or '?' for a list of available commands.<br>palouseFW> em<br>            ^<br>ERROR: % Invalid input detected at '^' marker.<br>ASAFW> en<br>Password:<br>Password:<br>Password:<br>Access denied.<br>asaFW> en<br>Password: *********<br>asaFW# show running-config<br>: Saved<br>:<br>ASA Version 7.0(8)<br>!<br>hostname asaFW<br>domain-name testing.local<br>enable password 8Ry2YjIyt7RRXU24 encrypted<br>passwd 2KFQnbNIdI.2KYOU encrypted<br>multicast-routing<br>names<br>dns-guard<br>!<br>interface Ethernet0/0<br> description Public Interface<br> nameif outside<br> security-level 0<br> ip address 72.150.82.66 255.255.255.192<br> no igmp<br>!<br>interface Ethernet0/1<br> description Inside Interface<br> nameif inside<br> security-level 100<br> ip address 192.168.10.2 255.255.255.0<br>!<br>interface Ethernet0/2<br> description DMZ for Mainframe<br> nameif nx4201<br> security-level 60<br> ip address 192.1.14.1 255.255.255.0<br>!<br>interface Ethernet0/3<br> description MPLS<br> shutdown<br> nameif MPLS<br> security-level 100<br> ip address 192.168.14.1 255.255.255.0<br>!<br>interface Management0/0<br> nameif management<br> security-level 100<br> ip address 192.168.1.1 255.255.255.0<br> management-only<br>!<br>banner login This is a private computer facility, protected by a security system<br>. Access to and use requires explicit<br>banner login written, current authorization and is limited to purposes of the or<br>ganization's business.<br>banner login Unauthorized access or attempts to use, alter, destroy, or damage d<br>ata, programs, or equipment may<br>banner login violate applicable local, state, or federal law and could result in<br> criminal prosecution, civil liability, or both.<br>boot system disk0:/asa803-k8.bin<br>boot system disk0:/asa708-k8.bin<br>ftp mode passive<br>clock timezone PST -8<br>clock summer-time PDT recurring<br>same-security-traffic permit intra-interface<br>access-list inside_nat0_outbound extended permit ip 192.168.10.0 255.255.255.0 1<br>92.1.14.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.11.0 255.255.255.0 1<br>92.1.14.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.12.0 255.255.255.0 1<br>92.1.14.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.13.0 255.255.255.0 1<br>92.1.14.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.15.0 255.255.255.0 1<br>92.1.14.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.17.0 255.255.255.0 1<br>92.1.14.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.10.0 255.255.255.0 1<br>92.168.18.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.10.0 255.255.255.0 1<br>92.168.19.0 255.255.255.0<br>access-list inside_nat0_outbound extended permit ip 192.168.10.0 255.255.255.0 1<br>92.168.20.0 255.255.255.0<br>access-list 100 extended permit ip 192.168.10.0 255.255.255.0 192.1.14.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.168.11.0 255.255.255.0 192.1.14.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.168.12.0 255.255.255.0 192.1.14.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.168.13.0 255.255.255.0 192.1.14.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.168.15.0 255.255.255.0 192.1.14.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.168.17.0 255.255.255.0 192.1.14.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.1.14.0 255.255.255.0 192.168.10.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.1.14.0 255.255.255.0 192.168.11.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.1.14.0 255.255.255.0 192.168.12.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.1.14.0 255.255.255.0 192.168.13.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.1.14.0 255.255.255.0 192.168.15.0 255.255<br>.255.0<br>access-list 100 extended permit ip 192.1.14.0 255.255.255.0 192.168.17.0 255.255<br>.255.0<br>access-list 100 extended deny ip any any<br>access-list 101 extended permit ip 192.168.10.0 255.255.255.0 192.168.18.0 255.2<br>55.255.0<br>access-list 102 extended permit ip 192.168.10.0 255.255.255.0 192.168.19.0 255.2<br>55.255.0<br>pager lines 24<br>logging enable<br>logging trap informational<br>logging asdm informational<br>logging from-address Fairfield-FW@palouse1.local<br>logging host inside 192.168.10.199<br>mtu outside 1500<br>mtu inside 1500<br>mtu nx4201 1500<br>mtu MPLS 1500<br>mtu management 1500<br>ip local pool RemoteAccess 192.168.20.100-192.168.20.200 mask 255.255.255.0<br>ip verify reverse-path interface outside<br>no failover<br>icmp deny any outside<br>icmp permit any inside<br>icmp permit 192.1.14.0 255.255.255.0 nx4201<br>asdm image disk0:/asdm508.bin<br>asdm history enable<br>arp timeout 14400<br>global (outside) 101 12.150.82.126 netmask 255.255.255.255<br>nat (inside) 0 access-list inside_nat0_outbound<br>nat (inside) 101 192.168.10.0 255.255.255.0<br>nat (inside) 101 192.168.11.0 255.255.255.0<br>nat (inside) 101 192.168.12.0 255.255.255.0<br>nat (inside) 101 192.168.13.0 255.255.255.0<br>nat (inside) 101 192.168.14.0 255.255.255.0<br>nat (inside) 101 192.168.15.0 255.255.255.0<br>nat (inside) 101 192.168.17.0 255.255.255.0<br>access-group 100 in interface nx4201<br>route outside 0.0.0.0 0.0.0.0 12.150.82.65 1<br>route outside 192.168.20.0 255.255.255.0 192.168.10.2 1<br>route inside 192.168.11.0 255.255.255.0 192.168.10.4 1<br>route inside 192.168.12.0 255.255.255.0 192.168.10.4 1<br>route inside 192.168.13.0 255.255.255.0 192.168.10.4 1<br>route inside 192.168.15.0 255.255.255.0 192.168.10.4 1<br>route inside 192.168.17.0 255.255.255.0 192.168.10.4 1<br>timeout xlate 3:00:00<br>timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02<br>timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00<br>timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00<br>timeout uauth 0:05:00 absolute<br>group-policy RemoteAccess internal<br>group-policy RemoteAccess attributes<br> dns-server value 192.168.10.88<br> default-domain value palouse<br> webvpn<br>username DataPro password iaaqwlirXxC8/hqq encrypted privilege 15<br>username fairfield password 3CkZJXm/13/uhfIg encrypted privilege 15<br>username sdruffell password UK5Es6.fyidMxg2i encrypted privilege 0<br>username sdruffell attributes<br> vpn-group-policy RemoteAccess<br> webvpn<br>aaa authentication enable console LOCAL<br>aaa authentication http console LOCAL<br>aaa authentication ssh console LOCAL<br>aaa authentication telnet console LOCAL<br>http server enable<br>http 192.168.10.50 255.255.255.255 inside<br>http 192.168.10.81 255.255.255.255 inside<br>http 192.168.10.87 255.255.255.255 inside<br>http redirect inside 80<br>no snmp-server location<br>no snmp-server contact<br>snmp-server enable traps snmp authentication linkup linkdown coldstart<br>crypto ipsec transform-set ESP-AES-MD5 esp-aes esp-md5-hmac<br>crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac<br>crypto ipsec security-association lifetime seconds 28800<br>crypto ipsec security-association lifetime kilobytes 4608000<br>crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA<br>crypto dynamic-map outside_dyn_map 20 set security-association lifetime seconds<br>28800<br>crypto dynamic-map outside_dyn_map 20 set security-association lifetime kilobyte<br>s 4608000<br>crypto map OUTSIDE_MAP 20 match address 101<br>crypto map OUTSIDE_MAP 20 set peer 24.117.110.57<br>crypto map OUTSIDE_MAP 20 set transform-set ESP-AES-MD5<br>crypto map OUTSIDE_MAP 20 set security-association lifetime seconds 28800<br>crypto map OUTSIDE_MAP 20 set security-association lifetime kilobytes 4608000<br>crypto map OUTSIDE_MAP 30 match address 102<br>crypto map OUTSIDE_MAP 30 set peer 10.254.254.254<br>crypto map OUTSIDE_MAP 30 set transform-set ESP-AES-MD5<br>crypto map OUTSIDE_MAP 30 set security-association lifetime seconds 28800<br>crypto map OUTSIDE_MAP 30 set security-association lifetime kilobytes 4608000<br>crypto map OUTSIDE_MAP 65535 ipsec-isakmp dynamic outside_dyn_map<br>crypto map OUTSIDE_MAP interface outside<br>crypto map outside_map 30 set peer 75.148.59.222<br>crypto map outside_map 30 set security-association lifetime seconds 28800<br>crypto map outside_map 30 set security-association lifetime kilobytes 4608000<br>isakmp identity address<br>isakmp enable outside<br>isakmp policy 10 authentication pre-share<br>isakmp policy 10 encryption 3des<br>isakmp policy 10 hash sha<br>isakmp policy 10 group 2<br>isakmp policy 10 lifetime 86400<br>isakmp disconnect-notify<br>tunnel-group 24.117.110.57 type ipsec-l2l<br>tunnel-group 24.117.110.57 ipsec-attributes<br> pre-shared-key *<br>tunnel-group 10.254.254.254 type ipsec-l2l<br>tunnel-group 10.254.254.254 ipsec-attributes<br> pre-shared-key *<br>tunnel-group RemoteAccess type ipsec-ra<br>tunnel-group RemoteAccess general-attributes<br> address-pool RemoteAccess<br> default-group-policy RemoteAccess<br>tunnel-group RemoteAccess ipsec-attributes<br> pre-shared-key *<br>telnet 192.168.10.50 255.255.255.255 inside<br>telnet 192.168.10.81 255.255.255.255 inside<br>telnet 192.168.10.87 255.255.255.255 inside<br>telnet timeout 5<br>ssh timeout 5<br>console timeout 30<br>!<br>class-map inspection_default<br> match default-inspection-traffic<br>!<br>!<br>policy-map global_policy<br> class inspection_default<br>  inspect ftp<br>!<br>service-policy global_policy global<br>smtp-server 192.168.10.87<br>Cryptochecksum:e6307a77e893712e6d009143e5cc1df5<br>: end<br>ASAFW#]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22636279</guid>
<pubDate>Tue, 30 Jun 2009 18:35:03 EDT</pubDate>
</item>

</channel>
</rss>
