Dear NetPro folks,
I've been working on a homologation process for the deployment of Cisco ASA 5520 appliances and I've been unable to successfully make use of static NAT/PAT in order to translate services from the outside pool of IP addresses to inside (real) IP addresses (there is no DMZ perimeter at this time; there are "outside" and "inside" interfaces only).
The scenario is as follows:
- Inside: 10.1.4.16/24
- Outside: 126.96.36.199/26
The pool of registered IP addresses is as follows: 188.8.131.52/26.
The actual ASA configuration (or at least a small part of it that represents the scope of my issue) is as follows:
ip address 10.1.4.16 255.255.255.0
ip address 184.108.40.206 255.255.255.192
object-group service DM_INLINE_TCP_1 tcp
port-object eq 1374
port-object eq 3389
port-object eq ftp
port-object eq ftp-data
port-object eq www
access-list outside_access_in extended permit tcp any host 220.127.116.11 object-group DM_INLINE_TCP_1 log disable
access-group outside_access_in in interface outside
global (outside) 1 interface
nat (inside) 1 10.1.0.0 255.255.0.0
static (inside,outside) tcp 18.104.22.168 ftp-data 10.1.4.10 ftp-data netmask 255.255.255.255
static (inside,outside) tcp 22.214.171.124 ftp 10.1.4.10 ftp netmask 255.255.255.255
static (inside,outside) tcp 126.96.36.199 www 10.1.4.10 www netmask 255.255.255.255
static (inside,outside) tcp 188.8.131.52 3389 10.1.4.10 3389 netmask 255.255.255.255
static (inside,outside) tcp 184.108.40.206 1374 10.1.4.10 1374 netmask 255.255.255.255
route outside 0.0.0.0 0.0.0.0 220.127.116.11 1
route inside 10.1.0.0 255.255.0.0 10.1.4.254 1
There are, of course, several other Access Control Lists and Static NAT/PAT entries, and each one of them uses a separate IP address from the global pool (ie.: 18.104.22.168, 22.214.171.124... 126.96.36.199), and the objective here is to NAT these registered IP addresses to their respective private ones at some specific ports, from outside to inside (ie.: 188.8.131.52 TCP 22 --> 10.1.4.8 TCP 22). These translations are not working either.
I would really appreciate if someone could possibly help me out. Please find enclosed a drawing and the actual ASA config (the full version of it).
I look forward to hearing from you soon. Thank you in advance!