ASA 5505 Port Forwarding

Unanswered Question

I am having simple issue with setting up port forwarding for RDC on ASA 5505. I have configured several other ASA 5505 appliances using the same commands and they all work fine. Here is the running config. Any help would be appreciated.

Result of the command: "show conf"

: Saved

: Written by enable_15 at 05:11:58.270 UTC Thu Mar 19 2009


ASA Version 7.2(2)


hostname ciscoasa

domain-name default.domain.invalid

enable password xxxx encrypted



interface Vlan1

nameif inside

security-level 100

ip address


interface Vlan2

nameif outside

security-level 0

ip address 70.x.x.x


interface Ethernet0/0

switchport access vlan 2


interface Ethernet0/1


interface Ethernet0/2


interface Ethernet0/3


interface Ethernet0/4


interface Ethernet0/5


interface Ethernet0/6


interface Ethernet0/7


passwd xxxx encrypted

ftp mode passive

dns server-group DefaultDNS

domain-name default.domain.invalid

access-list outside_access_in_web extended permit tcp any interface outside eq 3389

pager lines 24

logging asdm informational

mtu outside 1500

mtu inside 1500

icmp unreachable rate-limit 1 burst-size 1

asdm image disk0:/asdm-522.bin

no asdm history enable

arp timeout 14400

global (outside) 1 interface

nat (inside) 1

static (inside,outside) tcp interface 3389 3389 netmask

access-group outside_access_in_web in interface outside

route outside 70.x.x.x 1

timeout xlate 3:00:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00

timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00

timeout uauth 0:05:00 absolute

http server enable

http inside

no snmp-server location

no snmp-server contact

snmp-server enable traps snmp authentication linkup linkdown coldstart

telnet timeout 5

ssh timeout 5

console timeout 0

dhcpd auto_config outside


dhcpd address inside

dhcpd enable inside



class-map inspection_default

match default-inspection-traffic



policy-map type inspect dns preset_dns_map


message-length maximum 512

policy-map global_policy

class inspection_default

inspect dns preset_dns_map

inspect ftp

inspect h323 h225

inspect h323 ras

inspect rsh

inspect rtsp

inspect esmtp

inspect sqlnet

inspect skinny

inspect sunrpc

inspect xdmcp

inspect sip

inspect netbios

inspect tftp


service-policy global_policy global

prompt hostname context


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
robertson.michael Thu, 03/19/2009 - 12:48

Hi Almir,

Your ACL and NAT statements both look good to me. Try adding:

ASA(config)# interface e0/x

ASA(config-if)# switchport access vlan 1

Where e0/x is the interface that the RDP server ( is connected to (e.g. e0/1). This will configure the switch port as an access port for VLAN 1 (your inside network).

Hope that helps.


ex_pmadayag Mon, 03/23/2009 - 10:05

config looks fine

Does RDP work locally?

If you access the rdp server from outside, do you get hit counts in your outside ACL?


This Discussion