Port forwarding in Cisco ISR 2811

Unanswered Question
Mar 20th, 2009
User Badges:

Hi I have a Cisco ISR2811 running advanced ip services with CME and CUE in it.


I need to Port forward from the outside to the inside port 22 for SSH.


example outside ip address 1.1.1.1 inside ip address 10.100.100.10


I know I need the command


ip nat inside source static tcp <private ip> 22 <public ip> 22


However on my ACL to permit this.

would I permit from my outside IP address or from the remote site I want to be able to access this.


and then do I apply that ACL to the FA0/0 which is the public interface as ACL 101 inbound


thank in advance


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Jon Marshall Fri, 03/20/2009 - 12:05
User Badges:
  • Super Blue, 32500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Greg


Your acl would look like


access-list 101 permit tcp host eq 22


and then yes you apply it inbound on the outside interface.


Jon

GregL Fri, 03/20/2009 - 12:22
User Badges:

Thanks Jon I will give that a try next week.

Actions

This Discussion