Port forwarding in Cisco ISR 2811

Unanswered Question
Mar 20th, 2009
User Badges:

Hi I have a Cisco ISR2811 running advanced ip services with CME and CUE in it.

I need to Port forward from the outside to the inside port 22 for SSH.

example outside ip address inside ip address

I know I need the command

ip nat inside source static tcp <private ip> 22 <public ip> 22

However on my ACL to permit this.

would I permit from my outside IP address or from the remote site I want to be able to access this.

and then do I apply that ACL to the FA0/0 which is the public interface as ACL 101 inbound

thank in advance

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Jon Marshall Fri, 03/20/2009 - 12:05
User Badges:
  • Super Blue, 32500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN


Your acl would look like

access-list 101 permit tcp host eq 22

and then yes you apply it inbound on the outside interface.


GregL Fri, 03/20/2009 - 12:22
User Badges:

Thanks Jon I will give that a try next week.


This Discussion