Inspect Open Ports on ASA5505

Unanswered Question
Jan 26th, 2010

Hi all,

I would like to know what commend to use to inspect or review which ports are blocked or open on the ASA 5505.

Thanks in advance,


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Kureli Sankar Tue, 01/26/2010 - 12:20

sh service-policy ---> This will tell you the inspections configured and the traffic that it has seen.

To see what ports are open on the ASA5505 you need to see what you are allowing on the ACL applied on the outside interface.

That will be for through the box traffic. http, ssh to the outside interface can be checked with the following commands.

sh run ssh

sh run http


skhirbash Tue, 01/26/2010 - 21:11

Thanks for the response.

I created a one to one NAT statement but when I ping the pubilc ip address from the outside, it doesn't responde. Can you tell me what I am doing wrong? Here is a sample of thenat statement:

nat (inside) 0 access-list nonat
nat (inside) 1
static (inside,outside) netmask
static (inside,outside) netmask
static (inside,outside) netmask
access-group outside_access_in in interface outside

Is there anything else I need to do.

Thanks in advance,


Use " show run access-list" to view the access-list in

their simplest form.  Use "show access-list" to

see the access-list details, to include any object-group members and hit counts.

Use "show access-group" to see which access lists are applied to which interfaces.

If you are not familiar with the CLI, I recommend you use the ASDM gui.  It's much easier to see the ACL's in the ASDM than it is to interpret them in their raw form.


This Discussion