Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Help with Port Forwarding from Outside Address

Can someone point me to info on port forwarding from an external address to an internal address. This firewall has a DMZ, but the machine I want to port forward to does not sit in the DMZ. All attempts to solve have lead to my machines in the DMZ not working.

Everyone's tags (2)
2 ACCEPTED SOLUTIONS

Accepted Solutions
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Hi,

Be aware that an ACL must allow the traffic comes from Internet to DMZ servers.

Br,

Cisco Employee

Re: Help with Port Forwarding from Outside Address

Ok, have you already checked all ACLs for inside and outside directions?

10 REPLIES
Cisco Employee

Re: Help with Port Forwarding from Outside Address

Hi,

Try this command below:

static (inside,outside) tcp 1.1.1.1 www 2.2.2.2 www netmask 255.255.255.255

where 1.1.1.1 = it is your public ip address and 2.2.2.2 it is your internal one ( RFC 1918 ). In this example, the firewall is performing a static PAT for HTTP service. In this case, the reachable ip address for the Internet will be 2.2.2.2

Br,

Cisco Employee

Re: Help with Port Forwarding from Outside Address

Sorry, the ip will be 1.1.1.1 to be reachable by Internet

New Member

Re: Help with Port Forwarding from Outside Address

So are you saying:

static (inside,outside) tcp External-IP www Internal-IP www netmask 255.255.255.255

Cisco Employee

Re: Help with Port Forwarding from Outside Address

That's correct.

Br

New Member

Re: Help with Port Forwarding from Outside Address

Thanks for the reply, but it didn't work.

Cisco Employee

Re: Help with Port Forwarding from Outside Address

Hi,

Be aware that an ACL must allow the traffic comes from Internet to DMZ servers.

Br,

New Member

Re: Help with Port Forwarding from Outside Address

Yes,  realize that. But, this is not a DMZ host, it is one that sits on the inside network.

Cisco Employee

Re: Help with Port Forwarding from Outside Address

Ok, have you already checked all ACLs for inside and outside directions?

New Member

Re: Help with Port Forwarding from Outside Address

Got it. I added:

access-list Inside_access_out extended permit tcp any host 192.168.14.252 eq www

access-list Inside_access_out extended permit tcp host 192.168.14.252 eq www any

and everything finally worked.

Thanks again for your help.

Chuck

Cisco Employee

Re: Help with Port Forwarding from Outside Address

You are welcome.

Best regards,

Renato Saraiva

1205
Views
0
Helpful
10
Replies