02-10-2014 11:05 PM - edited 03-11-2019 08:43 PM
Dear Expters,
I want to configure NATing for the specifc Server inside the Secured LAN zone (172.18.64.11).
That server need to provide only access thorugh RDP/3189 port from only one iP address.
Inside IP address : 172.18.64.11
NATedIP address : 172.21.76.241
Firewall Outside IP address : 172.21.76.254
Out side iP address accessing the sever via RDP port = 172.24.105.16
Port TCP/UDP - 3189
Firewall Details :
Name: "Chassis", DESCR: "ASA 5505 Adaptive Security Appliance"
PID: ASA5505 , VID: V12 , SN: JMX17214138
System image file is "disk0:/asa901-k8.bin"
ASDM version - 7.1(1)52
COnfiguration appllied :
object network CRNCTL
host 172.18.64.11
object network CRNCTL_NATed
host 172.21.76.241
object network Temp_Admin
host 172.24.105.16
object service Remote_Desktop
service tcp destination eq 3189
description Remote_Desktop
object service RDP
service udp destination eq 3189
description RDP
object-group service TEMP
description TEMP
service-object object Remote_Desktop
service-object object RDP
object network CRNCTL
nat (inside,outside) static CRNCTL_NATed
access-list outside_access_in extended permit object-group TEMP object Temp_Admin object CRNCTL_NATed
access-group outside_access_in in interface outside
But it's not working.
When I am applying
access-list outside_access_in extended permit ip any any.
Than it's working.
Please help to resolve this issue.
02-10-2014 11:39 PM
Hi,
There are atleast 1 problem, probably 2.
So I would suggest the following options depending if the above port used was a typo/mistake or not
access-list outside_access_in permit tcp object Temp_Admin object CRNCTL eq 3389
access-list outside_access_in permit tcp object Temp_Admin object CRNCTL eq 3189
Hope this helps
Let me know how it goes.
Please do remember to mark a reply as the correct answer if it answered your question.
- Jouni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide