Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Port Forwarding ASA5505

I have an ASA5505 configured for Remote VPN connection. I am adding an IP phone server that will allow remote IP phones to connect to the internal phone system. I need to Port Forward port 59002 to an internal IP address. Is there an easy way to do this? Thanks, Kevin

13 REPLIES

Re: Port Forwarding ASA5505

Kevin,

Is the IP phone software or hardware based?

Community Member

Re: Port Forwarding ASA5505

Andrew,

I believe it is hardware based because I have an actual phone as a remote and a computer inside my network. It is an ESI 50 system.

Thanks,

Kevin

Re: Port Forwarding ASA5505

Just add an entry to the acl allowing any remote access to the NAT ip using a desintaiton TCP/UDP port required.

Community Member

Re: Port Forwarding ASA5505

Can you give me the entry for that? I have added a couple of access-list commands and static commands to the configuration. I can see the static entry in the NAT using ASDM showing the port on the outside and the IP on the inside but it still does not work.

Re: Port Forwarding ASA5505

you just need to allow the port on the ACL on your remote user policy group.

see this http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080641a52.shtml

Community Member

Re: Port Forwarding ASA5505

Francisco,

This remote phone does not use the remote VPN connection. I think it just uses our public IP and port. With the port forwarded to the IP of the ESI computer on the inside of the network.

Thanks,

Kevin

Cisco Employee

Re: Port Forwarding ASA5505

Static (INSIDE,OUTSIDE) tcp interface 59002 59002

Access-list permit tcp/udp eq 59002

Cisco Employee

Re: Port Forwarding ASA5505

I just gave you the commands

Community Member

Re: Port Forwarding ASA5505

I see that now thanks! Please forgive me, I am not an IT professional, just a small business owner trying to survive. Can you give me an example of the and the . I know what my public IP is. Thanks!

Cisco Employee

Re: Port Forwarding ASA5505

Static (INSIDE,OUTSIDE) tcp interface 59002 59002

Access-list ACL_OUT permit tcp/udp ANY eq 59002

access-group ACL_OUT in interface OUTSIDE.

If you hace any problem please send me the

show run access-group

show access-list

Community Member

Re: Port Forwarding ASA5505

When I type in the access-list command, I get the error Invalid Hostname with the indication on the "e" of eq.

Community Member

Re: Port Forwarding ASA5505

Success!! I added the word "host" before the public IP and then followed the rest of the commands. The phone works! Thanks!!!!

Cisco Employee

Re: Port Forwarding ASA5505

Very Welcome have a good one

941
Views
0
Helpful
13
Replies
CreatePlease to create content