Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NATing issue.

---------------------------------------

ASDM Version 649-103

ASA Version 8.2(5)33

----------------------------------------

I have an issue that I know is simple enough that has to do with NATting.  I have pasted below the config that is pertinent to this question.

We have two public IPs from our ISP, one is assigned to the Outside interface while the second one we want to be forwarded (port 5721) to an internal server.

If I point the default gateway to this firewall everything works great with the config listed below.  I however want to point the server to our core as we have several internal networks that need to access this server.

Every time I attempt to do this though it fails miserably.  I can no longer ping the external IP of .147.

I almost think that my NAT is simply configured wrong and the only reason it works when the server is pointing directly to the firewall is because it's using the default PAT configured and not the Static NAT I created.

One other thing,

When I attempt to create an access group  Inside_access_in in interface Inside all my tunnels fail because the implicit rule to permit all traffic to less secure networks is replaced.....

At this point I am just grasping at straws here....

!

interface Ethernet0/0

nameif Outside

security-level 0

ip address 64.xxx.xxx.146 255.255.255.240

!

object-group service DM_INLINE_SERVICE_1

service-object icmp

service-object icmp echo-reply

service-object icmp echo

object-group service Kaseya_External_Management tcp-udp

description Kaseya_External_Management Port 5721

port-object eq 5721

object-group service DM_INLINE_SERVICE_2

service-object icmp

service-object icmp echo-reply

service-object icmp echo

object-group service DM_INLINE_SERVICE_3

service-object icmp

service-object icmp echo

service-object icmp echo-reply

global (Outside) 1 interface

nat (Inside) 0 access-list Inside_nat0_outbound

nat (Inside) 1 0.0.0.0 0.0.0.0

static (Inside,Outside) 64.xxx.xxx.147 10.xxx.xxx.231 netmask 255.255.255.255

access-group Outside_access_in in interface Outside

route Outside 0.0.0.0 0.0.0.0 64.xxx.xxx.145 1

object-group service DM_INLINE_SERVICE_1
service-object icmp
service-object icmp echo-reply
service-object icmp echo
object-group service Kaseya_External_Management tcp-udp
description Kaseya_External_Management Port 5721
port-object eq 5721
object-group service DM_INLINE_SERVICE_2
service-object icmp
service-object icmp echo-reply
service-object icmp echo
object-group service DM_INLINE_SERVICE_3
service-object icmp
service-object icmp echo
service-object icmp echo-reply

!

global (Outside) 1 interface
nat (Inside) 0 access-list Inside_nat0_outbound
nat (Inside) 1 0.0.0.0 0.0.0.0
static (Inside,Outside) 64.xxx.xxx.147 10.xxx.xxx.231 netmask 255.255.255.255
access-group Outside_access_in in interface Outside
route Outside 0.0.0.0 0.0.0.0 64.xxx.xxx.145 1

!

Thank you in advance !!

Everyone's tags (4)
360
Views
0
Helpful
0
Replies