01-22-2009 05:09 PM - edited 03-04-2019 12:56 AM
I have a new ASA-5505 Bun-K9 license. Does this allow 3 vlan's unrestricted traffic flow or do I need a Secure License to obtain full functionallity on all 3 vlan's?
Best Regards
01-22-2009 07:35 PM
Jose
I do not have access to a 5505 right now to check it. But my memory is that the standard license on the 5505 puts some restriction on the use the the third VLAN. To get unrestricted functionality on all 3 VLANs I believe that you need the upgraded license.
HTH
Rick
01-23-2009 03:20 AM
Thanks Rick, I did some late reading last night and found that the 5505 can configure all 3 vlans but the DMZ cannot initiate any connection. The initiation must come from either the inside or outside vlan's........
Any idea on how to do port forwarding with this thing?
Best Regards
01-24-2009 04:40 PM
Jose
Your finding is consistent with what I remembered. I recently configured port forwarding on an ASA5505. I configured it basically as:
static (inside,outside) tcp interface
which establishes a static translation (port forwarding) from the port# on the outside interface to port# on the inside interface. The thing that surprised me about this is that it worked when I specified the keyword "interface" but not when I specified the address of the interface.
HTH
Rick
01-24-2009 05:08 PM
Rick
That's interesting I'm going to have to do some reading on the interface parameter for the static command. I' let you know what I find?
Regards
01-24-2009 06:51 PM
Here's what I found out:
Uses the interface IP address as the mapped address. Use this keyword if you want
to use the interface address, but the address is dynamically assigned using DHCP.
Maybe the address lease had expired?
01-24-2009 06:54 PM
I for got to add this note:
Note You must use the interface keyword instead of specifying the actual IP
address when you want to include the IP address of an interface in a static
PAT entry.
01-25-2009 05:39 PM
Jose
This note explains the behavior that I described in my response. If you do port forwarding where some packet is sent to the outside interface on some port number and you want to forward it to some host inside on some port number then you use the static command to set up a static PAT and you need to use the keywork interface instead of specifying the ip address of the interface.
HTH
Rick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide