Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Ports 443 and 80

Hello Folks,

I am in need of some help. I have a RDP server on my network that I have set up for external access from the internet. I have also configured my router to forward in the nessecary locations and opened up the right ports or so I thought. I have enabled CBAC on my router to inspect all interfaces inbound and outbound traffic and applied an access list allowing traffic in on ports 443 and 80 to my outbound interface pointing inbound. Yet I am still unable to navigate to the website or IP address externally. I went to "sheilds up!" at grc.com to test my opened ports and they are still saying those two ports are closed. Am I missing something on my access list that wouldn't allow port 443 or 80 based traffic to converse that interface.

here is my configuration:

service timestamps log datetime msec

service password-encryption

!

hostname ROLIAJ01

!

boot-start-marker

boot-end-marker

!

!

enable secret 4 avq1sKoPiePO9fyYwxoCGtXKX9/uitvC9ih8omI4b1.

!

no aaa new-model

!

clock timezone utc 2 0

!

no ipv6 cef

ip source-route

ip cef

!

!

!

!

!

ip inspect name GMRA tcp router-traffic

ip inspect name GMRA udp router-traffic

ip inspect name GMRA icmp router-traffic

!

multilink bundle-name authenticated

!

crypto pki token default removal timeout 0

!

!

license udi pid CISCO1941/K9 sn FGL161920AW

!

!

!

redundancy

!

!

!

!

!

!

!

!

!

!

!

interface Embedded-Service-Engine0/0

no ip address

shutdown

!

interface GigabitEthernet0/0

description External Interface

ip address 81.x.x.x 255.255.255.252

ip access-group 101 in

ip nat outside

ip inspect GMRA in

ip inspect GMRA out

ip virtual-reassembly in

duplex auto

speed auto

!

interface GigabitEthernet0/1

description Internal Interface

no ip address

ip nat inside

ip inspect GMRA in

ip inspect GMRA out

ip virtual-reassembly in

duplex auto

speed auto

!

interface GigabitEthernet0/1.20

description Vlan20 Trunk

encapsulation dot1Q 20

ip address 192.168.20.1 255.255.255.0

ip nat inside

ip virtual-reassembly in

!

interface GigabitEthernet0/1.30

encapsulation dot1Q 30

ip address 192.168.30.1 255.255.255.0

!

interface GigabitEthernet0/1.40

encapsulation dot1Q 40

ip address 10.10.10.1 255.255.255.128

!

interface GigabitEthernet0/1.99

description Vlan99 Trunk

encapsulation dot1Q 99

ip address 192.168.99.1 255.255.255.0

!

interface FastEthernet0/0/0

no ip address

!

interface FastEthernet0/0/1

no ip address

!

interface FastEthernet0/0/2

no ip address

!

interface FastEthernet0/0/3

no ip address

!

interface Vlan1

no ip address

!

ip forward-protocol nd

!

no ip http server

no ip http secure-server

!

ip nat pool GMRA 81.x.x.x 81.x.x.x prefix-length 30

ip nat source static tcp 192.168.20.37 80 81.x.x.x 80 extendable

ip nat source static tcp 192.168.20.37 443 81.x.x.x 443 extendable

ip nat source static udp 192.168.20.37 3389 81.x.x.x 3389 extendable

ip nat inside source list 7 pool GMRA overload

ip nat inside source static tcp 192.168.20.37 3389 81.x.x.x 3389 extendable

ip route 0.0.0.0 0.0.0.0 81.x.x.x

!

access-list 7 permit 192.168.20.0 0.0.0.255

access-list 101 permit tcp any any eq 443

access-list 101 permit tcp any any eq www

access-list 101 permit tcp any any eq 3389

!

!

Thanks in advanced,

Eddie

Everyone's tags (8)
236
Views
0
Helpful
0
Replies
CreatePlease login to create content