Outside NAT / Port Translation assistance needed

Image, says it all really...

I can't configure two external public IP (1.1.1.2 and 1.1.1.3) addresses that point to the same host but different ports (443 for the first) and 8443 for the latter.

Assuming you have your web servers in the DMZ:

(a) static (DMZ, outside) 1.1.1.2 tcp https 2.2.2.2 https netmask 255.255.255.255

(b) permitted HTTPS-OUT extended access list tcp any host 1.1.1.2 eq https

(c) group-HTTPS-OUT access in interface outside

For the second entry, you may need to do this.

(a) static (DMZ, outside) tcp 1.1.1.3 https 2.2.2.2 8443 netmask 255.255.255.255

(b) permitted HTTPS-OUT extended access list tcp any host 1.1.1.3 eq https

(c) group-HTTPS-OUT access in interface outside

Tags: Cisco Security

Similar Questions

  • outside NAT question

    I created an external NAT for my pc to allow internal users to access my pc in my domain name. But because of the domain name is not configured yet, I can only test the outside NAT by referring to my external IP address. For example, my pc has ip internal 10.10.10.11, external ip 82.1.1.11. I have a static nat 10.10.10.11 value 82.1.1.11, also affect a foreign 82.1.1.11 nat 10.10.10.11. My pc has established access list rules to allow external access to my port 80 and 8080. However, when I type http://82.1.1.11/sitename/ to access one of my site, I can't. If I change the url to refer to my internal ip address, the site is displayed correctly.

    Is there something I need to put in place to make it work?

    Thank you

    Pls see below:

    "To access an address of dnat_ip alias with the static control instructions and access-list, specify the address of dnat_ip in the statement of access-list command as the address which traffic is allowed to. The following example illustrates this point.

    alias (inside) 192.168.201.1 209.165.201.1 255.255.255.255

    static (inside, outside) 209.165.201.1 192.168.201.1 netmask 255.255.255.255

    access-list acl_out permit tcp host 192.168.201.1 host 209.165.201.1 eq ftp - data

    Access-group acl_out in interface outside.

    http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/PIX/pix_sw/v_62/cmdref/AB.htm

  • How can I enable UPnP (Universal Plug and Play) or NAT - PMP (NAT Port Mapping Protocol) Protocol?

    I'm trying to set up the screen Edovia and they say that I need to enable UPnP (Universal Plug and Play) or NAT - PMP (NAT Port Mapping Protocol) Protocol.

    How can I do this?

    In Airport utility. The form is in your router.

  • Using "Alias" vs "Outside NAT"?

    Greetings,

    Recently, I started with a company that has a PIX 515. I upgraded the IOS from 1.0000 to 6.3 (5) and installed the PDM 3.04.

    When I try to run the PIX via PDM, it prompts with 'the PDM does not support the 'Alias' command in your configuration... You should migrate to the newer 'Outside NAT' feature (or Bi-Directional NAT).

    Here are my statements about "Alias." Can someone please provide a preview/examples on how to migrate these declarations?

    (inside) alias x.x.x.x y.y.y.y 255.255.255.255

    (inside) alias x.x.x.x y.y.y.y 255.255.255.255

    (inside) alias x.x.x.x y.y.y.y 255.255.255.255

    alias (dmz) x.x.x.x y.y.y.y 255.255.255.255

    static (inside, outside) x.x.x.x y.y.y.y 255.255.255.255 netmask www www tcp 0 0

    static (inside, outside) tcp x.x.x.x citrix ica y.y.y.y citrix ica netmask 255.255.255.255 0 0

    static (dmz, outside) x.x.x.x y.y.y.y 255.255.255.255 netmask https-https tcp 0 0

    static (dmz, outside) x.x.x.x y.y.y.y 255.255.255.255 netmask ftp ftp tcp 0 0

    static (inside, outside) x.x.x.x y.y.y.y 255.255.255.255 netmask smtp smtp tcp 0 0

    static (inside, outside) x.x.x.x y.y.y.y 255.255.255.255 netmask smtp smtp tcp 0 0

    static (inside, outside) x.x.x.x y.y.y.y 255.255.255.255 netmask www www tcp 0 0

    static (inside, outside) tcp x.x.x.x citrix ica y.y.y.y citrix ica netmask 255.255.255.255 0 0

    static (inside, outside) tcp x.x.x.x y.y.y.y 81 netmask 255.255.255.255 0 0

    static (inside, dmz) x.x.x.x y.y.y.y netmask 255.255.255.0 0 0

    public static (inside, outside) x.x.x.x y.y.y.y netmask 255.255.255.255 0 0

    public static (inside, outside) x.x.x.x y.y.y.y netmask 255.255.255.255 0 0

    Hello.. Command alias is used for the translation of IP addresses that overlap... for example if you have a remote using 192.168.0.1 and you have also your internal network using the same range, so you can get 192.168.0.1 appear to your LAN as a different IP... in this case 10.10.10.10

    alias (inside) 10.10.10.10 192.168.0.1 255.255.255.255

    You can also use aliases to redirect traffic to a different address. This translates the destination IP address.

    In your config file looks like

    (inside) alias x.x.x.x y.y.y.y 255.255.255.255

    alias (dmz) x.x.x.x y.y.y.y 255.255.255.255

    they have already been configured using

    static (inside, dmz) x.x.x.x y.y.y.y netmask 255.255.255.0 0 0

    public static (inside, outside) x.x.x.x y.y.y.y netmask 255.255.255.255 0 0

    A kind... I suggest to remove... then type in clear xlate (this interrupts your current connections for a few seconds)... and test to make sure that everything is OK and finally save the changes wr mem.

    I hope this helps... Please, write it down if she does! ..

  • Hi, I just bought a macbook pro 13 ", however it has no ethernet port, have I need to buy a device of air port and what one do need me?

    I just bought a macbook pro 13 ", however it has no ethernet port, have I need to buy a device of air port and what one do need me?

    Your MacBook Pro has built in WiFi.

    Wi - Fi

    802.11ac wireless Wi - Fi network; IEEE 802.11a/b/g/n compatible

    It is the best way to connect. You will need a router if you don't already have one.

    If you want to use ethernet wire you can use this cable. ter http://www.apple.com/shop/product/MD463LL/A/thunderbolt-to-gigabit-ethernet-adap? fnode = 8 b See the following link for more useful information if you are new to Mac.

    Kim

  • I have a mouse Microsoft Wireless Mobile 4000 and it won't work in the USB port that I need.

    The port that I need for work is where I took out the logitech corded mouse.   How can I fix it?  It works in another port, but not the one I want.

    Hello

    1 did you changes to the computer?

    2. you receive an error message?

    Method 1:

    I suggest you run the Microsoft fixit tool and check.

    Hardware devices do not work or are not detected in Windows FIX IT:

    http://support.Microsoft.com/mats/hardware_device_problems

    Method 2:

    I suggest you to see link and check.

    Open the hardware and devices Troubleshooter

    http://Windows.Microsoft.com/en-us/Windows7/open-the-hardware-and-devices-Troubleshooter

    Method 3:

    I also suggest you to see the links and check.

    I would say as update you the USB drivers and check.

    Update of the hardware driver that is not working properly:

    http://Windows.Microsoft.com/en-us/Windows7/update-a-driver-for-hardware-that-isn ' t-work correctly

    What to do when a device is not installed correctly:

    http://Windows.Microsoft.com/en-us/Windows7/what-to-do-when-a-device-isn ' t-installed-correctly

  • My Hotmail account has been hacked and translated into Arabic... even my contacts. I need English translation assistance.

    My Hotmail account has been hacked... and the pirates were obviously Arabic because they were able to get not only me, but all my contacts.  I was finally able to reset my password late last night.  But now when I go on my Hotmail I can't read my emails or anything like that because it's in Arabic, as are all my contacts.  I need to translate it into English, but I can't pass on each of these sites to you because all the titles at the top telling me 'before '... "delete", "Exit" is in Arabic and I do not read or speak the language.  This is why I can't convey all these pages to Bing or Google for a translation.  I need my account set to be translated into English.

    Hello

    The question you have posted is related to Windows Live and would be better suited to the Discussion Windows Live groups. Please visit the link below to find a community that will provide the support you want.

    Hotmail Portal

    http://windowslivehelp.com/product.aspx?ProductID=1

  • What NAT ports in the firewall for VMware View Server Security?

    We have a Cisco ASA and I wonder what are the ports I need NAT from the outside to the Security Server?  I'm assuming that port 443, but don't know if this is correct or if maybe other ports must be open.

    Thank you!

    Brian

    This KB should help you, http://kb.vmware.com/kb/1027217.

  • NAT / Port Forwarding WRV200

    Hi, I need access to a digital video recorder (192.168.3.200 port 12088) from the internet (Telenet/Belgium). I use a Cisco/Linksys WRV200 (192.168.3.254) to access the internet. I can access the WRV200 remotely (on the Internet) and I created then redirect the port: Port-8016-8016 > 192.168.3.200 Port 12088-12088 > 192.168.3.200 connect to the DVR internally works well, but to access the DVR from the outside does not work for some reason any. Any suggestions?

    These products are processed by the Cisco Small Business support community. (URL: https://supportforums.cisco.com/community/netpro/small-business )

  • NAT Ports inaccessible over the site to site VPN

    We have a series of 2900 SRI at HQ and several of Cisco WRVS4400N VPN routers to small branch offices. The branch offices are connected to HQ via IPSec site-to-site. Everything seems to work fine, except users in the box executive offices not access all the services on servers HQ where the port was NAT'd to the outside. For example, we organize Office services remotely via https, port 443 is NAT made appeal to the outside, but users in the branch offices cannot access this port. They receive a time-out error. I tried searching but all I can find is info on crossing IPSec NAT. thank you...

    With this config-NAT, your router ensures that the internal server has to be accessible by the public IP address. You can add a roadmap to your NAT static entry exempt of NAT VPN traffic. Which might look like the following:

    ip nat inside source static tcp 10.0.0.11 443 xxx.xxx.xxx.165 443 route-map SERVER-NAT extendable!ip access-list extended SERVER-NAT-ACL deny ip 10.0.0.0 0.255.255.255 10.0.0.0 0.255.255.255 permit ip any any!route-map SERVER-NAT permit 10 match ip address SERVER-NAT-ACL
  • Multiple outside NAT at the same internal IP address

    In my view, the answer is no, but wanted to check.

    Can I have multiple NATs on the same interface to a single internal IP?

    For example.

    static (inside, outside) a.a.a.2 10.20.30.248 netmask 255.255.255.255

    static (inside, outside) a.a.a.3 10.20.30.248 netmask 255.255.255.255

    Where the subnet and the IP block is also on for two external NATs.

    Hello

    If you try to do the following:

    definition of the IP 10.20.30.248 to a.a.a.2

    and

    definition of the IP 10.20.30.248 to a.a.a.3.

    Learn to translate the internal ip address to two external ip addresses. If Yes, then this is not possible.

    I hope this helps.

    Kind regards

    Anisha

    P.S.: Please mark this thread as answered, if you feel that your query is resolved. Note the useful messages.

  • DMVPN NAT - T emergency assistance?

    can someone please provide me with the DMVPN hub server configuration when the hub server is configured with nat?

    I will be grateful...

    Hi Mohammed,.

    I think you can visit these links:

    NAT-transparency aware DMVPN

    «Also added in versions IOS Cisco 12.3(9a) and 12.3 (11) T is the ability to make router DMVPN hub behind static NAT.» It was a change in the support of ISAKMP NAT - T. For this feature to use DMVPN spoke all routers and routers hub must be upgraded and IPsec must use the mode of transport.

    For the NAT-transparency aware improvements to work, you must use IPsec transport mode on the game of transformation. In addition, even if NAT-transparency (IKE and IPsec) can take in charge two peers (IKE and IPsec) translated the same IP address (using UDP ports to differentiate them), this feature is not supported for DMVPN. All rays DMVPN must have a unique IP address, after being translated NAT. They may have the same IP address before they translated NAT. »

    Public static NAT & DMVPN Hub ---> another similar post.

    It will be useful.

    Thank you.

    Portu

    Post edited by: Javier Portuguez

  • serious problem with HP support assistant needs to close

    Presario SG3-110UK

    I downloaded an update for Assistant help now some time ago and I get an error "this application has encountered a serious problem and needs to close"-button to close the application or restart. Reboot Gets the same message.

    I uninstalled and reinstalled the application several times. It works once and then I get the error message.

    How to load a picture so that you can see what I'm talking about?

    Hello

    Try the following

    Firstly, uninstall your current version of HP Support Assistant using Microsoft 'Fixit' at the following link: this is particularly useful for correcting problems that may prevent resettlement on the machines running a 64 bit OS.

    http://support.Microsoft.com/mats/Program_Install_and_Uninstall

    When this has completed, restart the computer.

    Then download and install the latest version of HP Support Assistant of the page on the link below - the download links are to the bottom of the page.

    http://h18021.www1.HP.com/helpandsupport/HP-support-Assistant.html

    After installation, restart the computer again.

    Kind regards

    DP - K

  • Assistance needed: average N amount of waveforms

    Hello

    First of all, I have my apologies to re-post this topic, but I didn't help I need the last time I asked, probably because I didn't clearly what my problem was. So here goes...

    What I need is for some genius here to show me how the average amount of N of waveforms. I am able fluctuations of current in a specific time window (this depends on the amount of samples and of course sampling rate that I use).

    Currently, I record quantity N of waveforms (time series), but what I want to do is only to record an average undulating, e.g. n1 + n2 + n3/N (N = 3).

    I gave it a go using a loop, but it didn't give me the results I want (I know what's the problem with him, but don't know how to produce the waveform on the average).

    In summary to be as clear as I can be,

    (1) I am recording N waveforms of the DAQ Assistant

    (2) I want to collect in a queue and then take the average of the N wave

    (3) save the medium wave to my function write.

    Attached are 2 versions of LabView to my project.

    I would really get this spot and exploit this week if possible and would be very grateful for help in changing my vi.

    Thank you very much for reading!

    12.


  • Open Nat / Port before Xbox

    I use Cisco Cloud to connect to connect to my router E4200. I want to open my NAT type currently average on all games.

    Where the hell is the box add the ranges of ports? Is it still an option on the new cloud connect? If this is the case, it only makes it very easy to find. Could be given easier if you had a 'Games/Applications' tab/app as you did previously.

    Any help appreciated.

    It is safe

Maybe you are looking for

  • How can I get App Tabs to open on the location of the bookmark rather than the last visited one?

    For example, I have YouTube as an App tab. Everytime I open firefox the last think I watched on YouTube starts to play again. I would really like to put so the App tabs open on any page I put initially for.

  • Satellite C660-121 can not verify the recovery disk

    I bought a couple of days a go a new Satellite C660-121. Today, I went to do the recovery disks, but it fails to check the first DVD disc.The error I get is the followinghttp://img231.imageshack.us/i/failedcopy.PNG/ E:\ is the name of the DVD player.

  • Windows update fails to install with error 57F

    Since June 11 3 updates of MS - Office Outlook KB 970011, MS Word KB 969603 & MS Excel KB969681 failed to install. The error code is 57thThis happens every time the pc is switched on/off.I tried to install manually via start / all programs/windows up

  • BlackBerry Smartphones adding pop3 e-mail is not an option?

    I just bought a new 8310 on eBay because my last one had fallen into the water and wound up being cheaper for me. The phone is new (as far as I can tell) and shows no sigs usage, at all. I'm having a problem well and hope someone could me the tsar in

  • O as devo fazer para recover a DLL java 6

    I tried instalar java 6 by fazer declaracao 2009, como deu problema incompatibilidade POI EU had java o 7 wont, fiz has e desinstalacao com desapareceu uma DLL, e isto não sei qual e, como fazer para reparar este problema.