ASA 5510 - port forwarding to external

ASA 5510 - port forwarding to external

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
ASA 5510 - port forwarding to external Cowboy \(Gregory A. Beamer\) 07-23-2008
Posted by Cowboy \(Gregory A. Beamer\) on July 23, 2008, 10:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We have a VPN into our colocation facility and need to enable the following
scenarios for different vendors/clients.

1. Forward all messages on a port to a vendor/client address. Two options
here
a) Down another VPN on the ASA - preferred
b) Directly to an external address

2. Same as above, but also configure an internal route on the same port

We have been told by one consltant that this will probably require another
ASA, but I am not sure we are getting the correct answer. Does anyone know
if this is possible?

--
Gregory A. Beamer
MVP, MCP: +I, SE, SD, DBA

Subscribe to my blog
http://gregorybeamer.spaces.live.com/lists/feed.rss

or just read it:
http://gregorybeamer.spaces.live.com/

********************************************
| Think outside the box! |
********************************************


Network Magic Graduation 20% off animated banner
Posted by Artie Lange on July 24, 2008, 7:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Cowboy (Gregory A. Beamer) wrote:
> We have a VPN into our colocation facility and need to enable the
> following scenarios for different vendors/clients.
>
> 1. Forward all messages on a port to a vendor/client address. Two
> options here
> a) Down another VPN on the ASA - preferred
> b) Directly to an external address
>
> 2. Same as above, but also configure an internal route on the same port
>
> We have been told by one consltant that this will probably require
> another ASA, but I am not sure we are getting the correct answer. Does
> anyone know if this is possible?
>

Are the different vendors on different subnets? If so I do not see any
reason why you would not be able to create ACL's sufficient to restrict
traffic to the specified ports/IP address.


http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml


Posted by Cowboy \(Gregory A. Beamer\) on July 24, 2008, 10:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
That is what I thought, as well. I am just not very Cisco savvy, so I
figured I would ping.

--
Gregory A. Beamer
MVP, MCP: +I, SE, SD, DBA

Subscribe to my blog
http://gregorybeamer.spaces.live.com/lists/feed.rss

or just read it:
http://gregorybeamer.spaces.live.com/

********************************************
| Think outside the box! |
********************************************
> Cowboy (Gregory A. Beamer) wrote:
>> We have a VPN into our colocation facility and need to enable the
>> following scenarios for different vendors/clients.
>>
>> 1. Forward all messages on a port to a vendor/client address. Two options
>> here
>> a) Down another VPN on the ASA - preferred
>> b) Directly to an external address
>>
>> 2. Same as above, but also configure an internal route on the same port
>>
>> We have been told by one consltant that this will probably require
>> another ASA, but I am not sure we are getting the correct answer. Does
>> anyone know if this is possible?
>>
>
> Are the different vendors on different subnets? If so I do not see any
> reason why you would not be able to create ACL's sufficient to restrict
> traffic to the specified ports/IP address.
>
>
>
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml
>


Posted by Artie Lange on July 24, 2008, 10:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Cowboy (Gregory A. Beamer) wrote:
> That is what I thought, as well. I am just not very Cisco savvy, so I
> figured I would ping.
>

No problem, if you need further help with the design or config, post
some additional details and the people of the group should be able to
assist you!


Similar ThreadsPosted
Re: External request to a port which is not NATED by the Cisco ASA 5510 : How is this possible ? June 3, 2008, 3:30 am
Port forwarding from cisco 2600 to ASA-5510 July 20, 2006, 10:23 am
redirect external tcp port to another outside host March 5, 2008, 12:24 pm
Port forwarding February 2, 2006, 3:05 pm
Port forwarding help? June 4, 2006, 10:23 pm
Need help Port forwarding on PIX 501 September 14, 2006, 9:18 am
Port 21 forwarding on PIX 501 September 15, 2006, 11:56 pm
PIX Port Forwarding November 15, 2006, 2:42 pm
port forwarding December 13, 2006, 9:39 am
Port Forwarding October 7, 2008, 9:36 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map