artofrf.com

Ali's Technology Blog

Menu
  • Home
  • Important Links
  • About Me
  • Tools and Scripts
Menu

ASA 8.4 NAT with specific ports

Posted on May 22, 2013December 16, 2019 by mali

Cisco ASA NAT specific ports TCP/UDP Version 8.4

So we all are pretty much used to the new Cisco ASA 8.3+ NAT, Auto NAT and Twice NAT. I am writing this article on, “how to NAT single or multiple specific ports to a single Public IP address”. When and why would you want to do this? Well some companies can’t afford to have a huge range of Public IP addresses and/or they might be running out or they have way to many internal servers/resources. Using this method Public IP’s can be conserved and can be used for multiple internal resources instead of just one.

Scenario 1

First let me give you an example if you just want to simply NAT an internal IP to a Public IP on Cisco ASA running version 8.4. Example, we have an internal IP of 10.1.1.10 and Public IP of 1.1.1.1:

object network obj-10.1.1.10
host 10.1.1.10
nat (inside,outside) static 1.1.1.1

That is it now you can create an access list for the specific need you have for that server lets say people from the outside need to access it over 443:

access-list outside_in extended permit tcp any gt 1024 host 10.1.1.10 eq 443

Scenario 2

Now some one from the outside can type “https://1.1.1.1” or associated FQDN and access this web server. But what happens if you need another Public IP address for another internal resource and need 22 (ssh) opened up for it. You already used up your last IP address. So when I ran into such issue I did this:

object network obj-10.1.1.10 (Server 1)
host 10.1.1.10
exit
object network obj-10.1.1.20 (Server 2)
host 10.1.1.20
exit
object network obj-1.1.1.1 (Public IP)
host 1.1.1.1
exit
object service HTTPS (Created a service object for HTTPS)
service tcp source eq 443
exit
object service SSH (Created a service object for SSH)
service tcp source eq 22
exit
nat (inside,outside) source static obj-10.1.1.10 obj-1.1.1.1 service HTTPS HTTPS (NAT1-SERVER1)
nat (inside,outside) source static obj-10.1.1.20 obj-1.1.1.1 service SSH SSH (NAT2-SERVER2)

access-list outside_in extended permit tcp any gt 1024 host 10.1.1.10 eq 443
access-list outside_in remark **** Access list for Server 1 HTTPS Access ****
access-list outside_in extended permit tcp any gt 1024 host 10.1.1.20 eq 22
access-list outside_in remark **** Access list for Server 2 SSH Access ****

Using this method I was able to use a single Public IP and assign it to multiple internal servers on different Ports i.e 443 and 22. Now if someone uses 443 for the public IP of 1.1.1.1 they will get to the internal server 10.1.1.10. Now if someone uses SSH to the Public IP 1.1.1.1 they will get to the Internal server 10.1.1.20. Similarly I can utilize this one Public IP Address and assign it to other internal resources and other ports such as 21, 80, 25 etc

Note:Use this as a reference point only. There are other configuration options available to tweak this according to your needs. Remember to always backup your work before you make any changes, always test configurations in the lab and never do anything that you can not undo

Category: Cisco Security

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • Nile Secure Guest – Configuration and Use Case
  • WLAN Pros Toolbox
  • Nile does NAC – Configuring Trust Engine
  • WLAN Validator
  • PCAP I/O Graph Analyzer

Tags

AirDrop arista Arista AGNI Arista CV-CUE Arista NAC Arista WIPS Arista WPA3 UPSK Aruba Central Automating Mist Switch Templates Automation AWDL Configuring Switch Templates in Mist CWAP 403 EAP Format MAC Addresses Hamina Network Planner Juniper SRX300 MacBook Marvis mdns MFD8 MFD9 Mist Access Assurance MistAI Mist Auto Placement Mist MPSK Mist Wireless NaaS Networking Field Day NFD32 NileNav Nile Secure Nile Wi-Fi Social Channels Tech Field Day Troubleshooting with Marvis Troubleshooting with Mist Troubleshooting with Mist AI Troubleshooting with Wireshark Wireless Adjuster Wireless Adjuster Level II Wireless troubleshooting WLPC wlpc2023 Wyebot

Tech Blogs

  • WiFiTodd
  • CCNA Wireless
  • Cisco Full Bars
  • Packet Life
  • Havilandweb
  • Gjermund Raaen
  • Bad-Fi
  • The ASCII Construct
  • Juniper Port Checker
  • WiFrizzy
  • Spectrum Chart
  • BadgerWiFi

Recent Comments

  • Hiten Thakkar on PCAP I/O Graph Analyzer
  • mali on Deploying Nile Secure – My First NSB
  • Larry Farrish on Deploying Nile Secure – My First NSB
  • Courtney on Mist Access Point – CSV
  • ayoub chabrouk on Ubiquiti stealing the show at MFD11

Archives

  • August 2026
  • July 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • May 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • November 2018
  • October 2018
  • September 2018
  • May 2018
  • January 2018
  • December 2017
  • August 2017
  • January 2017
  • September 2014
  • December 2013
  • October 2013
  • May 2013
  • August 2012
  • July 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • AeroHive
  • Arista
  • Arista
  • Aruba
  • Aruba
  • Aruba Central
  • BYoD
  • Certifications
  • Cisco
  • Cisco
  • Cisco EEM Scripting
  • Cisco Routing
  • Cisco Security
  • Cisco VoIP
  • Cisco VPN
  • Cisco Wireless
  • Conferences and Meetings
  • Design
  • Ekahau
  • General
  • Hamina
  • IoT, IIoT, OT
  • Juniper Security
  • Juniper Switching
  • Juniper/Mist
  • Linux
  • Microsoft
  • Mist
  • Mist Wireless
  • Nile
  • Nile Secure
  • Nile Wi-Fi
  • Programming/Automation
  • Python
  • Ruckus
  • Ruckus Wireless
  • Ruckus/Brocade
  • Ruckus/Brocade Scripting
  • Ruckus/Brocade Switching
  • Secure Guest Service
  • Security
  • Switching
  • Tools
  • Troubleshooting
  • Trust Engine
  • Uncategorized
  • Windows
  • Wireless
  • Wireless
  • WLAN Tools
© 2026 artofrf.com | Powered by Minimalist Blog WordPress Theme