- Posts: 1390
- Thank you received: 0
Opening Port Range for Cisco ASA 5505
15 years 9 months ago #29157
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: Opening Port Range for Cisco ASA 5505
The Global command shouldn't be necessary. All this command is for really is for specifying your outbound NATting.
The Static NAT should work without the public IP address being specified as the static nat will add this to your external for you.
The Static NAT should work without the public IP address being specified as the static nat will add this to your external for you.
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
15 years 9 months ago #29188
by jhun
Replied by jhun on topic Re: Opening Port Range for Cisco ASA 5505
Thanks smurf
Hhhmmm..that's a little bit weird then, because when I've used the command that SOlo had outlined, it did not work. When I've added the global command, things started working.
I'll experiment more on this.
Thanks
Hhhmmm..that's a little bit weird then, because when I've used the command that SOlo had outlined, it did not work. When I've added the global command, things started working.
I'll experiment more on this.
Thanks
15 years 9 months ago #29213
by S0lo
Studying CCNP...
Ammar Muqaddas
Forum Moderator
www.firewall.cx
Replied by S0lo on topic Re: Opening Port Range for Cisco ASA 5505
I don't see why it can't work without the global . global works in conjunction with the nat command to do dynamic NAT for outbound traffic. But your running a server, the static NAT should be enough!!. Can you post your config and drop a few details about what you're trying to do? You can mask out any private info from the config.
Studying CCNP...
Ammar Muqaddas
Forum Moderator
www.firewall.cx
15 years 9 months ago #29227
by Smurf
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
Replied by Smurf on topic Re: Opening Port Range for Cisco ASA 5505
To be honest i have never tried it but in theory i dont see why the global command is needed if you are only using a StaticNAT.
Hmm, i have myself pondering now, not got my Cisco kit yet though so cannot test it (well, i have my Cisco 2950 Switch and 2 x Cisco 2611 routers but not my Pix515 and ASA5510....but they will be coming )
Hmm, i have myself pondering now, not got my Cisco kit yet though so cannot test it (well, i have my Cisco 2950 Switch and 2 x Cisco 2611 routers but not my Pix515 and ASA5510....but they will be coming )
Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
15 years 9 months ago #29236
by jhun
Replied by jhun on topic Re: Opening Port Range for Cisco ASA 5505
hi guys,
just to confirmed, yes it will work without the additional global command. I've just tried it and tested.
Now I'm wondering why it was not working the first time. Well, anyways I guess I'll investigate this more once I have the time.
Thanks again for all the help.
just to confirmed, yes it will work without the additional global command. I've just tried it and tested.
Now I'm wondering why it was not working the first time. Well, anyways I guess I'll investigate this more once I have the time.
Thanks again for all the help.
15 years 9 months ago #29241
by S0lo
Glad it worked
Studying CCNP...
Ammar Muqaddas
Forum Moderator
www.firewall.cx
Replied by S0lo on topic Re: Opening Port Range for Cisco ASA 5505
hi guys,
just to confirmed, yes it will work without the additional global command. I've just tried it and tested.
Now I'm wondering why it was not working the first time. Well, anyways I guess I'll investigate this more once I have the time.
Thanks again for all the help.
Glad it worked
Studying CCNP...
Ammar Muqaddas
Forum Moderator
www.firewall.cx
Time to create page: 0.158 seconds