Skip to main content

Opening Port Range for Cisco ASA 5505

More
15 years 2 months ago #29157 by Smurf
The Global command shouldn't be necessary. All this command is for really is for specifying your outbound NATting.

The Static NAT should work without the public IP address being specified as the static nat will add this to your external for you.

Wayne Murphy
Firewall.cx Team Member
www.firewall.cx

Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
More
15 years 2 months ago #29188 by jhun
Thanks smurf
Hhhmmm..that's a little bit weird then, because when I've used the command that SOlo had outlined, it did not work. When I've added the global command, things started working.

I'll experiment more on this.

Thanks
More
15 years 2 months ago #29213 by S0lo
I don't see why it can't work without the global :?. global works in conjunction with the nat command to do dynamic NAT for outbound traffic. But your running a server, the static NAT should be enough!!. Can you post your config and drop a few details about what you're trying to do? You can mask out any private info from the config.

Studying CCNP...

Ammar Muqaddas
Forum Moderator
www.firewall.cx
More
15 years 2 months ago #29227 by Smurf
To be honest i have never tried it but in theory i dont see why the global command is needed if you are only using a StaticNAT.

Hmm, i have myself pondering now, not got my Cisco kit yet though so cannot test it (well, i have my Cisco 2950 Switch and 2 x Cisco 2611 routers but not my Pix515 and ASA5510....but they will be coming ;) )

Wayne Murphy
Firewall.cx Team Member
www.firewall.cx

Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
More
15 years 2 months ago #29236 by jhun
hi guys,


just to confirmed, yes it will work without the additional global command. I've just tried it and tested.

Now I'm wondering why it was not working the first time. Well, anyways I guess I'll investigate this more once I have the time. :wink:

Thanks again for all the help.
More
15 years 2 months ago #29241 by S0lo

hi guys,


just to confirmed, yes it will work without the additional global command. I've just tried it and tested.

Now I'm wondering why it was not working the first time. Well, anyways I guess I'll investigate this more once I have the time. :wink:

Thanks again for all the help.


Glad it worked :)

Studying CCNP...

Ammar Muqaddas
Forum Moderator
www.firewall.cx
Time to create page: 0.151 seconds