Cisco 2901 router static route

Associate
Joined
12 Oct 2004
Posts
1,432
Location
Aberdeen, Scotland
Hi guys, I'm a complete Cisco newb, and need some help if you'd be so kind! I've got an internal ESET server that I need to allow an external cloud hosted Labtech server to connect directly to it along with endpoint agents, the ports this communicate on are TCP 2222 and 2223. So ideally I need a static route that says all traffic on ports 2222 and 2223 be directed to the internal IP of the ESET server.

From looking at an old ASA5510 I've used before, we had something similar configured, and so I've taken lines from that and modified, if I add the following, do you think it'll work?:

permit tcp any any eq 2222
permit tcp any any eq 2223

static (inside,outside) tcp ext_IP_of_Router 2222 internal_ESET_IP 2222 netmask 255.255.255.255 tcp 512 256
static (inside,outside) tcp ext_IP_of_Router 2223 internal_ESET_IP 2223 netmask 255.255.255.255 tcp 512 256

If I'm on the right track... how do I go and add then go and add this to the running config?

Thanks guys :)
 
Last edited:
Thanks for the reply:

Basically I have a server in the cloud that I have pointed to the public facing external IP of our in-house router, I need to configure a static route/port forward that will allow any external traffic that hits our router on ports 2222 and 2223 to flow through to a server sitting behind the router on an internal IP address. I only want this to happen for those specific ports, and I'm not sure how to go about it on the router.

Cheers
 
Last edited:
Would this do it?

ip nat inside source static tcp internal_Server_IP 2222 Router_Public_IP 2222 extendable

Or should the Router_Public_IP above be the IP address of the external cloud server trying to connect in? In which case, is there a way to allow all traffic to port 2222 to route to the internal server IP instead of locking it down to a single external IP?
 
Last edited:
Thanks for that, very helpful. The internal subnet that the ESET server sits on is VLANed, and looking at the config it's configured under interface GigabitEthernet0/1.100, should I change the NAT rule above to reflect that too?
 
Back
Top Bottom