Hi,
I'm reasonably new to Cisco ASA firewalls and I'm having trouble getting one to work as an internal firewall on my network. Its replacing a Sonicwall 3600 firewall.
Here's what I'm trying to do:
I have a production network (outside - security level 0) (PLC's, old PC's etc.) which is on the 192.168.131.0/24 range. I have a server network (inside - security level 100) which is on the 10.39.192.0/22 range.
The devices on the production network are all PLC's and old PC's and I can't change the config. In order for servers on the server network to pull information from them I've enabled a dynamic NAT rule on the firewall so all traffic coming from the server network is NAT'd behind the IP of the firewall interface on the production network. This works fine, I can ping devices on the production network and my application works no problem.
Now I have a requirement to allow traffic from the production network access devices on the server network. I have a new PC on the production network and its default gateway is the firewall interface IP. I've created a rule to allow it Remote Desktop to a server on the server network (10.39.193.55) but when I attempt to connect I get the following error in the logs:
"No translation group found for tcp outside:192.168.131.222/46195 dst inside: 10.39.193.55/3389"
I've tried a few different rules to get it working but no matter what I do I get the same error. Would anyone be able to help? What I need is for the firewall not to NAT traffic from production to server networks but maintain the NAT from the server to the production network (disabling this will allow the traffic from the production to the server network strangly enough!)
Thanks in advance,
P
I'm reasonably new to Cisco ASA firewalls and I'm having trouble getting one to work as an internal firewall on my network. Its replacing a Sonicwall 3600 firewall.
Here's what I'm trying to do:
I have a production network (outside - security level 0) (PLC's, old PC's etc.) which is on the 192.168.131.0/24 range. I have a server network (inside - security level 100) which is on the 10.39.192.0/22 range.
The devices on the production network are all PLC's and old PC's and I can't change the config. In order for servers on the server network to pull information from them I've enabled a dynamic NAT rule on the firewall so all traffic coming from the server network is NAT'd behind the IP of the firewall interface on the production network. This works fine, I can ping devices on the production network and my application works no problem.
Now I have a requirement to allow traffic from the production network access devices on the server network. I have a new PC on the production network and its default gateway is the firewall interface IP. I've created a rule to allow it Remote Desktop to a server on the server network (10.39.193.55) but when I attempt to connect I get the following error in the logs:
"No translation group found for tcp outside:192.168.131.222/46195 dst inside: 10.39.193.55/3389"
I've tried a few different rules to get it working but no matter what I do I get the same error. Would anyone be able to help? What I need is for the firewall not to NAT traffic from production to server networks but maintain the NAT from the server to the production network (disabling this will allow the traffic from the production to the server network strangly enough!)
Thanks in advance,
P