User's Manual

Table Of Contents
Firewall
Firewall Access Rule Configuration Examples
Cisco ISA500 Series Integrated Security Appliance Administrator Guide 189
6
Allowing Inbound Traffic to the RDP Server using a Specified Public IP address
User Case: You host a RDP server on the DMZ. Your ISP has provided a static IP
address that you want to expose to the public as your RDP server address. You
want to allow Internet user to access the internal RDP server by using the
specified public IP address.
Solution: You can create a port forwarding rule or an Advanced NAT rule and a
firewall access rule as follows to allow inbound traffic to the RDP server.
Problem: DMZ Wizard?
STEP 1 Set the IP address of 172.39.202.101 to the WAN interface.
STEP 2 Create a host address object with the IP 192.168.12.101 called “RDPServer” and a
host address object with the IP 172.39.202.102 called “PublicIP”.
STEP 3 Create a TCP service object with the port range from 3389 to 3389 called “RDP”.
STEP 4 Go to the Firewall -> NAT -> Port Forwarding page to create a port forwarding
rule as follows.
STEP 5 Or go to the Firewall -> NAT -> Advanced NAT page to create an Advanced NAT
rule as follows.
Original Service RDP
Translated Service RDP
Translated IP RDPServer
WAN WAN1
WAN IP PublicIP
Enable Port Forwarding On
From WAN1
To DMZ
Original source address ANY
Original destination
address
PublicIP