NAT range of ports on Cisco ASA
NAT a range of ports on a Cisco ASA for FTP use.
In this example I need SSL support, passive ports.
object-group service PassiveFTP tcp
port-object range 60000 60015
static (inside,outside) tcp interface ftp 192.168.1.20 ftp netmask 255.255.255.255
access-list allow_inbound extended permit tcp host host object-group PassiveFTP
access-list allow_inbound extended permit tcp host interface outside eq ftp
static (inside,outside) tcp interface 60000 192.168.1.20 60000 netmask 255.255.255.255
static (inside,outside) tcp interface 60001 192.168.1.20 60001 netmask 255.255.255.255
static (inside,outside) tcp interface 60002 192.168.1.20 60002 netmask 255.255.255.255
static (inside,outside) tcp interface 60003 192.168.1.20 60003 netmask 255.255.255.255
static (inside,outside) tcp interface 60004 192.168.1.20 60004 netmask 255.255.255.255
static (inside,outside) tcp interface 60005 192.168.1.20 60005 netmask 255.255.255.255
static (inside,outside) tcp interface 60006 192.168.1.20 60006 netmask 255.255.255.255
static (inside,outside) tcp interface 60007 192.168.1.20 60007 netmask 255.255.255.255
static (inside,outside) tcp interface 60008 192.168.1.20 60008 netmask 255.255.255.255
static (inside,outside) tcp interface 60009 192.168.1.20 60009 netmask 255.255.255.255
static (inside,outside) tcp interface 60010 192.168.1.20 60010 netmask 255.255.255.255
static (inside,outside) tcp interface 60011 192.168.1.20 60011 netmask 255.255.255.255
static (inside,outside) tcp interface 60012 192.168.1.20 60012 netmask 255.255.255.255
static (inside,outside) tcp interface 60013 192.168.1.20 60013 netmask 255.255.255.255
static (inside,outside) tcp interface 60014 192.168.1.20 60014 netmask 255.255.255.255
static (inside,outside) tcp interface 60015 192.168.1.20 60015 netmask 255.255.255.255