This is well documented in the Cisco ASA Configuration Guide. Your DMZ host will now be accessible at ftp: //10.177.5.40. Nat (dmz,outside) static interface service tcp ftp ftp Then you will create an object for your DMZ host and use a static 'nat' statement with the service keyword to create a port-level static PAT for your object, like so: object network DMZHOST For example, assuming you have something like: interface Ethernet0/2
You can do this for any port, but each port can only be forwarded to one internal device using a static PAT statement. You can do a static PAT (Port Address Translation) to forward specific ports for an IP (including the ASA's interface IP) to different internal devices.