ASA version prior to 8.3  ciscoasa(config)# static (inside , outside) tcp interface 3389 192.168.1.10 3389 netmask 255.255.255.255  ciscoasa(config)# access-list OUTSIDE-IN extended permit tcp any any eq 3389  ciscoasa(config)# access-group OUTSIDE-IN in interface outside   ASA version 8.3 and later  ciscoasa(config)# object network RDP_static  ciscoasa(config-network-object)# host 192.168.1.10  ciscoasa(config-network-object)# nat (inside , outside) static interface service tcp 3389 3389  ciscoasa(config)# access-list OUTSIDE-IN extended permit tcp any host 192.168.1.10 eq 3389  ciscoasa(config)# access-group OUTSIDE-IN in interface outside   NOTE:  Notice that in version 8.3 we reference the Real IP address (192.168.1.10) in the access-list and not the mapped IP