ASA version prior to 8.3 ciscoasa(config)# static (inside , outside) tcp interface 3389 192.168.1.10 3389 netmask 255.255.255.255 ciscoasa(config)# access-list OUTSIDE-IN extended permit tcp any any eq 3389 ciscoasa(config)# access-group OUTSIDE-IN in interface outside ASA version 8.3 and later ciscoasa(config)# object network RDP_static ciscoasa(config-network-object)# host 192.168.1.10 ciscoasa(config-network-object)# nat (inside , outside) static interface service tcp 3389 3389 ciscoasa(config)# access-list OUTSIDE-IN extended permit tcp any host 192.168.1.10 eq 3389 ciscoasa(config)# access-group OUTSIDE-IN in interface outside NOTE: Notice that in version 8.3 we reference the Real IP address (192.168.1.10) in the access-list and not the mapped IP