Networks

Question

Locked

Asa Dmz Config

By alarbed ·
Hi Experts,

I have an issue with NAT, while configuring three zones asa implementation (Outside/Dmz/Inside).

Objective is:
Allow all inside to internet
Allow Dmz to internet (OS/Apps updates)
Allow some services/ports from internet to Dmz
Allow some services/port from internet to inside

ACL's working fine, but NAT is not, here what I am doing:


Dmz: 192.168.2.0 255.255.255.0
Inside: 192.168.1.0 255.255.255.0
Outside: 1.1.1.1

! Dynamic NAT for both Inside & DMZ to Internet
global (outside) 100 interface
nat (Dmz) 100 192.168.2.0 255.255.255.0
nat (inside) 100 192.168.1.0 255.255.255.0

! public address to server in DMZ
static (Dmz,outside) 1.1.1.3 192.168.2.20 netmask 255.255.255.255
! public address to server in Inside
static (inside,outside) 1.1.1.2 192.168.2.30 netmask 255.255.255.255
! allow webserver to access DB Servers inside
static (Dmz,inside) 192.168.1.20 192.168.2.20 netmask 255.255.255.255

The point is, when I configure the above, Dmz zone to inside does not work!
but when I stop "static (Dmz,Inside)", all the inside loose the connection to the net, but all other direction work fine!

Any idea why?

Thanks

This conversation is currently closed to new comments.

Thread display: Collapse - | Expand +

All Answers

Collapse -

One thought

by NetMan1958 In reply to Asa Dmz Config

I don't know if this is causing your problem but it doesn't look right. According to this:
"Inside: 192.168.1.0 255.255.255.0"
you are using 192.168.1.0/24 on your LAN(inside). But you have this:
"! public address to server in Inside
static (inside,outside) 1.1.1.2 192.168.2.30 netmask 255.255.255.255 "
Unless that is a mis-print, you are trying to static NAT the inside to an IP on the DMZ subnet.

Related Discussions

Related Forums