Question

Locked

Asa Dmz Config

By alarbed ·
Hi Experts,

I have an issue with NAT, while configuring three zones asa implementation (Outside/Dmz/Inside).

Objective is:
Allow all inside to internet
Allow Dmz to internet (OS/Apps updates)
Allow some services/ports from internet to Dmz
Allow some services/port from internet to inside

ACL's working fine, but NAT is not, here what I am doing:


Dmz: 192.168.2.0 255.255.255.0
Inside: 192.168.1.0 255.255.255.0
Outside: 1.1.1.1

! Dynamic NAT for both Inside & DMZ to Internet
global (outside) 100 interface
nat (Dmz) 100 192.168.2.0 255.255.255.0
nat (inside) 100 192.168.1.0 255.255.255.0

! public address to server in DMZ
static (Dmz,outside) 1.1.1.3 192.168.2.20 netmask 255.255.255.255
! public address to server in Inside
static (inside,outside) 1.1.1.2 192.168.2.30 netmask 255.255.255.255
! allow webserver to access DB Servers inside
static (Dmz,inside) 192.168.1.20 192.168.2.20 netmask 255.255.255.255

The point is, when I configure the above, Dmz zone to inside does not work!
but when I stop "static (Dmz,Inside)", all the inside loose the connection to the net, but all other direction work fine!

Any idea why?

Thanks

This conversation is currently closed to new comments.

2 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Answers

Collapse -

One thought

by NetMan1958 In reply to Asa Dmz Config

I don't know if this is causing your problem but it doesn't look right. According to this:
"Inside: 192.168.1.0 255.255.255.0"
you are using 192.168.1.0/24 on your LAN(inside). But you have this:
"! public address to server in Inside
static (inside,outside) 1.1.1.2 192.168.2.30 netmask 255.255.255.255 "
Unless that is a mis-print, you are trying to static NAT the inside to an IP on the DMZ subnet.

Back to Networks Forum
2 total posts (Page 1 of 1)  

Related Discussions

Related Forums