Network Setup (NAT vs static route)



I have some questions regarding NAT vs static routing.

Here is the physical setup:
LAN-------ROUTER-------INTERNET
|
|
DMZ

Router is an 1811
Both servers in DMZ (call them DMZ1 and DMZ2) have at least 2 NICs
We have three public IP addresses

Right now, this is the logical setup:

LAN uses 10.0.0.0/21
DMZ uses 10.0.8.0/21
Router is 10.0.3.1
Router's FE0 is A.A.A.A and A.A.A.A is also dynamic NAT for LAN
B.B.B.B is static NAT to DMZ1
C.C.C.C is static NAT to DMZ2

So, the question is this:
Would it be better to just use static routes for the DMZ?
If not, what is the advantage to using NAT in the DMZ rather than
static routes?
I had tried static routes before, and it solved the problem of needing
split dns for internal/external access to the DMZ.
One thing that strikes me as odd is that, using NAT, the router is the
endpoint of any trace to DMZ1 or DMZ2, when, in my mind, it should
simply be a hop between them.


Would it also be advisable to set up a separate VLAN for the DMZ, as
well?

.



Relevant Pages

  • Re: Trying to connect to a Viewstation
    ... > At work we have a Video Conferencing Device, a Polycom Viewstation ... > It is in the DMZ of our 3com Superstack firewall but to avoid problems ... > SMC wireless router (NAT, ... > In France we use ADSL with a Netopia Cayman 3341 router. ...
    (microsoft.public.internet.netmeeting)
  • Re: Static Translations Disappearing
    ... this router and see if they have the same behavior. ... you are running into a NAT bug. ... It wouldn't hurt to change IOS and ... ....where it just shows all translations being dynamic (0 static, ...
    (comp.dcom.sys.cisco)
  • Re: SMTP server behind an ADSL Switch?
    ... It is definitely not a NAT default host. ... >differences of a commercial grade and a home DSL router for 50 bucks ... Still in both cases the system in the DMZ are in front of the ...
    (comp.os.vms)
  • Re: moved a working network, now it doesnt work
    ... router I can ping the internet with no problem. ... From one of your Linux machines can you ping the FA 0/1 interface (default ... are NOT natting so if CAN ping from the router, ...
    (comp.dcom.sys.cisco)
  • Re: IP Route Tables - Point to Point Connection - Only Routing 1 way
    ... Your ksshorley1 router is performing network address translation (NAT) on ... default route command. ...
    (comp.dcom.sys.cisco)