Re: ASA 5505 NAT/PAT static Question



In the message <498dcdfc$0$146$fb624d75@xxxxxxxxxxxxxxxxxxx> Colin Cant
wrote:

| Hi NG,
|
| i got following problem to solve:
|
| I got one single public ip address where by i PAT all my internal
| 192.168.X.Y networks.
| I got one DMZ interface using 192.168.2.X.
| I got internal hosts as example 192.168.3.X.
|
| now with the following config, my hosts from the internal network as well as
| the dmz hosts can get out to 0.0.0.0 without a problem.
|
| My current problem is, that i cannot connect from my internal 192.168.3.X
| network via my outside PAT address on to services with are hostet in the DMZ
| (192.168.2.X)
| what is the correct "static" config for connecting from inside via PAT
| address into my DMZ ?
|
| global (outside) 1 interface
| nat (inside) 0 access-list inside_nat0_outbound
| nat (inside) 1 0.0.0.0 0.0.0.0
| nat (dmz) 1 192.168.2.0 255.255.255.0
| static (dmz,outside) tcp interface www 192.168.2.XX www netmask
| 255.255.255.255 <-- DMZ Host

Why don't you connect to the DMZ address instead of the public address?

If it is because you don't have an inside DNS server and the dns name is
resolved to the public address then you can sort this out using dns
doctoring:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml
.



Relevant Pages

  • PAT --> DMZ --> Firewall --> LAN
    ... We just got a firewall and want to add it to our network. ... I am going to want to setup DNS on a box in the DMZ. ... that is translated by PAT to 10.10.1.1. ...
    (microsoft.public.windows.server.networking)
  • Re: Using Microsoft DNS for Public domains
    ... addresses that forward to my two nameserver DNS Servers on my home machine, ... the public IP addresses pointing to the internal DMZ IP addresses. ... >> name I registered two nameservers at my registrar. ... >> the internal DMZ IP of the primary DNS server. ...
    (microsoft.public.windows.server.dns)
  • Re: Domain Controller That Service a DMZ
    ... Where DNS resolution is done, and what resolution path is used, is ... you evidently have machines in that DMZ on which people can ... > for authentication, group policy, etc for the DMZ. ... > the DMZ to be able to use the DMZ domain controller to lookup the DNS ...
    (microsoft.public.windows.server.security)
  • Re: When you run Dcpromo.exe on Windows 2008 to create a replica domain controller, you receive a me
    ... A DMZ is used for servers that are accessed from the outside world with public ip addresses. ... so we can exclude DNS as a problem. ... server has no problem joining the domain. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Trusting external domain
    ... allow zone transfers to the IP's on the other domain's DNS servers. ... Create secondary DNS zones in each domain for the other domain (eg: ... down your firewall access from the DMZ to your internal domain). ...
    (microsoft.public.windows.server.active_directory)