I have a 515e, 6.3(4) with an internal interface and a DMZ. The DMZ interface is 10.0.20.1 and the outside interface is 69.xxx.yyy.188/28
I have setup a web server which is currently the only device in the DMZ. I need to make a static mapping to this box but for some reason I just can't get it to work. The web server's local address is 10.0.20.100 and the public address that I need to statically map it to is 69.xxx.yyy.187/28
Here's my config so far:
interface ethernet0 100full
interface ethernet1 100full
interface ethernet2 100full
nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 dmz security50
ip address outside 69.xxx.yyy.188 255.255.255.240
ip address inside 192.168.20.1 255.255.255.0
ip address dmz 10.0.20.1 255.255.255.0
access-list dmz_in permit ip any any
access-list outside_in permit ip host 69.xxx.yyy.187 any
global (outside) 1 interface
global (dmz) 1 10.0.20.110-10.0.20.120
nat (inside) 1 Inside_LAN 255.255.255.0 0 0
nat (dmz) 1 dmz 255.255.255.0 0 0
static (outside,dmz) 10.0.20.100 69.xxx.yyy.187 netmask 255.255.255.255 0 0
access-group outside_in in interface outside
access-group dmz_in in interface dmz
I have the access-lists open for troubleshooting purposes... The global (dmz) statement is temporary so that I can access the DMZ from my inside network.
Any help would be greatly appreciated.
Haha, no offense you never know who you're dealing with. There was a similar post here within the last few days. I believe it was an arp issue on the isp router. Something to consider.