Help with rule/nat on ASA 5520

Unanswered Question
Feb 2nd, 2009

Hi,

I hope this is possible.

I have a Cisco ASA 5520 with 2 DMZ's (on a Cisco 3750 trunked from the ASA).

One DMZ1 (172.24.0.0/24) has our webservers and DMZ2 (10.10.0.0/16) has a remote company with servers we use.

Now they have as me to prepare routing on my ASA so if they send data to 192.168.200.22 port 703 is will instead go to 172.23.0.18 port 703 which is our web vlan.

Not sure why they are sending to 192.168.200.22 yet on 702, but I need to get our ASA to respond to this request on 172.23.0.18 on 703.

Hope you can advise

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Collin Clark Mon, 02/02/2009 - 11:42

On DMZ2 you need to create NAT's. For example-

static (inside,dmz2) 192.168.200.22 172.23.0.18 netmask 255.255.255.255

From their side they point the 192.168.200.x network out their firewall (to your IP of 10.10.x.y, your firewall IP) and the ASA will listen for requests and translate.

Hope that helps.

Actions

This Discussion