Help with rule/nat on ASA 5520

Unanswered Question
Feb 2nd, 2009
User Badges:

Hi,


I hope this is possible.


I have a Cisco ASA 5520 with 2 DMZ's (on a Cisco 3750 trunked from the ASA).


One DMZ1 (172.24.0.0/24) has our webservers and DMZ2 (10.10.0.0/16) has a remote company with servers we use.


Now they have as me to prepare routing on my ASA so if they send data to 192.168.200.22 port 703 is will instead go to 172.23.0.18 port 703 which is our web vlan.


Not sure why they are sending to 192.168.200.22 yet on 702, but I need to get our ASA to respond to this request on 172.23.0.18 on 703.


Hope you can advise

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Collin Clark Mon, 02/02/2009 - 11:42
User Badges:
  • Purple, 4500 points or more

On DMZ2 you need to create NAT's. For example-


static (inside,dmz2) 192.168.200.22 172.23.0.18 netmask 255.255.255.255


From their side they point the 192.168.200.x network out their firewall (to your IP of 10.10.x.y, your firewall IP) and the ASA will listen for requests and translate.


Hope that helps.

Actions

This Discussion