ASA: temporarily rewrite destination IP

Unanswered Question
Aug 24th, 2009
User Badges:


We have an internal application (Server-A) that has a hardcoded IP for LDAP lookups. The LDAP server is also internal, but on a different interface/VLAN of the ASA. The LDAP server (LDAP-A) is experiencing problems, and I would like to temporarily redirect LDAP (tcp/389) lookups from Server-A to LDAP-B. We can't change the destination IP in Server-A's configuration. LDAP-A and LDAP-B are on the same subnet.

Normal traffic flow looks like this:

Server-A -> ASA int 1 -> ASA int 2 -> LDAP-A

I somehow need ASA int 1 to see LDAP-A's destination address and rewrite it to LDAP-B's IP. Is this possible?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Yudong Wu Mon, 08/24/2009 - 09:44
User Badges:
  • Gold, 750 points or more

try this:

static (int2,int1) tcp LDAP-A-IP 389 LDAP-B-IP 389

Or if you would like to do static policy NAT.

static (int2,int1) tcp LDAP-A-IP 389 access-list TEST

access-list TEST permit tcp LDAP-B-IP eq 389 Server-A-IP


This Discussion