Hairpin from inside to public ip nat to DMZ

Unanswered Question
Oct 28th, 2009
User Badges:

Hello I have an ASA5510 which I am trying to move into production.

Currently I have external, internal, and DMZ interfaces. I have a proxy setup for the inside traffic to get out. I also have a static nat for a DNS server in the DMZ zone. I would like to have the users on the inside interface get to outside public ip of the DNS server not the private one.

inside is

dmz is

outside is

static (dmz,outside) 172.16.1.x netmask

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Panos Kampanakis Wed, 10/28/2009 - 11:51
User Badges:
  • Cisco Employee,

From what you are describing it seems you want the inside user to use the for the dns. The you will just need

static (dmz,inside) 172.16.1.x netmask

And of course to open the inside to not drop traffic to the

I hope it helps.



This Discussion