ASA 5505. Can't browse from pc in DMZ with two IP's on one NIC

Unanswered Question
Nov 30th, 2009

I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Jon Marshall Mon, 11/30/2009 - 13:26

markupacreek wrote:

I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

Mark

So what does the access-list "dmz_access_in" look like and what are the private IPs of the XP box ?

Jon

Actions

This Discussion