cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1184
Views
0
Helpful
1
Replies

ASA 5505. Can't browse from pc in DMZ with two IP's on one NIC

markupacreek
Level 1
Level 1

I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

markupacreek wrote:

I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

Mark

So what does the access-list "dmz_access_in" look like and what are the private IPs of the XP box ?

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card