ASA 5505. Can't browse from pc in DMZ with two IP's on one NIC

Unanswered Question
Nov 30th, 2009
User Badges:

I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Jon Marshall Mon, 11/30/2009 - 13:26
User Badges:
  • Super Blue, 32500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

markupacreek wrote:


I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

Mark


So what does the access-list "dmz_access_in" look like and what are the private IPs of the XP box ?


Jon

Actions

This Discussion

Related Content