Re-IP DMZ to private space, NAT to public

Unanswered Question
Mar 18th, 2010
User Badges:


After the initial information gathering, I find I am at a standstill as-to how I should procede.

We are currently in the process of implementing One-to-One static NAT'ing on our DMZ servers, and RE-IP'ing them to private IP space.

We need to enable DNS resolution, LDAP authentication between the DMZ servers and our network, while making them accessible tobi the public.

I'm hoping for a bit of hand-holding on this issue, since I am not sure where to begin.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
dan_track Thu, 03/18/2010 - 07:39
User Badges:

On which platform are you going to do this? Can you post current configuration?


vilaxmi Fri, 03/19/2010 - 19:46
User Badges:
  • Cisco Employee,


Static translation for DMZ server :

static (dmz,outside) netmask

access-list inbound extended permit tcp any host

access-group inbound in interface outside // to permit the inbound TCP connections from any outside IP address to the public IP address of server//

Now, coming to your DNS resolution, I would need to know, where is you DNS server located ? For the external clients, external DNS server would take care of name resoultion.




This Discussion