Problems redirecting web server through ASA

Unanswered Question
Aug 10th, 2010
User Badges:

Hi ...

I need some help or sugestions about the following configuration.

I was trying to replace an Microsoft ISA Firewall with an ASA 5520.

I've attached the schema (ASAredirect.jpg) and the ASA configuration (asa.txt).

The ISA server had the outside interface working as PAT interface with some blacklist URL filtering.

In this firewall we found configured some ports redirections to inside servers:

ISA interface IP address: 9999 ->

ISA interface IP address: 9998 ->

ISA interface IP address: 9997 ->

ISA interface IP address: 9996 -> ->

I could configure the ASA Firewall to replace the ISA server:

- configure some URL filters using regex.

- configure the nat and global commands.

- configure the static command to redirect ports:

static (inside,outside) tcp interface 9999 3389 netmask

static (inside,outside) tcp interface 9997 3389 netmask
static (inside,outside) tcp interface 9998 3389 netmask
static (inside,outside) tcp interface 9996 3389 netmask
static (inside,outside) tcp interface www www netmask

But, we have an special problem with the last redirect instruction.

The web page is in a host outside. When you try this redirects to a web server inside the ASA (see the graphic).  If you are outside (Internet) you can get access to and If you try to get access to from inside works fine, but when try to get access to won't work.  The inside station can't access

After this I tried to ping from inside stations to outside ASA interface, but it's not working.  I modified the access rules, static and nat-control configuration but I can't get access to the outside interface neither

Please, your help in this.

If you have any sugestion related to URL filtering I'll appreciate.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Nagaraja Thanthry Tue, 08/10/2010 - 20:59
User Badges:
  • Cisco Employee,


Please try the following:

If you are running code version older than 8.2:

Nagaraja Thanthry Tue, 08/10/2010 - 21:05
User Badges:
  • Cisco Employee,


I checked your configuration again and this configuration should work:

Nagaraja Thanthry Tue, 08/10/2010 - 21:22
User Badges:
  • Cisco Employee,


Can you please post the output of "show run statics", "show run nat", and "show run global" again here? Also, please remove " ip verify reverse-path interface inside" and try again.



guigonza Wed, 08/11/2010 - 06:47
User Badges:

Thanks for your attention ...

I removed the "ip verify reverse-path interface inside", but it didn't work.

I'm requesting the show results ... as soon as I get them I'll send ...

I was trying to ping the ASA outside interface from inside and is not possible. 

The problem is:   from the inside network is not possible to get access to ASA outside interface.


This Discussion