Configuring routing from internal interface to NATed Public IP on another internal interface.

Unanswered Question

I have ASA with two DMZ interfaces. I have requirement to route trafic from one device in first DMZ zone to a Public NATed IP of the device in second DMZ zone. Example: first DMZ, second DMZ

Device in first DMZ has ip

Device in second DMZ has IP NATed to Public IP( Requirement for my solution to work device from first DMZ needs to call device in second DMZ by Public IP (not private)

How can i configure my ASA to do that?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Federico Coto F... Thu, 08/26/2010 - 16:44
User Badges:
  • Green, 3000 points or more


static (DMZ2,DMZ1)

With the above command the following will happen...

When hosts on the DMZ1 try to talk to (which is the NAT IP for the server on DMZ2)... the ASA will send it to the DMZ2 interface (instead than sending it to the outside as it would normally do).



This Discussion