cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
525
Views
0
Helpful
4
Replies

ASA nat query

Tejas Kunte
Level 1
Level 1

i have an ASA 5520 runnng 8.4(1)

it has the following interfaces

WAN - public IP

DMZ -  public IP

Prod - 192.168.1.X

for internet access i have the following statement

object network Prod_Subnet_Internet

nat (Production,WAN) dynamic interface

do i need a similar statement if hosts in the Prod network need to access hosts in the DMZ ?

4 Replies 4

cadet alain
VIP Alumni
VIP Alumni

Hi,

If DMZ hosts are not on the internet then you don't need to as by default nat-control is disabled.

Regards.

Alain

Don't forget to rate helpful posts.

dmz hosts are on the internet, they all have public IPs

Hi,

Then you need to do a NAT because private adresses are not routeable on the internet.

Regards.

Alain

Don't forget to rate helpful posts.

1 more thing

i am able to ping those dmz ips without a nat stmt

is icmp handled differently ?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card