Please see attached my network diagram and following configuration.
ip address 192.168.0.243 255.255.255.0
ip address 10.0.0.2 255.255.255.252
ip address 172.29.1.1 255.255.255.0
access-list DMZTOLocal extended permit ip host 192.168.0.241 192.168.0.0 255.255.0.0
static (DMZ,local) 192.168.0.241 172.29.1.5 netmask 255.255.255.255
access-group DMZTOLocal out interface local
inspect dns preset_dns_map
inspect h323 h225
inspect h323 ras
I get ping and access to 192.168.0.241(172.29.1.5) from 192.168.0.0/16, but cant get access and ping from 172.29.1.5 to 192.168.0.0/16.
what can i do if i want to get ping from DMZ to local ? ??
Please suggest me.
The ASA/Pix firewalls allow you to go from a higher security level to lower security level by default, but blocks traffic coming the other direction. You'll need to add an acl on the dmz interface allowing the traffic into you local lan from the dmz.
As a side not, is there a reason that you're natting into the DMZ from your local side? You shouldn't if you can help it.
access-list FromDMZ permit icmp host 172.29.1.5 192.168.0.0 255.255.255.0
access-group FromDMZ in interface DMZ
Please rate useful posts...