Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA 5505 Base License - DMZ workaround

OK, so I get that the ASA 5505 Base License can only have a 3rd named VLAN interface if that interface has the "no forward interface XXX" command used. I have a customer with the following interfaces:

  1. outside
  2. inside
  3. DMZ

The DMZ is currently configured to prevent forwarding to the inside interface. Hosts on inside and DMZ have Internet (can sent to outside), Internet hosts can access hosts on both VLANs through ACLs and NAT statements, but DMZ hosts cannot initiate any connections to hosts on the inside. I get that, and understand it is by design. But I have a theoretical workaround that I cannot get working, and I am curious if it is a licensing issue or misconfiguration.

From the DMZ, I initiate a connection to a public IP, which I do auto NAT on the outside interface to translate that to an inside host. Technically the traffic goes from DMZ to outside, then outside to inside. Problem is that I cannot make heads or tails of the configuration to test this. Partially because it's a confusing concept to me, and partially because I am new to the 8.4+ NAT syntax and this is all being attempted on an ASA running 9.1.

So, besides buying the Security Plus license, is this even possible? If the license upgrade is the only option, what part number am I looking for? The ASA is brand new, running the base license, 10 inside hosts, FOS 9.1

Cisco Employee

ASA 5505 Base License - DMZ workaround


The best way to solve this will be to buy security plus license since the workaround you are planning won't work



Luis Silva

"If you need PDI (Planning, Design, Implement) assistance feel free to reach"

Luis Silva "If you need PDI (Planning, Design, Implement) assistance feel free to reach us"