Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA 5505. Can't browse from pc in DMZ with two IP's on one NIC

I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

Everyone's tags (6)
1 REPLY
Hall of Fame Super Blue

Re: ASA 5505. Can't browse from pc in DMZ with two IP's on one N

markupacreek wrote:

I have an ASA 5505 and an XP box in the DMZ.  The XP box host IIS FTP and HTTP using one NIC with two IP's.  Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work.  The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host.  In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".

Mark

So what does the access-list "dmz_access_in" look like and what are the private IPs of the XP box ?

Jon

924
Views
0
Helpful
1
Replies