i can't have dns server and i try to use static (dmz,inside) 184.108.40.206 192.168.3.31 net 255.255.255.255 but inside's clients don't access to dmz-network.please help me. and server in inside-network its nat already. inside's clients don't access them via nat ip [public ip] but can access via private ip its ok.
If the inside network wants to reach server 192.168.3.31 on DMZ via its public IP 220.127.116.11, then all you need is the static that KS suggested:
static (dmz,inside) 18.104.22.168 192.168.3.31
I assume from your post, that the inside clients resolve the IP 22.214.171.124 for your DMZ server, and that's why you want to reach the server from the inside using the public IP...
The above static statement should do it....
Could you verify that the DNS response that you're getting for your server is the public IP? Can you PING 126.96.36.199 from the inside network?
From the configuration, it should work, if still does not work, please use the Packet Tracer utility from CLI or ASDM and that will show you which process in the ASA is denying the traffic (or check the logs)
Because , user access website then click link to access service [the link in url link public IP don't link to dns name of server] , if user stay @ office always use access to website and click link in web for acess not input private IP to access.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :