Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)

IT industry standard ASA deployment. Please advise

We have a question regarding the deployment of ASA. We are moving from PIX to ASA. Currently in the PIX we are using Alias command. It is no longer supported in the ASA. We have inside,DMZ, and outside interface. With our current setup we can access DMZ server via DMZ aadress but unable to access via their static map public IP. If I put in alias command for the dmz and public address we can address via name and public IP. How is the majority of people out there deploying this. Is everyone access DMZ via private dmz address or via public IP? or does everyone access to servers in dmz via their public IP. Please advise.


Re: IT industry standard ASA deployment. Please advise

Most of my customers prefer to use the public IP. It's pretty easy to setup int he ASA. Here's a link of reference.

Hope that helps.


Re: IT industry standard ASA deployment. Please advise

Most of the issues I see are when people do not have inside DNS, in which case it would make more sense to do destination nat with the public ip. Otherwise, using the dmz address is the way to go imho.

CreatePlease to create content