Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
You may experience some slow load times, errors, and slight inconsistencies. We ask for your patience as we finalize the launch. Thank you.

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NAT and Static Statements

I have an ASA 5500 that sits behind the internet router. On this ASA, I have the inside hosts that connects tto the internet via a proxy server. The proxy server is located in the dmz, where I have my ISA,Web client and exchange servers(all in dmz), everybody connects to the internet via the proxy server located in the dmz.

Also I want my remote users to have access to the dmz.

Can someone please give me a step by step config guide on how to do this.

inside hosts---->ASA----->internet router





A config guide with the scenario that has a step by step guide will be deeply appreciated.

Attached is what have been able to come up with, please correct me where necessary.


  • Firewalling

Re: NAT and Static Statements

In this case your poxy server ip is natted with public IP which Is allowed to communicate to internet .

If you want external users to access your DMZ server you must nat that server IP via using static nat command and allow access rules on outside interface .

Hope this help.


New Member

Re: NAT and Static Statements

By reading your text file, I think you're on right track. However, in step 7, you should have "access-group 110 in interface dmz" instead of "access-group 110 out interface outside"