Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Attention: The Community will be in read-only mode on 12/14/2017 from 12:00 am pacific to 11:30 am.

During this time you will only be able to see content. Other interactions such as posting, replying to questions, or marking content as helpful will be disabled for few hours.

We apologize for the inconvenience while we perform important updates to the Community.

ASA5540 NAT Problem

I'm setting up ASA5540 to replace PIX525. I have a problem, traffic is not flowing from the DMZ to Outside interface. I enabled ping from the outside interface to dmz and debugged icmp trace. This is what i found, "ICMP echo request untranslating Outside:172.18.124.3 to DMZ:exchange

ICMP echo request from Outside:172.18.124.1 to DMZ:172.18.124.3 ID=1024 seq=24576 len=32"

Simply, there was no reply from the DMZ. And when i ping from DMZ to Outside, i dont see any traffic passing in ASA. Please help as my emails are not going out. Attached is my configuration file.

3 REPLIES
Green

Re: ASA5540 NAT Problem

You need to allow icmp in your outside and dmz access lists. Also, you are only allowing your exchange server to smtp to 172.16.0.0.

Re: ASA5540 NAT Problem

Sorry that config is rather old, i have this access list in my current config.

access-list outside_access_dmz extended permit icmp any host 172.18.124.3

but still i get the same.

New Member

Re: ASA5540 NAT Problem

I looked at your config and was extremely confused at what you're trying to accomplish. But, I only glanced at it and not trying to construct your network.

My suggestions, albeit a novice one, would be to add ICMP to your inspection. As far as the connectivity, I'm hard pressed to find what you're doing with the IP scheme and your nat0.

Sorry

142
Views
0
Helpful
3
Replies
CreatePlease to create content