cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
347
Views
0
Helpful
4
Replies

How can I get LAN users to use "outside" IP's of ASA

whiteford
Level 1
Level 1

Hi,

We have an ASA 5520 fireall with 20 public IP's which NAT'd to various web servers on the DMZ.

The thing is the internal LAN users can access them by typing in the internal IP of the server, but is it possible to treat the servers like an external company so if they type the public IP of FQDNS then it will be resolved?

Thanks

4 Replies 4

noran01
Level 3
Level 3

The easiest way to do this is if you are running your own internal DNS that forwards outbound. Just add FQDN records pointing to you internal ips. When an internal user types hosta.domain.com it would resolve to the internal ip and route accordingly.

This would only work if you had internal DNS, but also had an external DNS server hosting your public resources.

Collin Clark
VIP Alumni
VIP Alumni

static (dmz,inside) netmask 255.255.255.255

Is this a NAT from internal to external IP?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card