Cisco ASA 5510 NAT setup inside dmz out

birddog2008
birddog2008 used Ask the Experts™
on
Hey Guy's,

I'm setting up a brand new Cisco ASA 5510 from scratch.  Simple network to begin, but I need help with NAT.

Inside = 192.168.10.0/24
Ouside = 216.13.114.0/28
DMZ = 192.168.129.0/24

I need to be able to ping between Inside and DMZ and any Inside subnet can access any DMZ subnet.  I'm fricking lost!

I setup:

nat (Inside) 1 192.168.10.0 255.255.255.0
global (Outside) 1 interface

I haven't enabled nat-control...but I was reading that eventhough that is not enabled once I'm traversing NAT through an interface, I'll have to use static NAT.  I tried
static (DMZ,Inside) 192.168.129.0 192.168.10.0 netmask 255.255.255.0
static (Inside,DMZ) 192.168.10.0 192.168.129.0 netmask 255.255.255.0
But still no ping nor any IP connectivity

Any help would be greatly appreiated!
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Head of IT Security Division
Top Expert 2010
Commented:
Did you enabled this traffic on the lower security interfaces to inside?
If not this causes the problem

access-list DMZ_access_in extended permit ip 192.168.129.0 255.255.255.0 192.168.10.0
access-group DMZ_access_in in interface DMZ

after that don't forget to 'clear xlate'!

Best regards,
IStvan


Commented:
Is this the same question as the other one?

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial