Solved

Access DMZ by using public IPs

Posted on 2010-09-08
10
515 Views
Last Modified: 2012-05-10
Is there a way to configure a Cisco ASA so that internally I can use the same external IPs to access a DMZ site.  Right now I need to keep clone domains for all of our hosted sites.  For example, if www.contoso.com points to 123.123.123.1 I add that number to the external DNS for contoso.com.  Internally, I have to keep another DNS domain for contoso.com that points www.contoso.com to 192.168.1.1

I am redoing my DNS and I don't want to keep these clone domains.  Is there a way to configure NAT, etc so that internally I can use the same 123.123.123.1 address?
0
Comment
Question by:phoenix-sys
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 33626247
Dont'think that is going to work. The external ip's are 'connected' to the outside interface (i.e. the interface is in that network) so that route is automatically learned. What you are trying to do is to go to your external address, so go out the outside interface, make a u-turn and go back to the dmz. No go afaik.
0
 
LVL 2

Expert Comment

by:andrel39
ID: 33626254
I don't know about the Cisco ASA but with SonicWall it is possible to do what you are asking using NAT and/or routing rules.
0
 
LVL 4

Expert Comment

by:ullas_unni
ID: 33626266
try this:

static (dmz,inside) ip 123.123.123.1 192.168.1.1 netmask 255.255.255.255

and

nat (inside) 2 0.0.0.0 0.0.0.0
global (dmz) 2 interface
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 

Author Comment

by:phoenix-sys
ID: 33626340
I have seen this with the Sonicwall is why I was asking.  I did try the static above, but not with the nat (inside) and global(dmz).  I will have to try that tomorrow morning before everyone gets in.  Too late for today.
0
 
LVL 4

Expert Comment

by:ullas_unni
ID: 33626385
@ erniebee- in firewall, destination NAT decides your egress interface.

so the packet flow is:

ACL--> Destination NAT-->Route look up--> Source NAT

so in my solution above static is the destination NAT so it decides the egress interface ie the dmz and nat global statements are for source translation.
0
 

Author Comment

by:phoenix-sys
ID: 33626446
Looking at the answer I want to verify one thing.


123.123.123.x is a public IP
192.168.1.x is a DMZ private IP

10.1.1.x is my internal LAN

Did I maybe confuse this or does this still hold true?
0
 
LVL 4

Expert Comment

by:ullas_unni
ID: 33626491
in my answer

123.123.123.1 is the public ip of the server.
192.168.1.1 is the private ip of your server.

the internal LAN users should be able to access the server on 123.123.123.1
0
 

Author Comment

by:phoenix-sys
ID: 33626498
OK, thanks.  I will try that in the morning.
0
 
LVL 4

Accepted Solution

by:
ullas_unni earned 500 total points
ID: 33626532
and a small correction... the static is:

static (dmz,inside) 123.123.123.1 192.168.1.1 netmask 255.255.255.255

there is no 'ip' keyword as in my earlier mentioned static..!!
0
 

Author Comment

by:phoenix-sys
ID: 33626717
OK, I picked one website that I figured no one would be using.  this did work.
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question