Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

DMZ server to Internal LAN communication

Posted on 2010-09-20
4
Medium Priority
?
445 Views
Last Modified: 2013-11-16
I have a stupid question.  Stupid because I have done this in the past, and cannot for the life of me remember how I did it.

I have a server on the DMZ of my ASA-5540 with an IP address of 192.168.125.55 and I need it to access my SQL server on my internal protected network which has an IP address of 172.16.180.50

I thought the command(s) to do this was something like below, but it is not working, and it has been literally 5 years since I last did this, and just cannot remember.  Any help would be greatly appreciated.

access-list DMZ extended permit tcp any host 172.16.180.50 eq 1433

static (inside,DMZ) 192.168.125.55 172.16.27.55 netmask 255.255.255.255

Thank you for any assistance in advance,

Jeff
0
Comment
Question by:jgrammer42
  • 2
4 Comments
 
LVL 3

Expert Comment

by:pmctrek
ID: 33715813
Are you applying the access-list to the interface?  From the example you missing the access-group DMZ <nic> inbound

Paul
0
 

Author Comment

by:jgrammer42
ID: 33715912
pmctrek,

Yes, I am.   I should have added that to my original post.  I do have the following command set in the ASA configuration.

access-group DMZ in interface dmz

Sorry about that.

Thank you,
Jeff
0
 
LVL 17

Accepted Solution

by:
Jimmy Larsson, CISSP, CEH earned 500 total points
ID: 33716029
Try:
no static (inside,DMZ) 192.168.125.55 172.16.27.55 netmask 255.255.255.255
static (inside,DMZ) 172.16.180.50 172.16.180.50

/Kvistofta
0
 

Author Comment

by:jgrammer42
ID: 33716118

Kvistofta,

That appears to have done it.

Thank you!

Jeff
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
In this article, we’ll look at how to deploy ProxySQL.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question