Solved

DMZ server to Internal LAN communication

Posted on 2010-09-20
4
438 Views
Last Modified: 2013-11-16
I have a stupid question.  Stupid because I have done this in the past, and cannot for the life of me remember how I did it.

I have a server on the DMZ of my ASA-5540 with an IP address of 192.168.125.55 and I need it to access my SQL server on my internal protected network which has an IP address of 172.16.180.50

I thought the command(s) to do this was something like below, but it is not working, and it has been literally 5 years since I last did this, and just cannot remember.  Any help would be greatly appreciated.

access-list DMZ extended permit tcp any host 172.16.180.50 eq 1433

static (inside,DMZ) 192.168.125.55 172.16.27.55 netmask 255.255.255.255

Thank you for any assistance in advance,

Jeff
0
Comment
Question by:jgrammer42
  • 2
4 Comments
 
LVL 3

Expert Comment

by:pmctrek
ID: 33715813
Are you applying the access-list to the interface?  From the example you missing the access-group DMZ <nic> inbound

Paul
0
 

Author Comment

by:jgrammer42
ID: 33715912
pmctrek,

Yes, I am.   I should have added that to my original post.  I do have the following command set in the ASA configuration.

access-group DMZ in interface dmz

Sorry about that.

Thank you,
Jeff
0
 
LVL 17

Accepted Solution

by:
Kvistofta earned 125 total points
ID: 33716029
Try:
no static (inside,DMZ) 192.168.125.55 172.16.27.55 netmask 255.255.255.255
static (inside,DMZ) 172.16.180.50 172.16.180.50

/Kvistofta
0
 

Author Comment

by:jgrammer42
ID: 33716118

Kvistofta,

That appears to have done it.

Thank you!

Jeff
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article is focussed on erradicating the confusion with slash notations. This article will help you identify and understand the purpose and use of slash notations. A deep understanding of this will help you identify networks quicker especially w…
Introduction This article explores the design of a cache system that can improve the performance of a web site or web application.  The assumption is that the web site has many more “read” operations than “write” operations (this is commonly the ca…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

947 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now