Link to home
Start Free TrialLog in
Avatar of bentham1
bentham1Flag for United Kingdom of Great Britain and Northern Ireland

asked on

ASA 5505: access from Single Machine in DMZ to all internal machines on a specific port

WE have a pix on a stub network. We have 2 DMZs on it and want to allow a PC which is on it's own in one of the DMZ's and needs to contact the PC's on the internal network . Is it possible to do dynamic nat from outside to inside?  Can I have an example based on below.

ASA 5505

DMZ1 , Sec level 50 Int Address 192.168.2.1 /24    PC address 192.168.2.100
Inside,  Sec level 100 Int Address 172.16.2.1 /16    PC address Range 172.16.2.10 - 20

Thanks
Avatar of Garry Glendown
Garry Glendown
Flag of Germany image

Would you really need NAT at all? Yes, NAT should work, but have you tried setting up an NAT excemption? If the ASA is the Default Gateway for both the DMZ and the inside network, nothing else should be necessary ... (or, you could configure the "allow traffic through firewall without NAT" option, then all you need is the access list entry)
Avatar of bentham1

ASKER

For some reason, NAT is a requirement. Can't make that out myself - but I am too far down the pecking order!!
ASKER CERTIFIED SOLUTION
Avatar of Garry Glendown
Garry Glendown
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial