NAT problem on 2 ASA's

Posted on 2011-10-02
Last Modified: 2012-06-21
Ok this config was working for a while and then just stopped and I'm at a loss with this one. I have two ASA 5505's connected together. ASA1 is directly connected the internet via DHCP and has an Outside, Inside, and DMZ vlan. ASA2 is connected to ASA1 and only has an Inside and Outside vlan. ASA2's Outside is connected to ASA1's DMZ and from there I'm trying to NAT to the Outside vlan. From ASA2, I can ping the Inside interface but not the Outside of ASA2 or the DMZ of ASA1. I used to be able to ping the DMZ of ASA1 from an Inside host on ASA2 but this is no longer the case. On ASA1 from the ASDM I can see that ICMP packets are reaching ASA1 on the DMZ, but I cannot connect to the Internet. Essentially what I'm trying to do here is connect ASA2 to ASA1 as if ASA1 was the ISP. ASA2 is then hosting VM's so that I can test my configurations. I have attached a diagram and my two configs to try to make this clear as possible. Any help is appreciated ;-)
Question by:CyberSec
    LVL 10

    Accepted Solution

    So my understanding in you are using ASA1's DMZ as the outside interface for ASA2?  I may be missing something here, but it doesn't look like you have annat rule on ASA2 that map external to internal

    Author Comment

    SuperTaco..... SuperTaco..... Where do I begin...... LOL just kidding ;-) Ok here is the situation. I'm learning these ASA's and only configed ASA2 from the CLI. I must have screwed it up. I took my laptop and configured ASA2 via the ASDM and did static mapping and now it works perfect. Thanks for the suggestion. I have to learn the CLI better... but for now I just needed this to work. Thank you!!!

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
    This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now