?
Solved

NAT problem on 2 ASA's

Posted on 2011-10-02
2
Medium Priority
?
387 Views
Last Modified: 2012-06-21
Ok this config was working for a while and then just stopped and I'm at a loss with this one. I have two ASA 5505's connected together. ASA1 is directly connected the internet via DHCP and has an Outside, Inside, and DMZ vlan. ASA2 is connected to ASA1 and only has an Inside and Outside vlan. ASA2's Outside is connected to ASA1's DMZ and from there I'm trying to NAT to the Outside vlan. From ASA2, I can ping the Inside interface but not the Outside of ASA2 or the DMZ of ASA1. I used to be able to ping the DMZ of ASA1 from an Inside host on ASA2 but this is no longer the case. On ASA1 from the ASDM I can see that ICMP packets are reaching ASA1 on the DMZ, but I cannot connect to the Internet. Essentially what I'm trying to do here is connect ASA2 to ASA1 as if ASA1 was the ISP. ASA2 is then hosting VM's so that I can test my configurations. I have attached a diagram and my two configs to try to make this clear as possible. Any help is appreciated ;-)
Network-Diagram.pdf
-ASA1-Config.txt
-ASA2-Config.txt
0
Comment
Question by:CyberSec
2 Comments
 
LVL 10

Accepted Solution

by:
SuperTaco earned 2000 total points
ID: 36899336
So my understanding in you are using ASA1's DMZ as the outside interface for ASA2?  I may be missing something here, but it doesn't look like you have annat rule on ASA2 that map external to internal
0
 

Author Comment

by:CyberSec
ID: 36899669
SuperTaco..... SuperTaco..... Where do I begin...... LOL just kidding ;-) Ok here is the situation. I'm learning these ASA's and only configed ASA2 from the CLI. I must have screwed it up. I took my laptop and configured ASA2 via the ASDM and did static mapping and now it works perfect. Thanks for the suggestion. I have to learn the CLI better... but for now I just needed this to work. Thank you!!!
0

Featured Post

Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question