Solved

Cisco ASA routing

Posted on 2012-12-26
1
247 Views
Last Modified: 2013-03-22
I have a cisco ASA 5510 firewall.
have 3 physical interfaces on it right now

corp-192.168.15.1/24   (192.168.15.2 is corp router)
inside-192.168.5.1/24
dmz-192.168.102.1/24

we have another network between a router on the corporate network that has a network on the same address as one of our physical networks (192.168.5.x/24).  It has an SMTP server that we want a server on our DMZ network to be able to use.

when we send a request from 192.168.102.99 (DMZ network) to 192.168.5.6 (SMTP) server, it is routed to the physical interface on inside network.  

How can we override this and any requests made from 192.168.102.99 to 192.168.5.6 using port 25, get routed out the corp network instead of trying to go to the inside network by default.

was thinking a route statement and/or a static statement is what i need

route outside 192.168.5.6 255.255.255.255 192.168.15.2 1

or do need static like below

static (DMZ,outside) 192.168.5.6 192.168.5.6 netmask 255.255.255.255

or need both?

thanks
0
Comment
Question by:rkneal
1 Comment
 
LVL 20

Accepted Solution

by:
rauenpc earned 500 total points
ID: 38722555
You need to pick a fake subnet, and use it for nat purposes. Make a static route on the Asa for the fake network with a next hop of the router. Configure the router with a static nat to translate a fake ip to the real ip.

Post configs if you need help accomplishing this.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question