Solved

Cisco ASA routing

Posted on 2012-12-26
1
244 Views
Last Modified: 2013-03-22
I have a cisco ASA 5510 firewall.
have 3 physical interfaces on it right now

corp-192.168.15.1/24   (192.168.15.2 is corp router)
inside-192.168.5.1/24
dmz-192.168.102.1/24

we have another network between a router on the corporate network that has a network on the same address as one of our physical networks (192.168.5.x/24).  It has an SMTP server that we want a server on our DMZ network to be able to use.

when we send a request from 192.168.102.99 (DMZ network) to 192.168.5.6 (SMTP) server, it is routed to the physical interface on inside network.  

How can we override this and any requests made from 192.168.102.99 to 192.168.5.6 using port 25, get routed out the corp network instead of trying to go to the inside network by default.

was thinking a route statement and/or a static statement is what i need

route outside 192.168.5.6 255.255.255.255 192.168.15.2 1

or do need static like below

static (DMZ,outside) 192.168.5.6 192.168.5.6 netmask 255.255.255.255

or need both?

thanks
0
Comment
Question by:rkneal
1 Comment
 
LVL 20

Accepted Solution

by:
rauenpc earned 500 total points
ID: 38722555
You need to pick a fake subnet, and use it for nat purposes. Make a static route on the Asa for the fake network with a next hop of the router. Configure the router with a static nat to translate a fake ip to the real ip.

Post configs if you need help accomplishing this.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now