?
Solved

Alternative NAT for host behind ASA 5510

Posted on 2013-06-21
5
Medium Priority
?
801 Views
Last Modified: 2013-06-25
I have a client with an ASA 5510 and a pool of public IP numbers. His MX record points to an IP (155) that is not the static IP for the outside interface on the ASA (153). He has static nat configured for https and smtp on the IP (155) for Exchange. There is a dynamic nat for all outgoing traffic to use the interface IP. Some emails are being rejected since the reverse lookup does not match the MX record. Is it possible to configure nat so that outgoing traffic for the exchange server is a static IP (155) instead of the interface IP (153)?

Thanks.
0
Comment
Question by:fisher_king
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 25

Accepted Solution

by:
Cyclops3590 earned 2000 total points
ID: 39266993
yes.  just configure a static nat

ASA OS 8.3+
object-group network exchange-server
  host **internal IP of server**
  nat (inside,outside) static **public IP of server** dns

ASA OS pre-8.3
static (inside,outside) **public IP** **internal IP** netmask 255.255.255.255 dns

remember to get rid of static pats that reference that server then

and run 'clear xlate' after you're done reconfiguring to ensure new translations take affect
0
 

Author Comment

by:fisher_king
ID: 39266999
I tried that, but the Exchange server did not have any internet access. I did not include the dns re-write and I did not clear xlate. I will try again and let you know.

Thanks.
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 39267008
ya, you need to do a clear xlate or the translations can still be wrong causing unexpected behavior.
0
 

Author Comment

by:fisher_king
ID: 39267015
I realized that I also couldn't map the entire inner and outer becasue there was another pat for that IP. We will move to another public IP in their pool and test. Thanks again.
0
 

Author Closing Comment

by:fisher_king
ID: 39276110
Thanks again for your help.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Suggested Courses
Course of the Month15 days, 15 hours left to enroll

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question