Solved

Alternative NAT for host behind ASA 5510

Posted on 2013-06-21
5
777 Views
Last Modified: 2013-06-25
I have a client with an ASA 5510 and a pool of public IP numbers. His MX record points to an IP (155) that is not the static IP for the outside interface on the ASA (153). He has static nat configured for https and smtp on the IP (155) for Exchange. There is a dynamic nat for all outgoing traffic to use the interface IP. Some emails are being rejected since the reverse lookup does not match the MX record. Is it possible to configure nat so that outgoing traffic for the exchange server is a static IP (155) instead of the interface IP (153)?

Thanks.
0
Comment
Question by:fisher_king
  • 3
  • 2
5 Comments
 
LVL 25

Accepted Solution

by:
Cyclops3590 earned 500 total points
ID: 39266993
yes.  just configure a static nat

ASA OS 8.3+
object-group network exchange-server
  host **internal IP of server**
  nat (inside,outside) static **public IP of server** dns

ASA OS pre-8.3
static (inside,outside) **public IP** **internal IP** netmask 255.255.255.255 dns

remember to get rid of static pats that reference that server then

and run 'clear xlate' after you're done reconfiguring to ensure new translations take affect
0
 

Author Comment

by:fisher_king
ID: 39266999
I tried that, but the Exchange server did not have any internet access. I did not include the dns re-write and I did not clear xlate. I will try again and let you know.

Thanks.
0
 
LVL 25

Expert Comment

by:Cyclops3590
ID: 39267008
ya, you need to do a clear xlate or the translations can still be wrong causing unexpected behavior.
0
 

Author Comment

by:fisher_king
ID: 39267015
I realized that I also couldn't map the entire inner and outer becasue there was another pat for that IP. We will move to another public IP in their pool and test. Thanks again.
0
 

Author Closing Comment

by:fisher_king
ID: 39276110
Thanks again for your help.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
A short film showing how OnPage and Connectwise integration works.
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now