Solved

Asa5505 to route port 443 to 2 different IP's

Posted on 2013-10-23
4
335 Views
Last Modified: 2013-10-27
Hi experts

I have a client with:
-  only one IP address  
- an ASA5505 in front
- 2 webservers on the inside

I need to direct all https / port 443 traffic to webserver #1, unless the traffice comes from a specific IP, then it needs to go to webserver #2.

using a different port for server02 is not an option. Is this possible?

I tried this but it directs everyting to #1 stil..:
static (inside,outside) tcp x.x.x.x https webserver2 https netmask 255.255.255.255
static (inside,outside) tcp interface https webserver1 https netmask 255.255.255.255
0
Comment
Question by:Sander123
  • 2
4 Comments
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 450 total points
ID: 39595654
and this?

object network webserver1
 host x.x.x.x

object network webserver2
 host x.x.x.x

object network special_ip
 host x.x.x.x

object service nat-https
 service tcp destination eq 443

nat (outside,inside) source static special_ip special_ip destination static interface webserver2 service nat-https nat-https unidirectional no-proxy-arp
nat (outside,inside) source static any any destination static interface webserver1 service nat-https nat-https unidirectional no-proxy-arp

access-list outside_access_in extended permit object nat-https object special_ip object webserver2
access-list outside_access_in extended permit object nat-https any object webserver1

I am doing this from head so if there is a syntax error please let me know!

P.S. You will need the ASA 9.x version to do this properly!
0
 

Author Comment

by:Sander123
ID: 39596682
Hi Henkva

txs, I prob should have mentioned this ASA is on fw 7.2(4) .
I could try and upgrade to fw 9 but i'd rather have some other solution since the device is one of the older models so i don't know if it can handle fw 9..
Also it's on the other side of the country so if i can avoid spending 6 hours in the car i'd rather do that ;)

Is there no way to do this with firmware 7.2?

Thanks
0
 
LVL 2

Assisted Solution

by:mannyfernandez
mannyfernandez earned 50 total points
ID: 39596824
Sander23,

Sadly, I do not think there is  way to do this with the legacy code.  Although the 9 train is preferred though, you CAN do it on 8.3 and above.

Manny
0
 
LVL 12

Expert Comment

by:Henk van Achterberg
ID: 39596838
You will need 512MB RAM to run 8.3 though.
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
policy routing to fw2 18 68
ssh setup on Cisco swith 11 66
Viber-Only Restriction 6 44
ASA DHCP setup 5 29
If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question