Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco ASA hairpin for guest network

Posted on 2013-12-20
6
Medium Priority
?
760 Views
Last Modified: 2014-01-13
I just replaced a Netscreen firewall with an ASA 5515-X.  Everything works, almost!  The Netscreen allowed clients on the guest network to access NATed hosts on the DMZ and inside interfaces, with their Internet addresses. There was nothing special about, it just worked. I think on the ASA I need to setup a hairpin or U-turn to make this work.  I have looked around and not sure I understand it, so I'm asking here.
 
Here's my config.  No vlans on the ASA just individual interfaces.
 
outside  #.#.#.#/28              From ISP
inside   10.0.0.0/8                internal DNS
guest    192.168.1.0/24        external DNS
dmz      192.168.2.0/24        exteranl DNS
 
What I would like is for any client on the guest network to act as if it was any client on the Internet.  Is this doable? If so what's the best way to do it?
 
Thanks...Jim
0
Comment
Question by:JimNowotny
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 

Author Comment

by:JimNowotny
ID: 39732077
This is version 9.1
0
 
LVL 13

Expert Comment

by:Quori
ID: 39733268
This is possible and is source NAT, but it'll appear to come from the IP address of the ASA interface, and you'll lose a lot of information useful to auditing. Is this really what you want? Its not great from a security point of view.

If so, are the interfaces (DMZ and Guest) the same security level?
0
 

Author Comment

by:JimNowotny
ID: 39733361
They are not, but can be. Right now the the DMZ is 50 and Guest is 25.
0
NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

 
LVL 29

Expert Comment

by:Jan Springer
ID: 39736021
A couple of things:

1) Don't change the security level, they're different for good reason
2) Do nat exemption between the guest and dmz networks
3) Create an access-list for guest network (in) allowing traffic to the dmz for only those services to specific IPs that need to be reached by guests.
0
 

Accepted Solution

by:
JimNowotny earned 0 total points
ID: 39740549
I've done I lot of looking around and it seems doing what I want to do is not recommended by Cisco.  Seems crazy to me.  So I'm just going to use a different firewall all together for the guest network.

This question can be marked closed.
0
 

Author Closing Comment

by:JimNowotny
ID: 39776074
No good answer
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question