Solved

How do I pass traffic from the DMZ to my LAN?

Posted on 2014-01-27
1
593 Views
Last Modified: 2014-01-28
I have a cisco 5510 with the old 8.2(5) system running on it. Id like to be able to pass ssh traffic from a server in the DMZ to a server on my lan.

DMZ Server : 192.168.250.230.
LAN Server: 192.168.3.201

What commands do I need to accomplish this?

Here are my interfaces.

interface Ethernet0/0
 nameif outside
 security-level 0
 ip address x.x.x.194 255.255.255.224
!
interface Ethernet0/1
 nameif inside
 security-level 100
 ip address 192.168.0.1 255.255.252.0
!
interface Ethernet0/2
 nameif dmz
 security-level 50
 ip address 192.168.250.1 255.255.255.0
!


My ACLs are called

access-group acl_out in interface outside
access-group inside_access_in in interface inside
access-group acl_dmz in interface dmz


Relatedly, I made an external A record for servername.mydomain.com and pointed it to the external IP, then a couple of commands in my ASA

access-list acl_out extended permit tcp any host x.x.x.198 eq xxx
static (dmz,outside) x.x.x.198 192.168.250.230 netmask 255.255.255.255

where xxx is the port we used, and that seems to work. Once connected to that machine though  I cant then ssh into a machine on my LAN.
0
Comment
Question by:Eric_Price
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 39813498
Pre 8.3 Code Example ASA 5500 Adding a DMZ Step By Step
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA 5506 blocks telnet 11 66
Configure IP on Sonicwall 2 41
Layer 3 Switch Configuration 12 86
upgrade Cisco Aironet AP 3 43
Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question