Source and Destination is same through ASA Firewall

Posted on 2014-02-17
Last Modified: 2014-03-07

My Server is at Inside Network.
My Laptop is at Inside Network

My server Public ip registered outside (internet DNS). and there is no internal DNS

When i am trying with  URL,which has registered in Public DNS , the request is going via ASA Firewall and hits to the DNS server and DNS server redirects to the Firewall and Firewall do the reverse-NAT and changes public to Private but my Laptop not able to access the server over URl

I have studied that Firewall will not send to the destination that has passed over the same  interface..

What would be the solution , Can it be cone over DNS-doctoring ?

Question by:RAMU CH
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39864614
You can try adding an entry on host file to do resolution with internal IP.

Author Comment

ID: 39864702
We cannot do 1000 PCs  hence it should happen over Firewall..

Is there any configuration in ASA firewall

Accepted Solution

Jordan Medlen earned 500 total points
ID: 39864778
Try adding a static route for the IP address of the URL you are trying to hit, and point it to your gateway IP address of the firewall.


route outside <ip_of_url> <firewall_ext_gw_ip> 1

This is a dirty trick to accomplish connectivity. Your firewall will now direct that traffic to it's gateway and the gateway device will send it right back around to the outside interface, and provided ACLs are in order, allow that traffic to pass back in.

Author Closing Comment

ID: 39912244

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor ( Top Charts is a view in which you can set seve…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question