Cisco ASA Outside and DMZ interface IPing


I have inherited an ASA config which I have questions on.  The outside interface is assign say  DMZ is   There are some static DMZ,outside for .  The previous asa I have handled all the external IPs would be assigned to the outside interface.  Is this setup standard?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Ken BooneNetwork ConsultantCommented:
Yes in your previous case you were port address translating to the public ip address assigned to the outside interface on the ASA.  In this case, you are statically mapping devices on the DMZ to specific public IP addresses.  The ASA will provide proxy arp for these devices and to the device outside the firewall they will all have the mac address of the outside interface.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
silvercasAuthor Commented:
thanks for that answer.  

the reason for this question is due to a problem with getting to these devices assigned to .  running an packet-tracer all appears well, though from the outside I am unable to access
Ken BooneNetwork ConsultantCommented:
So you need to make sure you have an access-list that allows the access to assigned to the outside interface.  What version of ASA software do you have?  You can post a sanitized version of your config and we can help you with it.
silvercasAuthor Commented:
so my problem turned out to be a missing route in the router.  added route for external ip to asa and all is well.  

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.