Help with NAT Configuration for Cisco ASA 5505

進行中 投稿 6年前 着払い
進行中 着払い

ASA 9.1

External Subnet: [url removed, login to view]

Firewall’s External Facing IP: [url removed, login to view]

Internal Subnet: [url removed, login to view] (Server VLAN)

VPN Client Subnet: [url removed, login to view]

Server1 Internal IP: [url removed, login to view]

Server1 External IP: [url removed, login to view]

Server2 Internal IP: [url removed, login to view]

Server2 External IP: [url removed, login to view]

Desired Behavior:

* Inbound connections to Server1 works for either external IP ([url removed, login to view]) or internal IP while VPN connected ([url removed, login to view])

* Outbound connections from Server1 appear as external IP ([url removed, login to view])

* Inbound connections to Server2 works for either external IP ([url removed, login to view]) or internal IP while VPN connected ([url removed, login to view])

* Outbound connections from Server1 appear as external IP ([url removed, login to view])

Current Behavior:

* Inbound connections work to either external IP or internal IP while VPN connected.

* Outbound connections to the Internet from Server do NOT work while static NAT is in place.

For example:

* If I remove the following two lines from the configuration:

object network INT_NC-SERVERB_[url removed, login to view]

nat (inside,outside) static EXT_[url removed, login to view]

* I am now able to ping 4.2.2.2 from SERVERB, but the external IP ([url removed, login to view]) for the server no longer works.

* If I add the two lines back into the configuration:

object network INT_NC-SERVERB_[url removed, login to view]

nat (inside,outside) static EXT_[url removed, login to view]

* I am no longer able to ping 4.2.2.2 from SERVERB, but the external IP ([url removed, login to view]) for the server works.

シスコ ネットワーク管理

プロジェクトID: #16710505

プロジェクトについて

3個の提案 リモートプロジェクト アクティブ 6年前