<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access Inside network printer from DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-inside-network-printer-from-dmz/m-p/2230156#M349944</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will give it a try and keep you posted of the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 May 2013 18:32:52 GMT</pubDate>
    <dc:creator>Douglas Sensenig</dc:creator>
    <dc:date>2013-05-14T18:32:52Z</dc:date>
    <item>
      <title>Access Inside network printer from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/access-inside-network-printer-from-dmz/m-p/2230154#M349941</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been spinning my wheels trying to figure out how to allow users in the DMZ, who have their own Internet connection, to access a printer on the Inside network but nothing else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA software 9.1.1&lt;/P&gt;&lt;P&gt;DMZ: 10.10.10.0/24&lt;/P&gt;&lt;P&gt;DMZ interface IP: 10.10.10.1&lt;/P&gt;&lt;P&gt;DMZ security level: 50&lt;/P&gt;&lt;P&gt;Inside: 192.168.0.0/24&lt;/P&gt;&lt;P&gt;Inside Interface IP: 192.168.0.1&lt;/P&gt;&lt;P&gt;Inside Security Level: 100&lt;/P&gt;&lt;P&gt;Printer: 192.168.0.51/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created an ACL to allow the 10.10.10.0/24 subnet access to the printer (192.168.0.51). I did not include a port # in the ACL as I was unsure of the port # used by the printer. What other steps do I need to take to resolve this issue? Static NAT, port redirect,etc?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your time and help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Douglas&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-inside-network-printer-from-dmz/m-p/2230154#M349941</guid>
      <dc:creator>Douglas Sensenig</dc:creator>
      <dc:date>2019-03-12T01:43:10Z</dc:date>
    </item>
    <item>
      <title>Access Inside network printer from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/access-inside-network-printer-from-dmz/m-p/2230155#M349942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not 100% sure on your setup BUT it seems to me that you are implying the the default route for the DMZ hosts points to somewhere else than the ASA DMZ interface IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess one option would be to NAT the "inside" printer to a "DMZ" network address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would essentially mean that even though DMZ hosts default gateway might be somewhere else than on the ASA, if they were actually to connect to an IP address on their directly connected network they would simply ARP for the MAC address of that destination IP address and the connection would be forwarded from the connecting host directly to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you could consider something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PRINTER&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.0.51&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,dmz) static 10.10.10.51&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT IP address used could naturally be something else IF the above IP address is already in use on the DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this works for you. If there is some problems we can use some commands to test if the rule works correctly or if there is some other problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to mark the reply as the correct answer if it answered your question. And/or rate helpfull answers &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ask more if needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 18:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-inside-network-printer-from-dmz/m-p/2230155#M349942</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-14T18:22:18Z</dc:date>
    </item>
    <item>
      <title>Access Inside network printer from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/access-inside-network-printer-from-dmz/m-p/2230156#M349944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will give it a try and keep you posted of the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 18:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-inside-network-printer-from-dmz/m-p/2230156#M349944</guid>
      <dc:creator>Douglas Sensenig</dc:creator>
      <dc:date>2013-05-14T18:32:52Z</dc:date>
    </item>
  </channel>
</rss>

