<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Creating Internal and external access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934935#M457573</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you would need to setup nat that I have suggested in my previous post, that would give you complete access to the servers from the inside interface. From anyother interface as well the config is going to the same, just chnage in the interface names.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Mar 2012 11:26:35 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2012-03-30T11:26:35Z</dc:date>
    <item>
      <title>Creating Internal and external access</title>
      <link>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934932#M457569</link>
      <description>&lt;P&gt;I am using an ASA&amp;nbsp; versions below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.2(1)&lt;/P&gt;&lt;P&gt;Device Manager Version 6.2(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been tasked with enabling access from our internal networks to servers that are hosted on the DMZ and NATed to external clients.&lt;/P&gt;&lt;P&gt;How do I do this? The DMZ is not an internal routable network so do I use another NAT somehow ?&lt;/P&gt;&lt;P&gt;How do I propergate the DMZ server across the internal network ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934932#M457569</guid>
      <dc:creator>jeffreydavy</dc:creator>
      <dc:date>2019-03-11T22:48:59Z</dc:date>
    </item>
    <item>
      <title>Creating Internal and external access</title>
      <link>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934933#M457570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Going by your description, I assume you have three interfaces on the ASA, outside, inside and DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to access the DMZ servers on public IP's from the inside interface, then you would need the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,inside) 1.1.1.1 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (DMZ) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where 1.1.1.1 is the public ip and 10.1.1.1 is the private ip of server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to access DMZ servers on their original ip's only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,inside) 10.1.1.0 10.1.1.0 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (DMZ) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be the minimum required config, unless I didnt understand your setup correct, moreover can you tell me wat device you are using?? model number?? base or plus license??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2012 10:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934933#M457570</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-03-30T10:01:26Z</dc:date>
    </item>
    <item>
      <title>Creating Internal and external access</title>
      <link>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934934#M457572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you for responding Varun, but I the DMZ network is not routable across our MPLS network so that is what I need to understand. Do I have to set up another NAT so that we can access the DMZ servers from anywhrere in our network? Even across the MPLS from other offices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using an ASA 5510 ver 8.2(1)&lt;/P&gt;&lt;P&gt;running ASDM 6.2(1)&lt;/P&gt;&lt;P&gt;here are the interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.10&lt;/P&gt;&lt;P&gt; description SE-GF1-CR-A Tranit&lt;/P&gt;&lt;P&gt; vlan 10&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.116.10.5 255.255.255.0 standby 10.116.10.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.666&lt;/P&gt;&lt;P&gt; description SE-GF1-CR-A Legacy&lt;/P&gt;&lt;P&gt; vlan 666&lt;/P&gt;&lt;P&gt; nameif Legacy&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.16.104.254 255.255.252.0 standby 172.16.104.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; description SE-GF1-CR-A Gi1/0/4 Trunk&lt;/P&gt;&lt;P&gt; speed 1000&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.20&lt;/P&gt;&lt;P&gt; vlan 20&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 40&lt;/P&gt;&lt;P&gt; ip address 172.16.111.1 255.255.255.0 standby 172.16.111.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; description SE-GF1-CR1-A connects to Tele2 ISP&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2.15&lt;/P&gt;&lt;P&gt; vlan 15&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address pix_outside 255.255.255.240 standby 212.247.51.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif Extern&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 212.247.51.17 255.255.255.240 standby 212.247.51.27&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2012 11:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934934#M457572</guid>
      <dc:creator>jeffreydavy</dc:creator>
      <dc:date>2012-03-30T11:01:58Z</dc:date>
    </item>
    <item>
      <title>Creating Internal and external access</title>
      <link>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934935#M457573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you would need to setup nat that I have suggested in my previous post, that would give you complete access to the servers from the inside interface. From anyother interface as well the config is going to the same, just chnage in the interface names.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2012 11:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-internal-and-external-access/m-p/1934935#M457573</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-03-30T11:26:35Z</dc:date>
    </item>
  </channel>
</rss>

