<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: host inside DMZ with a public IP configured - no access to o in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615520#M594316</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're running 8.2.x and below you need a static NAT and an ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 213.140.0.9 213.140.0.9&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 213.140.0.9 eq XXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need the static to create the NAT entry and the ACL to allow the ports needed. &lt;BR /&gt;The ACL should be applied to the outside interface in the inbound direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jan 2011 17:35:27 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2011-01-13T17:35:27Z</dc:date>
    <item>
      <title>host inside DMZ with a public IP configured - no access to outside</title>
      <link>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615519#M594314</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a server in a DMZ configured with a direct public IP. What do i have to configure on the ASA so that the Server is reachable from outside and have internet access from the DMZ? It`s a Webserver and FTP Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INSIDE: 10.10.10.0 /24&lt;/P&gt;&lt;P&gt;DMZ: 213.140.0.9 /29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA DMZ Interface: 213.140.0.10&lt;/P&gt;&lt;P&gt;DMZ Server: 213.140.0.12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment i`m not able to reach the internet or access from the internet the DMZ server. What steps do i have to configure in simple words for a beginner &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:34:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615519#M594314</guid>
      <dc:creator>born.jason</dc:creator>
      <dc:date>2019-03-11T19:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: host inside DMZ with a public IP configured - no access to o</title>
      <link>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615520#M594316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're running 8.2.x and below you need a static NAT and an ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 213.140.0.9 213.140.0.9&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 213.140.0.9 eq XXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need the static to create the NAT entry and the ACL to allow the ports needed. &lt;BR /&gt;The ACL should be applied to the outside interface in the inbound direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 17:35:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615520#M594316</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-13T17:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: host inside DMZ with a public IP configured - no access to o</title>
      <link>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615521#M594318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Frederic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if i`m running Asa 8.3(1) ? How it looks like there?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 18:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615521#M594318</guid>
      <dc:creator>born.jason</dc:creator>
      <dc:date>2011-01-13T18:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: host inside DMZ with a public IP configured - no access to o</title>
      <link>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615522#M594319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The concept is the same, but the syntax changes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-213.140.0.9&lt;/P&gt;&lt;P&gt;host 213.140.0.9&lt;/P&gt;&lt;P&gt;nat (dmz,outside) static 213.140.0.9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In version 8.3, the ACL should reference to the real IP not the NATed one but it does not matter here since you're using the public IP directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 18:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615522#M594319</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-13T18:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: host inside DMZ with a public IP configured - no access to o</title>
      <link>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615523#M594320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you mean network or the host?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-213.140.0.9&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;network&lt;/STRONG&gt; 213.140.0.9&lt;/P&gt;&lt;P&gt;nat (dmz,outside) static 213.140.0.9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or the DMZ host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-213.140.0.12&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;host&lt;/STRONG&gt; 213.140.0.12&lt;/P&gt;&lt;P&gt;nat (dmz,outside) static 213.140.0.12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the ACL is the same and i have to assign it to the inside interface like you said in your first post?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside permit tcp any host 213.140.0.9 eq XXX&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 19:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615523#M594320</guid>
      <dc:creator>born.jason</dc:creator>
      <dc:date>2011-01-13T19:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: host inside DMZ with a public IP configured - no access to o</title>
      <link>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615524#M594321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct. Since you are interested in accessing the host on a specific port, you can configure the object group with "host" keyword and then configure the STATIC NAT. In the access-list, you can allow access to specific ports. One thing you need to remember is some of the early 8.3 versions have Proxy ARP issues related to identity NAT (the way you are doing it). If your configuration did not work, then try configuring private IP on the DMZ and statically map it to a public IP on the outside and see if that helps (when you do this, in your access-list, you need to allow access to the real IP i.e. private IP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 22:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-inside-dmz-with-a-public-ip-configured-no-access-to-outside/m-p/1615524#M594321</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2011-01-13T22:55:32Z</dc:date>
    </item>
  </channel>
</rss>

