<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not able to access servers using public ip from internal seg in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483046#M711221</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to hear, and thanks for the update and rating.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 May 2010 06:19:30 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-05-18T06:19:30Z</dc:date>
    <item>
      <title>Not able to access servers using public ip from internal segment</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483043#M711056</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to access internal servers using public IP. The server and the client, Both are in inside DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The server has a static nat.The client uses global IP. ASA 5540 is been used&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Manish Gupta&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:46:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483043#M711056</guid>
      <dc:creator>QPM277111</dc:creator>
      <dc:date>2019-03-11T17:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to access servers using public ip from internal seg</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483044#M711111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you have the following:&lt;/P&gt;&lt;P&gt;Inside network: 192.168.1.0/24&lt;/P&gt;&lt;P&gt;DMZ network (where the server is): 192.168.5.0/24&lt;/P&gt;&lt;P&gt;Server IP: 192.168.5.5 --&amp;gt; NATed to 200.1.1.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the above, I assume you already have the following configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 200.1.1.5 192.168.5.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming that you would like to access the public ip of the server 200.1.1.5 from the inside network, you need to add the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,inside) 200.1.1.5 192.168.5.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have ACL assigned to the inside interface, you would need to allow traffic towards the public ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the above assumption is incorrect, and you have your server in the inside network instead (with ip of 192.168.1.5), and would like to access it from the inside via its public ip, here is the commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;static (inside,inside) 200.1.1.5 192.168.1.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;-- assuming that you have "nat (inside) 1 0 0" statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have ACL assigned to the inside interface, you would need to&amp;nbsp; allow traffic towards the public ip as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 May 2010 12:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483044#M711111</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-17T12:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to access servers using public ip from internal seg</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483045#M711164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue got resoved after i used a different public IP rather than the default global IP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 06:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483045#M711164</guid>
      <dc:creator>QPM277111</dc:creator>
      <dc:date>2010-05-18T06:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to access servers using public ip from internal seg</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483046#M711221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to hear, and thanks for the update and rating.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 06:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-access-servers-using-public-ip-from-internal-segment/m-p/1483046#M711221</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-18T06:19:30Z</dc:date>
    </item>
  </channel>
</rss>

