cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
336
Views
0
Helpful
4
Replies

two public natted to single private

lcaruso
Level 6
Level 6

Hi,

As long as this is for inbound traffic only, I'm assuming this will not cause problems?

Two different public ips on the outside interface (doesn't include the interface ip) static natted to a single dmz host.

Thanks.

1 Accepted Solution

Accepted Solutions

Hi,

I think it should work in the way you describe.

If connections are opened from the "outside" there should be no problem.

On the other hand if the server opens the connections at some point, it will only be using only one of the Static NAT configurations when connecting "outside". And the the Static NAT used for outbound connections would be chosen according to how the ASA handles NAT order of operations.

- Jouni

View solution in original post

4 Replies 4

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

You mean that you want 2 public IP addresses for a single DMZ host IP address?

Is theres a specific reason for this kind of setup and what is it?

I guess you can configure this but for it to actually have any possibility to work you have to somehow specify when each public IP address is used.

Can you first clarify the reasoning for looking for this kind of NAT setup and then we could look into the actual configuration.

Also mention your device software version.

- Jouni

Thanks for your reply. IOS is 8.3(2).

The webmaster specified that setup. Domain names resolve to the seperate outside address.

name1.domain.com = > public ip 1 => dmz host foo

name2.domain.com => public ip 2 => dmz host foo

dmz host foo uses http headers to determine which website traffic is sent to

My understanding was as long as the traffic is initiated inbound, this would work okay.

Hi,

I think it should work in the way you describe.

If connections are opened from the "outside" there should be no problem.

On the other hand if the server opens the connections at some point, it will only be using only one of the Static NAT configurations when connecting "outside". And the the Static NAT used for outbound connections would be chosen according to how the ASA handles NAT order of operations.

- Jouni

Seems to be working in testing as you describe.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card