cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
957
Views
0
Helpful
3
Replies

ASA 5510 strange behavior when move server to DMZ

skyranger9999
Level 1
Level 1

I begin setup ASA 5510 and create DMZ, succesfull add our proxy to DMZ and all works fine, now i want to add one more server to DMZ.

I add NAT and set our free external ip to it all works fine, but when i turn off networks cable from server, left only DMZ link and use it with NAT all stop working! I can ping DMZ gateway, but cant access internet :(

I attach my config to this post.

I am new to cisco devices, and suspect there may be some protection from IP address change or kinda, but cant figure out what wrong :(

3 Replies 3

Sajid Ali
Level 1
Level 1

skyranger9999,

I think no access-list permitting 192.168.1.4 from dmz to outside.

 

Always rate helpfull posts

Sajid Ali Pathan

192.168.1.4 works fine it 192.168.1.5 i have problems, but when i setup temporary any to nay globally it still did not work so it not ACL problem :(

I move 1 more of my server to DMZ after i run on it 'arp -d *' and reboot, but other server i still have this problem, when i set in NAT x.x.x.201 external ip it stops ping out sites and only ping DMZ, but when i change ip to free external in x.x.x.205 all begin works.

 

Prblem is there mail server and there DNS records i did not whant to change :(