05-23-2016 10:09 AM - edited 03-12-2019 12:47 AM
Hi,
I have an OUTSIDE interface (goes to another private network 10.1.1.254/24)
On the INSIDE interface (192.168.200.0/24) we have various servers. These are statically natted to a different ip eg 10.1.1.1 > 192.168.200.1, 10.1.1.2 > 192.168.200.10 etc
There is no dynamic nat from the INSIDE to the OUTSIDE or no global nat set.
I now need to add a DMZ (172.31.1.1/24) with dynamic NAT to the OUTSIDE. Will this break the static nat's (on the INSIDE interface) already in place?
Solved! Go to Solution.
05-24-2016 01:01 AM
There is also IOS Firewall.
You can add a dynamic NAT for just the DMZ to the outside interface without breaking the existing static NAT (assuming the IP addresses don't overlap anywhere).
05-23-2016 01:21 PM
It would help if you could at least say what kind of device you have. Cisco 800 series running IOS, Cisco ASA 5505 running 8.4(7), etc.
Could you post your current NAT configuration?
05-23-2016 10:25 PM
Sorry, Because I posted in firewalling I assumed it would be an ASA. It's an ASA 5510 running 8.2
05-24-2016 01:01 AM
There is also IOS Firewall.
You can add a dynamic NAT for just the DMZ to the outside interface without breaking the existing static NAT (assuming the IP addresses don't overlap anywhere).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide