11-05-2019 10:02 AM
Hello, I have ASA with next interfaces:
inside, security level 100
outside, security level 0
wifi, security level 50
dmz1 security level 20
Ad have in dmz1 server, for example 10.10.10.2 and my outside interface Ip for example 128.10.10.2/27
I have nat (outside,dmz) source static any any destination static extstvip intsrvip
where extsrvip is 128.10.10.3 and intsrvip 10.10.10.2
but I want to use single dns for all, mysrv.mycompany.com a:128.10.10.3 and when WiFi users gone to https://mysrv.mycompany.com they go to outside IP and I added next translation: nat(wifi,dmz1) source static wifinet wifinet destination static extsrvip intsrvip
This rule translate external Ip to real dmz ip and work fine .
but I want also allow WiFi users connect to webwpn to this Asa by outside Ip.
i try to added same translation like:
nat (WiFi,WiFi ) source static wifinet wifinet destination static outsideip WiFiinterfaceip
and enable webvpn on WiFi interface but it do not work.
what I do wrong :-) thank you!
11-05-2019 02:01 PM - edited 11-05-2019 02:18 PM
Hi there,
Whilst you can terminate VPNs on any interface, I believe that you need to use the interface which is closest to the client.
In this instance, if your WiFi users are coming in on your WiFi interface then you would have to terminate on that IP. They would not be able to connect to webvpn on the outside interface.
If you're trying to amend a DNS response to the client, try adding the keyword 'dns' to the end of your NAT statement to doctor the DNS response back to the client for your outside interface.
The following article might help:
11-05-2019 02:16 PM
I understand this, but I use public DNS on WiFi segment and it resolve my vpn fqdn to outside IP , and I want to translate it to wifi interface but I have problem.
Other way - I can deploy dedicated DNS server for WiFi segment and use other A record for vpn fqdn but it not best way.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide