Showing results for 
Search instead for 
Did you mean: 

ASA 5505 Base License - DMZ workaround


OK, so I get that the ASA 5505 Base License can only have a 3rd named VLAN interface if that interface has the "no forward interface XXX" command used. I have a customer with the following interfaces:

  1. outside
  2. inside
  3. DMZ

The DMZ is currently configured to prevent forwarding to the inside interface. Hosts on inside and DMZ have Internet (can sent to outside), Internet hosts can access hosts on both VLANs through ACLs and NAT statements, but DMZ hosts cannot initiate any connections to hosts on the inside. I get that, and understand it is by design. But I have a theoretical workaround that I cannot get working, and I am curious if it is a licensing issue or misconfiguration.

From the DMZ, I initiate a connection to a public IP, which I do auto NAT on the outside interface to translate that to an inside host. Technically the traffic goes from DMZ to outside, then outside to inside. Problem is that I cannot make heads or tails of the configuration to test this. Partially because it's a confusing concept to me, and partially because I am new to the 8.4+ NAT syntax and this is all being attempted on an ASA running 9.1.

So, besides buying the Security Plus license, is this even possible? If the license upgrade is the only option, what part number am I looking for? The ASA is brand new, running the base license, 10 inside hosts, FOS 9.1

1 Reply 1

Luis Silva Benavides
Cisco Employee
Cisco Employee


The best way to solve this will be to buy security plus license since the workaround you are planning won't work



Luis Silva

"If you need PDI (Planning, Design, Implement) assistance feel free to reach"

Luis Silva
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: