02-24-2023 11:37 AM
Hello.
"object network SERVER1
nat (dmz,Outside) static 1.1.1.1"
If the connection is initiated from the Outside to the DMZ , and the Outside ACL allows this traffic, will this circuit connect, or will it fail because there is needed an additional NAT rule?
Thank you.
Solved! Go to Solution.
02-24-2023 11:39 AM
@jmaxwellUSAF that'll work. Traffic sent to the nat ip of 1.1.1.1 will be untranslated to the private IP address of the DMZ server.
You'd obviously need an ACE in the ACL to the private (real) IP address of the server to permit the traffic.
02-24-2023 11:39 AM
@jmaxwellUSAF that'll work. Traffic sent to the nat ip of 1.1.1.1 will be untranslated to the private IP address of the DMZ server.
You'd obviously need an ACE in the ACL to the private (real) IP address of the server to permit the traffic.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide