01-14-2016 03:03 PM - edited 03-12-2019 12:08 AM
Hi,
we have a block of 8 ip's and a DMZ setup on an ASA 5510. We're using static NAT to forward ports onto hosts in the DMZ but I was wondering if it was possible to assign one of these hosts one of the public ip's directly rather than use a private ip address and static NAT?
Would there be any advantage to this?
01-14-2016 05:58 PM
You would have to configure the block on an actual ASA interface before you could configure the public IP address directly on the host.
01-14-2016 11:03 PM
Hi, we already have the block of 8 ip's configured on the outside interface. Currently, we're using static nat to reach the internal hosts in the DMZ but we're told that you don't need to use this all of the time eg we have another host and we're told that this can use an external ip (which is obviously set on the host itself) rather than a private ip and static nat.
We've not done this before so are wondering how you would go about this in the ASA. Obviously the ASA would still be doing the firewalling and access rules to host.
01-15-2016 12:36 AM
You would need to move the block of IP's to an interface, and ask the ISP to route them via your outside interface. You will loose the network and broadcast addresses, plus one for the ASA, so you would be left with 5 usable IP address.
01-14-2016 11:45 PM
This is how it's typically done:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide