02-05-2011 05:00 AM - edited 03-11-2019 12:45 PM
Hi,
I have Cisco ASA and i have connected Exchange 2007 Edge Server in DMZ and Client Acces Server in Local Network. Can anyone please tell me how to configure the ASA for this?
Thanks,
02-05-2011 05:28 AM
Hi Mohammed,
So what how do you want the server to be seen as by the client? do you want the clients to access the server with original ip address of the server or a translated ip address?
Also what is the security level configured on the DMZ and the local network?
basically on the ASA you will need configure a nat for traffic to parse the different security level interfaces.
Regards,
Anisha
02-05-2011 05:55 AM
02-05-2011 06:11 AM
hi,
So i understand the topology would be:
Client -- (inside) ASA (DMZ) -- Server..
Please let me know the server ip address and the ip you want to translate it to.
Regards,
Anisha
02-05-2011 06:38 AM
Hi,
Please have a look on the configuration of ASA is that configured properly or not.
Edge Transport Server (Frontend Server )IP is - 192.168.200.6 (Local IP) (this is server is in DMZ)
212.xx.xx.167 (Public IP)
Client Access Server (Backend Server) IP is - 172.20.16.5 (Local IP ) this server is in the local network.
Thanks,
02-06-2011 04:43 PM
Hi mohammed-amjad,
this looks very familiar to me, I recently had a quite similar case on one of our customers network. A couple of issues:
I cannot give you my config. because your situation might be totally different. We for example have 3 domain controllers on the inside with distributed functions, aditionally we have OWA which again needs some specific protocols (as far as I remember that's the rpc-over-ssl tunneling with some specific ports) and I'm not deep enough into the details of Microsoft to give you advice on what to configure, I'm glad that I have may situation a little bit under control.
At the moment (and I'm not happy with it) I have permitted quite generously tcp any from the frontend to the backend similar to your current "permit ip any any".
I'm afraid you need to be quite generous from dmz to inside in your situation.
Rgds,
MiKa
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide