12-11-2011 06:13 PM - edited 03-11-2019 03:01 PM
Hi,
I have a ASA5510 with 2 internal interfaces (inside1 and inside2 same security level) configured with OSPF for dynamic routing with 2 routers to corporate subnets. I have a server in a private subnet that needs to be accessed from Internet. So static pat is used in ASA with the command
static (inside1, outside) tcp interface www 192.168.1.1 www netmask 255.255.255.255
As OSPF is in use, the subnet 192.168.1.0/24 may be reachable from interface inside2. When I tried to configure the static command for inside2,
static (inside2, outside) tcp interface www 192.168.1.1 www netmask 255.255.255.255
the error message came out "WARNING: mapped-address conflict with existing static...". Is this just a warning, or this is not possible in ASA.
Thanks.
Solved! Go to Solution.
12-11-2011 11:04 PM
This is not possible routing for subnet 192.168.1.0/24 will only point to one interface inside1 or inside 2. Thats the reason error msg is coming.
In ASA when we configure route we need to tell outgoing interface for ex.
route inside x.x.x.x x.x.x.x
So while configuring 2nd command of yours makes ASA confusing what would be the outgoing interface for this traffic.
Thanks
Ajay
12-11-2011 11:04 PM
This is not possible routing for subnet 192.168.1.0/24 will only point to one interface inside1 or inside 2. Thats the reason error msg is coming.
In ASA when we configure route we need to tell outgoing interface for ex.
route inside x.x.x.x x.x.x.x
So while configuring 2nd command of yours makes ASA confusing what would be the outgoing interface for this traffic.
Thanks
Ajay
12-12-2011 11:30 AM
Thanks Ajay,
Then what is the point of having dynamic routing capability in ASA?
Regards.
Chuan
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: