cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1189
Views
0
Helpful
5
Replies

Asa Firewall 9.14 unable to get internal server outside to Internet

gashi.kadri
Level 1
Level 1

Im trying to setup my asa 5506x Firewall to my company , 

I have Exchange Server in my current setup and it is working well using ASA FIREWALL 5520 with version 8.2 

I have set the new ASA but i can not getting work like the current bcs the setup is different on ASa 5506x with version 9.14 

 

i have public ip addresses in both WAN IP 

I want that when uses from internet trying to reach my public ip they get responce from 192.168.88.95 which is my exchange sever in VLAN 60 

 

 

 

 

 

1 Accepted Solution

Accepted Solutions

Just to confirm have you check your dns server pointing to right DNS ip address/es

please do not forget to rate.

View solution in original post

5 Replies 5

your nat rules look good. also add the nat rule for your back up internet line too.

what you see when you do a packet tracer.

 

packet-tracer input VLAN10 tcp 8.8.8.8 1234 X.X.X.X 80 detail

where x.x.x.x is your public internet Ip address.

please do not forget to rate.

gashi.kadri
Level 1
Level 1

HI Sharaz i have fixed some of my rules what i have  used portforwarding for my exchange server so the server is reachable from out now but not reachable from VLANs 

i can reach from outside interner but not from internal using mail.mycompany.com 
but not from vlans 

You mentioned you can not reach server from internal vlans. for these vlans the default gateway is the firewall?

 

1. In your firewall configuratons your security-level of vlan60 is security-level 50 where as your other vlans have security-level 100. now from higher (for example security-level 100 to security-level 50) lower is allowed. what you see in syslog messages?

 

2. for mail.mycompany.com is the DNS entry is setup correctly? can you ping the ip address or can you reach the web-page using the ip address?

 

is there a router behind the firewall?

 

 

please do not forget to rate.

Just to confirm have you check your dns server pointing to right DNS ip address/es

please do not forget to rate.

thank you sharaz salim it was the dns who has causing this problem 

the dns server that i have inside my company .

i removed the dns entries and everythink is working fine thank to you 

Review Cisco Networking for a $25 gift card