04-24-2011 10:46 AM - edited 03-11-2019 01:25 PM
Hello community!
I have the following scenario:
ISP 1 ======== Router ========== ASA ========= INSIDE NETWORK
|| ||
|| ||
ISP 2 DMZ
I tested this scenario in a lab enviroment simulating an outside network on the router to check if ASA was doing NAT properly for both public subnets and it worked. The router had a default route pointing to the ASA an i was able to access services in Inside and DMZ networks. The problem is that when i tried this scenario in the real environment (the Router with route maps for PBR and the default-route pointing to ISPs) i could access services through only one of the public subnets from the Internet but not both. I think traffic knows how to go out but when coming from the Internet the router doesnt know what to do with it from the subnet that is not common between the Router and ASA. How can i fix this without using another interface of the ASA?? Any Idea? Thanks in advance.
AF.
Solved! Go to Solution.
04-24-2011 07:14 PM
There should be no problem for your router to route return traffic for subnet Y to the ASA using a next-hop from subnet X. Did you configure a static route on the router for subnet Y to point to the ASA's outside IP?
04-24-2011 07:14 PM
There should be no problem for your router to route return traffic for subnet Y to the ASA using a next-hop from subnet X. Did you configure a static route on the router for subnet Y to point to the ASA's outside IP?
04-26-2011 11:59 AM
Hey Roman! how are you doing?
Thanks for your reply. I did try with the static route pointing to the ASA but it didn´t work. Is it possibly to create subinterfaces on the ASA and then create a trunk between the ASA and the Router with the 2 subnets?. I don´t know why i didn´t worked that time, i also thought that the static route could be a solution. I couldn´t do much because i had a litle window to test changes in the real enviroment. Any recommendation?. Thanks again.
AF.
04-26-2011 03:11 PM
Hi Andre,
Would it be possible if you assign example IPs and masks to your diagram to understand better.. I cant seem to undestand who has which IPs.. How exactly are you natting and on which device?? Where is the ISPs router and how is it connected to your network?
Motaz Khraisat
04-28-2011 09:42 AM
Thank you all for your support. I did work with the static route from the Internet Router. We were having a problem with de public DNS server that wasnt updating a change in the config.
AF
04-28-2011 07:44 PM
I'm glad you figured it out.
04-28-2011 08:11 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide