05-24-2016 10:13 AM - edited 03-12-2019 12:47 AM
Hi,
If I have two web servers (say 10.1.1.1:80 & 10.1.1.2:81) in a DMZ, is it sufficient enough to add a static NAT or PAT only and the servers will be reachable from outside on those ports?
Or do you need an outgoing dynamic nat in order for those servers to reply outbound?
Solved! Go to Solution.
05-24-2016 01:13 PM
Hi there,
It is sufficient to use a static NAT entry for this because the ASA is stateful and will build a connection which allows the traffic to communicate both ways. If you go from outside to inside and use the unidirectional keyword, then the traffic can only be initiated from the outside.
You can learn more of how to configure this scenario here: http://www.internetworkingcareer.com/firewall/configure-nat-asa-firewall/
Regards,
Tim
05-24-2016 01:13 PM
Hi there,
It is sufficient to use a static NAT entry for this because the ASA is stateful and will build a connection which allows the traffic to communicate both ways. If you go from outside to inside and use the unidirectional keyword, then the traffic can only be initiated from the outside.
You can learn more of how to configure this scenario here: http://www.internetworkingcareer.com/firewall/configure-nat-asa-firewall/
Regards,
Tim
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide