Cisco ASA 5505 - Allowing traffic between two internal networks

Hi all,

I'm usually not working with this product, but this is what I'm trying to do.

I have 2 internal networks setup on our Cisco ASA 5505 firewall. (not done by me, I'm a new to this product)

I'm trying to access a server on one network from a PC located on the other internal network.

I'm wondering if someone can tell me how to do this? (preferable through the web gui)

Or how I debug this?

This is the current setup.



Name    Switch port       Security Level       IP address       Subnet mask         VLAN

Trust6    Ethernet0/6      100                      vlan 6 (this is where the server is)

Trust4    Ethernet0/4      100                      vlan 4 (this is where my connecting PC is)

(Checked the checkbox: "Enable traffic between two or more interfaces which are configured with same security level")

Security Policy:

Trust4 (incoming rules):

Source    Destination    Service    Action

any            any        ip        Permit

Trust6 (incoming rules):

Source    Destination    Service    Action

any            any        ip        Permit

When I try "Packet Tracer" from interface "Trust4" it fails on the NAT phase.

(Source ip:, Destination ip:

When I check the NAT rule, it says:

Type            Source     Interface    Address

Dynamic         any          outside      outside


Hope anyone can point me in the right direction.



Maykol Rojas
Try this

static (trust4,trust6)

static (trust6,trust4)

same-security-traffic permit inter-interface.

Let me know how it goes



Hi Maykol,

Thanks for your reply.

I took a look at the running config and saw that "same-security-traffic permit inter-interface" is already enabled.

But I would like to try your other suggestions. But before I do that. How do I revert this command, if I mess something up:

static (trust4,trust6)

And could you please explain what these two commands will do exactly?

Thanks for you for helping a novice




That what is going to do is to create a translation on the ASA so that people from Trust6 can see people from trust4 with the same IP.

If these interfaces (trust4, trust6) have access to another interface such as internet, mostlikely you are going to have an entry like this

nat (trust4) 1 0 0

That would nat everything going to some other place, if you dont have a global to go to Trust 6, your connection is going to fail because of NAT, and even if you add a global, it would fail because it is a dynamic NAT.

Basically, I just want to avoid doing translations and both 10.0.4 and 10.0.6 can communicate with each other, without doing nat translations.


