Cisco ASA - Combination of PUBLIC and LOCAL IP within one ASA 5510.
We configured ASA5510 like this:
Int0 – outside connected to modem
Int1 – inside connected to internal switch
IP Route is managed by configuring PPPOE within ASA
Our inside has IP 126.96.36.199/29
Our outside has IP 188.8.131.52
Obviously, we could use any of the static public IP address within range /29 connected to internal interface int1 which they are all consider behind Firewall and we could manage to open port or services to any. (e.g. if we connect application mail server to one static IP facing inside network like 184.108.40.206, we could manage to open SMTP ports in/out and or SSH to trusted IP)
What we need now is to have another range of internal IP address (i.e. class C like 10.10.10.1/24) in 3rd interface ASA (int2) and they have routed to one of the public IP within int1 (inside).
For instant, we want to have 10.10.10.1/24 routed to 220.127.116.11 and also have an opportunity to do apply firewall rules and NATing from external to internal (i.e. assume we set web-server on IP 10.10.10.195, we like to open port HTTP and HTTPS to public while external IP would be 18.104.22.168)
Clearly this is possible by adding another router – but we want to use same ASA5510 for both of these requirements.
If anyone done this before or have some solution, we would apricated the help and feedback.
As of June 2020, the Cisco ISE pxGrid App for QRadar Ver 1.1.0 is officially Validated and released by IBM, available for download from IBM XFE. Access the link to download app here.
The Cisco ISE pxGrid App V1.1 supports Cisco Identity Se...
i have an ip that is part of our internal network, i configured route map on the core to redirect the traffic to the firewall for further inspection.i checked the firewall logs i can see the traffic is redirect to the firewall successfully. i could ping o...
Hi, 1)May I know wht it means when context visibility Status showing 'disconnected" and '(blank)'?Difference between 'disconnected" and '(blank)'. Since both devices also not connected.I found tht these devices are no longer connected to the swi...
Hi ,I would like to configure multiple public ip (same subnet) on outside interface of ASA.I want to use static NAT for specific purpose.For example i have 8 public IP and I want to use 1 is internet ,1 for VPN ,1 for DMZ server and all ip want to a...
Hi all, Is it a way to retrieve the IPS policies from our IPS Appliance or censor? I have tried to look for a way but I am not able to do so. May I knwo any way can retrieve the policies from the Appliance either from the Appliance itself o...