cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
464
Views
0
Helpful
1
Replies

Help with rule/nat on ASA 5520

whiteford
Level 1
Level 1

Hi,

I hope this is possible.

I have a Cisco ASA 5520 with 2 DMZ's (on a Cisco 3750 trunked from the ASA).

One DMZ1 (172.24.0.0/24) has our webservers and DMZ2 (10.10.0.0/16) has a remote company with servers we use.

Now they have as me to prepare routing on my ASA so if they send data to 192.168.200.22 port 703 is will instead go to 172.23.0.18 port 703 which is our web vlan.

Not sure why they are sending to 192.168.200.22 yet on 702, but I need to get our ASA to respond to this request on 172.23.0.18 on 703.

Hope you can advise

1 Reply 1

Collin Clark
VIP Alumni
VIP Alumni

On DMZ2 you need to create NAT's. For example-

static (inside,dmz2) 192.168.200.22 172.23.0.18 netmask 255.255.255.255

From their side they point the 192.168.200.x network out their firewall (to your IP of 10.10.x.y, your firewall IP) and the ASA will listen for requests and translate.

Hope that helps.

Review Cisco Networking for a $25 gift card