cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
920
Views
0
Helpful
3
Replies

NAT from DMZ to Outside or inside doesn't work on FTD managed by FMC

ipv6x
Level 1
Level 1

Hello,

I am trying to understand why the nat from the DMZ zone doesn't work outside or inside.

DMZ Host 1 with private IP: 192.168.40.99 ----> I want to translate outside with IP: 192.0.2.50, I want to ssh from outside to DMZ H1.

Configured NAT from DMZ TO OUT see the photos.

I have configured ACP from out to DMZ allowing SSH traffic but doesn't work, any ideas why doesn't work?

 

 

1 Accepted Solution

Accepted Solutions

@ipv6x use a Static Auto NAT rule (not manual), the source address would be host "dmz-real-h1" and the translated address is "IP_192.0.2.50".

View solution in original post

3 Replies 3

@ipv6x use a Static Auto NAT rule (not manual), the source address would be host "dmz-real-h1" and the translated address is "IP_192.0.2.50".

@Rob Ingram i configured like this but nothing happened and I see on ACP hist the out-in-dmz gets hits but nothing passes why this?

ipv6x
Level 1
Level 1

I figured out @Rob Ingram i was missing the route from DMZ Host to FTD, after I configure the route now it worked. 

 

Thank you,

Regards,

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card