05-27-2012 04:22 AM - edited 03-11-2019 04:12 PM
hi all,
i am having cisco asa 5520 with internet having public ip and cisco 2911 with mpls link in my office .. the mpls link is between my HO and my branch
i am putting my webserver in the branch side i want to port forward one of my publicip in my office to be forwarded to branch web server.
is it poosible on the firewall ouside the local network.
thanks
cyril
05-27-2012 04:58 AM
Yes, it is possible to configure port forwarding on the firewall with ip address not local to the network, as long as the web server default gateway at the branch is pointing towards the ASA at the HQ.
I assume that the branch office internet gateway is via the HQ through MPLS?
05-27-2012 05:09 AM
hi jenni,
i am having seperate internet on my branch side but there is DSL 100mps with dynamic ip.
so i want to use my mpls link to forward the ports in my firewall.
is there any possiblity to confgiure without changing gateway because we are having some vlans on my branch side.
thanks
cyril
05-27-2012 05:13 AM
No, if you are port forwarding on your HQ firewall, that means traffic is coming in via HQ, and since branch office has its own internet connection, that means the return traffic will be routed via the branch office internet, and this is asymetric routing, and packet will be dropped on the ASA firewall.
To port forward on HQ firewall, the traffic needs to come in and out the same firewall.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide