06-06-2018 02:07 PM - edited 02-21-2020 07:51 AM
Hello,
I have a server off an interface on my ASA 5585 firewall. I need to give a contractor access to this from the outside interface but this server is not on my DMZ interface. Its on another interface that points to the corporate network (inside interface).
I usually NAT a public IP and give a contractor access to a DMZ server.
Can i do something like this but forward them on from the DMZ to the other interface on the ASA ie port forwarding.
just looking some advice - thanks
Solved! Go to Solution.
06-07-2018 03:28 AM
if the box your contractor is trying to connect to is on the inside and you cannot move it to the dmz, then you have no choice.
you might want to consider giving them limited VPN access or provide RDP access to a machine in the DMZ from which they can jump onto the internal machine.
If its a once off, just open the port and when they are done; close it
06-06-2018 04:58 PM - edited 06-06-2018 04:58 PM
Yes you can do a port forward from outside to inside, in the same way as from outside to dmz. its not desired, but it is possible
06-07-2018 02:07 AM
Is that my best option or would you know of a better way to do this?
Maybe Cisco have a best practise solution
thanks, Kevin
06-07-2018 03:28 AM
if the box your contractor is trying to connect to is on the inside and you cannot move it to the dmz, then you have no choice.
you might want to consider giving them limited VPN access or provide RDP access to a machine in the DMZ from which they can jump onto the internal machine.
If its a once off, just open the port and when they are done; close it
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide