cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1066
Views
0
Helpful
2
Replies

setting up internal and external with ASA

jmitchell26
Level 1
Level 1

My CTO want to implement an external firewall that connects to a dmz and internal firewall to connect to the internal LAN using ASA. We currently have an one ASA between the ISP and LAN, no dmz. I am using cisco packet tracer to help with some of the basic configuration but I am having issue get my LAN to get to the internet or access a server in the DMZ. Any help will be appreciated.ASA_to_ASA.png

2 Replies 2

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

I assume in your new topology the 'external' ASA will be NAT'ing both your internal and DMZ subnets (the entire 10.0.0.0/8)? If that is the case all you need to ensure is that the local routes to the DMZ layer3 switch are known by the internal layer3 switch and vice versa.

Static routing configured on all devices in the path would suffice for this.

 

Please share your config if this needs further explanation.

 

cheers,

Seb.

Dennis Mink
VIP Alumni
VIP Alumni

check routes and run a packet capture on the external FW to see if your LAN users hitting the internet, are actually hitting the external FW on its inside interface,

 

are you doing double NAT or only NAT on external FW?

Please remember to rate useful posts, by clicking on the stars below.

Review Cisco Networking for a $25 gift card