cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
479
Views
0
Helpful
1
Replies

Static NAT to inside DNS address

ROBERT CROOKS
Level 1
Level 1

I'm struggling to address an issue where as a policy I have internal virtualized/clustered servers on reserved DHCP addresses on a separate VLAN, and occasionally there is a situation where by the guests change hosts and end up on another VLAN (for whatever reason) or with a different IP address.

This isn't an issue for my internal users because all our communications works off DNS addresses, but I have a natted FTP server that whenever it changes IP/VLAN, i have to manually change the natted address on my ASA.

ex

static (inside,Outside) 100.100.100.101 192.168.100.39 netmask 255.255.255.255

would like to use a DNS address of ftp.domainname.com instead of the IP address so that if the inside IP changes I don't have to rewrite the static rule every time.

Is there any facility to do this with the ASA?

thanks

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Robert,

Not possible to do it on the ASA. You will need to use the ip address on the Nat statements.

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card