05-07-2017 07:23 AM - edited 03-13-2019 09:53 PM
I am looking through the documentation and trying to understand the recommended NAT and firewall for my Expressway-E. Here is what I have.
Expressway-E - In a DMZ interface on ASA 192.168.1.2
I have created a static NAT rule from the inside to the DMZ using the same IP's.
I have the Advanced networking option installed but I don't see how to enable the second interface. The GUI only shows Lan1.
Can I NAT the 192.168.1.2 out to the public or do I need to use the second interface for this and create another DMZ? The recommended approach says to use 2 network adapters when using 2 firewalls but I am only behind one ASA.
05-07-2017 06:08 PM
Use dual interfaces and save yourself a lot of problems.
System -> Network Interfaces -> IP
There's the option to use dual NIC, just change it to Yes.
With that, you can follow the best design with dual interfaces outlined in the documentation, make sure to choose LAN 2 as your external LAN interface.
05-07-2017 07:58 PM
Edit: With the dual do I need to put interface 1 on the inside network and only put interface 2 in the DMZ of the ASA?
Do I need to select the option "IPV4 static nat mode" for both interfaces? I have a static nat defined for both on the ASA.
05-20-2017 06:25 PM
You can choose whatever external interface you want (interface 1 or 2), just put the correct one under "External LAN interface" parameter under System > Network interfaces > IP
Since the NAT is done on the ASA, you need to put the parameter "IPv4 static NAT mode" to "On" and specify the public IP address in "IPv4 static NAT address" field.
Expressway-E needs to be aware of it in order to change the SIP/H323 signaling while traversing the firewall.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide