06-13-2023 12:29 PM
We are in the process of migrating from an older ASA to an FTD appliance. I've had the FTD in place for our site-to-site VPN's and am now at the point where I need to migrate servers which are behind the ASA over to the FTD.
We have an externally routable subnet which we refer to as the DMZ. It's not a true DMZ per say as it is located behind the outside interface.
Attached is a diagram.
I hope this answers most questions. I feel like I'm overlooking something stupid.
06-13-2023 05:10 PM - edited 06-13-2023 05:12 PM
Hi
If you can ping from the server to the internet but can not ping the server from the router, I only can think about firewall rule.
Seems everything is in place about the network side. Can only imagine rules missing
I looked I believe all the information and all seems right to me.
If you change the route ip route 72.72.72.44 255.255.255.255 72.72.72.52 does the router can ping?
06-15-2023 06:58 AM
Yes, when I switch the routes and gateway back, I can ping. I am going to test further during a maintenance window over the weekend.
06-23-2023 01:33 PM
The NAT configuration had 'any' defined for the source interface instead of just 'inside'. Once I corrected that, the issue was resolved.
06-23-2023 02:05 PM
Good to know.
Honestly in any moment I thought NAT was in place. Always considered routing only
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide