Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- From http://tinyurl.com/cqt7fx8
- ( http://www.experts-exchange.com/Security/Software_Firewalls/Enterprise_Firewalls/Cisco_PIX_Firewall/Q_26166375.html )
- Question
- Cisco ASA 5510 - multiple IPs on outside interface
- Asked by: francoisxi
- Hi folks,
- Currently have a single static on an ASA 5510, but am upgrading to a block of 5. How does one go about assigning a range of said static IP to the firewall? Is it as replacing the single with the range on the outside interface in the configuration? just want to make sure before I do anything.
- Thanks in advance
- Francis
- by: rharland2009Posted on 2010-05-06 at 12:26:23ID: 32656577
- You don't have to assign all five addresses to the interface. Those other addresses are for you to use for public-to-private mappings, DMZ boxes, or other devices you want on the public side of your ASA.
- by: mushkovPosted on 2010-05-06 at 12:33:05ID: 32656618
- rharland is correct. You can use the other static addresses to NAT to various hosts in your network by issuing the following command:
- static (<inside interface name>,<outside interface name>) <public IP address> <private IP address> netmask 255.255.255.255
- So if you had a public IP of 99.99.99.99 and a private IP of a hosts of 10.10.10.10, and your interface names are OUTSIDE and INSIDE, you would issue:
- static (INSIDE,OUTSIDE) 99.99.99.99 10.10.10.10 netmask 255.255.255.255
- Note that this would only affect incoming requests to 99.99.99.99. Outgoing NAT would depend on your global statement.
- For more information see: http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008046f31a.shtml
- by: 172pilotStevePosted on 2010-05-07 at 05:38:48ID: 32661439
- In my experience, just specifying the NAT commands wont work on the ASA..
- For me, before it would work, I had to add static arp entries for the other outside IPs, so that it would know to respond:
- arp outside IP2 001b.d594.f622 alias
- arp outside IP3 001b.d594.f622 alias
- arp outside IP4 001b.d594.f622 alias
- arp outside IP5 001b.d594.f622 alias
- All using the same MAC as the physical outside port, as determined by "show interface outside" as follows:
- StevesASA# sh int outside
- Interface Vlan2 "outside", is up, line protocol is up
- Hardware is EtherSVI
- MAC address 001b.d594.f622, MTU 1500
- Good luck!
- -Steve
- by: 172pilotStevePosted on 2010-05-07 at 05:40:23ID: 32661460
- By the way - IP2 through IP5 are just names in my config, and could just as easily have been the actual IP addresses, but I did this:
- name xxx.xxx.162.73 IP1 description External addr 1
- name xxx.xxx.162.74 IP2
- name xxx.xxx.162.75 IP3
- name xxx.xxx.162.76 IP4
- name xxx.xxx.162.77 IP5
- by: francoisxiPosted on 2010-05-08 at 11:42:53ID: 32669816
- Added the static nat route as defined, and then was able to assign firewall access rules and everything works!
Add Comment
Please, Sign In to add comment