I have a Cisco ASA5510 and articles related to ASA and mulitple Public IP says this cant be done. My question is how to best solve a scenario like this:
I have 3 zones, Outside, Inside and DMZ
- Outside is Internet
- Inside is Client machines
- DMZ is a zone for servers related to external and internal services.
My scenario is a bit more complex, but to keep things simple this will do:
I want to place an Exchange server and a web server (externally reachable in the DMZ zone)
The webserver uses both TCP80/443, the Exchange server uses 443
So to the problem:
With the ASA only having one public IP, how would you make a DNAT to port 443 on both the internal hosts behind 1 Public IP? Usually, when i do this kind of scenario With Linux boxes i use alias Interfaces like eth0:0, eth0:1 and set 1 Public IP on each.
To me this must be a pretty common scenario, any ideas on how to solve it With ASA?
/KGDI
Best Answer
First of all, if you truely only have one single public IP this isn't going to work trying to port forward the same port for two internal hosts.
If though you have a range of IPs, perhaps your ISP has given you a small /29 subnet, then you are in luck. If they are routing a /29 to your ASA then obviously as usual, you can only configure one IP on the outside interface but if it is receiving traffic for those additional IPs it can work with them.
(The below is an example from an ASA that gets assigned an IP over PPPoE and the ISP routes a /29 to that interface, but if for example your uplink is an Ethernet segment, ASAs can use proxy ARP).
As you haven't given the version of ASA OS you are running I can't more specific, so here is an example I have use, which is on 8.2. This is allowing RDP (port 3389) on a second public IP in the same subnet routed to the ASA, two a second internal hosts (I have included the default NAT rules etc so you can see the bigger picture).
I hope this is the correct config for you, been focusing on 8.4 as the changes they have introduced are too much for my simple brain and pre-8.4 stuff is falling out of my nose!