I have an ASA 5510. Inside interface is 10.30.0.1, connects to a 3750. The 3750 does all the vlans and inter-vlan routing.
User network is in 10.1.0.0/24, web servers in 10.2.0.0.
The web servers in 10.2.0.0/24 have static nats to 1.1.1.x and proper access list rules to allow access to the external ip, port 80 from the outside interface.
There is a global nat for 10.1.0.0/24 to 1.1.1.2.
I can access http;//10.2.0.10 from the user network,since that goes directly through the switch, but which is the external nat for 10.2.0.10 does not work.
I am trying to avoid having to re-do a bunch of local dns changes, which is the only other option i see.
Am I missing some sort of nat translation that maps the external nat'd address back to the inside network?
User network is in 10.1.0.0/24, web servers in 10.2.0.0.
The web servers in 10.2.0.0/24 have static nats to 1.1.1.x and proper access list rules to allow access to the external ip, port 80 from the outside interface.
There is a global nat for 10.1.0.0/24 to 1.1.1.2.
I can access http;//10.2.0.10 from the user network,since that goes directly through the switch, but which is the external nat for 10.2.0.10 does not work.
I am trying to avoid having to re-do a bunch of local dns changes, which is the only other option i see.
Am I missing some sort of nat translation that maps the external nat'd address back to the inside network?