Hi,
I've got my ASA set with STATICs to allow hosts on the DMZ to translated to addresses on the outside, so DMZ hosts are now accessable from the internet - ACL set allowing access from ANY - works fine. No problem here.
So now what I have is a web server for example on the outside that is accessable to the world.
Inside hosts on the lan however can't access anything on the OUTSIDE interface despite the outside is configured for ANY.
Just to clarify, what is happening is that a host on the INSIDE is trying to access a DMZ host that has a translation on to the OUTSIDE interface - the INSIDE host is attempting to access via an OUTSIDE address on the OUTSIDE interface - which doesn't work - can't even PING the OUTSIDE host address.
However, from another device on the internet (i.e. the source is from the OUTSIDE/INTERNET), access to the hosts is all fine and works well - the only clients who can't access our outside hosts are us!!
Clients on the inside can access anything they like on the internet - I've allowed access for all with no ACLs blocking anything traffic leaving the INSIDE.
Hellllppppp!!!
Thanks in advance
Phil B
I've got my ASA set with STATICs to allow hosts on the DMZ to translated to addresses on the outside, so DMZ hosts are now accessable from the internet - ACL set allowing access from ANY - works fine. No problem here.
So now what I have is a web server for example on the outside that is accessable to the world.
Inside hosts on the lan however can't access anything on the OUTSIDE interface despite the outside is configured for ANY.
Just to clarify, what is happening is that a host on the INSIDE is trying to access a DMZ host that has a translation on to the OUTSIDE interface - the INSIDE host is attempting to access via an OUTSIDE address on the OUTSIDE interface - which doesn't work - can't even PING the OUTSIDE host address.
However, from another device on the internet (i.e. the source is from the OUTSIDE/INTERNET), access to the hosts is all fine and works well - the only clients who can't access our outside hosts are us!!
Clients on the inside can access anything they like on the internet - I've allowed access for all with no ACLs blocking anything traffic leaving the INSIDE.
Hellllppppp!!!
Thanks in advance
Phil B