alessandro.bresciani ha scritto:Ciao!
Perdonami il ritardo nella risposta!
Ma mi dai una bella notizia, per lo meno non devo fare un upgrade di licenza.
Sei proprio sicuro? Io le ho provate tutte ma non riesco proprio ad accedere
dalla LAN ai server in DMZ. Ho seguito passo passo il manuale (Quick Start) non avendo grande esperienza su questa apparati. Ma niente da fare non riesco a stabilire sessioni LAN>DMZ, neanche riesco a pingare gli host che stanno in DMZ.
Ti copio la configurazione che attualmente gira su quel asa ( e funziona

)
Spero ti possa andare bene. bb
interface Vlan1
nameif inside-uff
security-level 100
ip address 192.168.0.200 255.255.255.0
!
interface Vlan2
no forward interface Vlan1
nameif inside-lab-dmz
security-level 50
ip address 10.0.0.254 255.255.255.0
!
interface Vlan3
nameif outside
security-level 0
ip address 10.1.0.200 255.255.255.0
!
interface Ethernet0/0
!
interface Ethernet0/1
switchport access vlan 2
!
interface Ethernet0/2
switchport access vlan 3
!
interface Ethernet0/3
shutdown
!
interface Ethernet0/4
shutdown
!
interface Ethernet0/5
shutdown
!
interface Ethernet0/6
shutdown
!
interface Ethernet0/7
shutdown
!
ftp mode passive
access-list static-out extended permit tcp x 255.255.255.0 any eq 2222
access-list static-out extended permit icmp any any
access-list static-out extended permit tcp x 255.255.255.0 any eq 8002
access-list static-out extended permit tcp x 255.255.255.0 any eq 3389
access-list static-out extended permit tcp x 255.255.255.0 any eq 8002
access-list static-out extended permit tcp x 255.255.255.0 any eq ftp
access-list static-out extended permit tcp x 255.255.255.0 any eq ftp-data
access-list static-out extended permit tcp x 255.255.255.0 any eq ftp-data
access-list static-out extended permit tcp x 255.255.255.0 any eq ftp
pager lines 24
mtu inside-uff 1500
mtu inside-lab-dmz 1500
mtu outside 1500
ip verify reverse-path interface inside-uff
ip verify reverse-path interface inside-lab-dmz
ip verify reverse-path interface outside
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-621.bin
no asdm history enable
arp timeout 14400
global (inside-lab-dmz) 1 interface
global (outside) 1 interface
nat (inside-uff) 1 192.168.0.0 255.255.255.0
nat (inside-lab-dmz) 1 10.0.0.0 255.255.255.0
static (inside-lab-dmz,outside) tcp interface 2222 10.0.0.1 ssh netmask 255.255.255.255
static (inside-lab-dmz,outside) tcp interface 8002 10.0.0.210 8002 netmask 255.255.255.255
static (inside-uff,outside) tcp interface 3389 192.168.0.100 3389 netmask 255.255.255.255
static (inside-lab-dmz,outside) tcp interface ftp 10.0.0.210 ftp netmask 255.255.255.255
static (inside-lab-dmz,outside) tcp interface ftp-data 10.0.0.210 ftp-data netmask 255.255.255.255
access-group static-out in interface outside
route outside 0.0.0.0 0.0.0.0 10.1.0.250 1