We are in process of upgrading from an ASA5505 to an ASA5510. I have a co-location configured for 3 ranges of public IP addresses on two different subnets. The 5505 is working as expected.
Example (modified IPs): 174.136.1.1, 72.249.1.1, 72.249.2.1
The firewall is assigned to 174.136.1.2. When bringing the 5510 online, traffic does not route correctly when NAT rules are created for any IP addresses in this range: 72.249.1.1, 72.249.2.1
- I confirmed the data packets route correctly when assigning a server to an IP that is on the same subnet as the firewall.
- When configuring additional VLANs for IP ranges 72.249.1.1 and 72.249.2.1, all packets route correctly. I put a switch between the Firewall and Datacenter router. However we do not have enough IPs to assign to additional VLANS.
- I tried to create a static route to 72.249.1.1, 72.249.2.1, that didn't work.
- Packet trace results were a positive but I am not sure if I am doing it correctly.
- I do see a Dynamic NAT rule on the 5505 vs Dynamic PAT rule on the 5510. I am unclear what the difference is. I think I have tried to toggle that on the 5510 with no luck.
- I am researching subinterfaces on the 5510 but I'm not sure if that is the solution.
We have a small window to do the firewall upgrade and that is typically late night. I've tried multiple times with no luck. I can't create a test bed environment at the office. I may request another drop from the datacenter for testing purposes. Any help would be appreciated. I can post the full config.