Ubuntu Server behind NAT (Help)

Tarrant64

Diamond Member
Sep 20, 2004
3,203
0
76
Trying to get an Ubuntu server to work behind a NAT setup. (Please move to Network Forum if necessary - I figured more Linux gurus would in this forum would be helpful).

Ubuntu 11.04 (wordpress) -> Cisco ASA 5510 (NAT to internal server) -> Internet

Firewall rules are already in place as well to allow HTTP/HTTPS and ICMP (for now just for verification it's up). I have several other NATs setup the same way to Windows web servers and have never had this problem. So I'm inclined to think it's something with the Ubuntu server.

When I set this up, I can no longer ping the outside world. Web pages do not work either. All traffic outside of the LAN ceases to work.

The second I drop the NAT from the configuration though, ping works fine and web pages come up just fine. I'm wondering what I'm missing on the Ubuntu server (assuming that's where the problem is) configuration.

eth0 on this server is a static IP and nameservers setup. DNS resolution works just fine. Ping to local domain workstations/servers works just fine.

Wondering if anyone can shed some light on this setup. Typically when I NAT a windows server it just works. Is there something different I need to do on the firewall end or am I missing something with Ubuntu. Please note, UFW (firewall) has been disabled.
 

AnonymouseUser

Diamond Member
May 14, 2003
9,943
107
106
What's the output of traceroute? Does the server have a unique IP address? Have you tried DHCP?
 

Tarrant64

Diamond Member
Sep 20, 2004
3,203
0
76
Traceroute goes to the local LAN IP first and then nothing.

Not sure how DHCP is going to help?
 

Tarrant64

Diamond Member
Sep 20, 2004
3,203
0
76
If DHCP works then your problem is with the manual config.

DHCP worked fine when the server was first setup. It could be something with the manual config I suppose. But everything works fine until NAT is enabled, so not sure why DHCP would somehow fix that.
 

Tarrant64

Diamond Member
Sep 20, 2004
3,203
0
76
Nevermind. Pretty damn sure I have what the problem is. I was given a public IP already in use by another device. Waiting for a new one and I think it all should just work now.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
There's nothing special about Linux in this case, if you can get to ports 80/443 internally then that's all you need to PAT on the ASA and that would have no affect on the ASA's ability to route other traffic unless you misconfigured the static or ACL statements.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |