route outside 0.0.0.0 0.0.0.0 192.168.5.1 1
route backup 0.0.0.0 0.0.0.0 192.168.4.1 2
nat (inside) 1 0 0
nat (dmz) 1 0 0
global (outside) 1 interface
global (backup) 1 interface
static (backup,dmz) tcp 0.0.0.0 www 0.0.0.0 www netmask 0.0.0.0
static (backup,dmz) tcp 0.0.0.0 https 0.0.0.0 https netmask 0.0.0.0
static (backup,dmz) tcp 0.0.0.0 smtp 0.0.0.0 smtp netmask 0.0.0.0
access-list NO_NAT_INSIDE extended permit ip <INSIDE-LAN-IP> 255.255.255.0 <DMZ-IP> 255.255.255.0
access-list NO_NAT_DMZ extended permit ip <DMZ-IP> 255.255.255.0 <INSIDE-LAN-IP> 255.255.255.0
nat (inside) 0 access-list NO_NAT_INSIDE
nat (dmz) 0 access-list NO_NAT_DMZ
Last edited by ptran; 06-11-2011 at 10:12 PM.
Trần Nhân Hòa
CMND #0146257668