Hi,
Currently I have a DMZ interface, and a LAN interface which is on
192.168.1.0.I have the following command in the firewall to allow traffic to flow between the DMZ and inside interface without NAT:
static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
Now, I have some other subnets on the inside network, and I want to observe the no NAT with those as well for traffic on the DMZ. I could list out all the networks, or use a larger subnet mask, but my question is: Is this the best way of doing this?
Thanks. Andrew.