Re: [fw-wiz] PIX 520 - control traffic between DMZ and inside devices

From: Miha Vitorovic (miha@nil.si)
Date: 12/17/02


To: "Eye Am" <eyeam@optonline.net>
From: "Miha Vitorovic" <miha@nil.si>
Date: Tue Dec 17 08:17:43 2002

Hi,

It is hard to tell you, what is wrong w/o seeing the config, but:

>Hers's my quandry: The webserver also needs to be limited to port 1433,
TCP
>and UDP, to a specific MSSQL server on the inside and all traffic may
flow
>on all ports to another computer on the inside. How do I control traffic
>between DMZ and inside devices?

To get to inside from DMZ you will need,

- static mappings of the inside devices (may be set to something like
"static (inside,DMZ) <translated address [global]> <inside address
[local]> netmask 255.255.255.255" if you need an entire [range of]
network[s])
- set the appropriate ACLs on the DMZ interface
- Set the routes for the inside networks (the ones that are not directly
connected to the inside interface).

set appropriate fixups if needed
clear xlat
hope for the best ;-)

---
  Miha Vitorovic
  Inženir v tehničnem področju
  Customer Support Engineer
   NIL Data Communications,  Einspielerjeva 6,  1000 Ljubljana,  Slovenia
   Phone +386 1 4746 500      Fax +386 1 4746 501     http://www.NIL.si


Relevant Pages

  • Re: Trihomed DMZ just doesnt work
    ... To be succsessful with tri-homed ISA configuration you should follow the ... You should assign your DMZ interface the IP address from the block of IPs ... And what we've got here with your configuration... ...
    (microsoft.public.isa)
  • Re: Help with creating DMZ on PIX 515E
    ... internal webserver that's connected to DMZ Interface 192.168.0.1. ... DMZ interface if you intend to initiate traffic from the DMZ to the ...
    (comp.dcom.sys.cisco)
  • Re: Linksys hacking?
    ... > forwards packets with that destination to the address of the DMZ. ... > confirmed this on a BEFSR41 running 1.40.2 firmware by running an nmap ... Packets destined for port 80/udp, ...
    (comp.security.firewalls)
  • Re: [fw-wiz] PIX access-list help
    ... inside & DMZ interfaces. ... I'm a little befuddled with PIX access lists and need some help and ... dmz interface and this is where the problems start. ... inside mail server I no longer have communication to the internet from ...
    (Firewall-Wizards)
  • PIX 515 Inbound/Outbound access list confusion
    ... These are NATed to the INSIDE and the DMZ ... OUTSIDE to INSIDE allow SMTP and HTTPS ... I decided to only have 2 access lists. ... This access list was applied to the DMZ interface ...
    (comp.dcom.sys.cisco)