DMZ network to internal network

Unanswered Question

I have read several posts on this and I still don't quite understand what needs to happen. I have a web server in the dmz ( that needs to access a SQL server on the internal network ( How do I allow this access. I currently can access the DMZ from any computer on the internal network. I have attached a sanitized copy of my config so you can see what I am doing.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
sundar.palaniappan Wed, 10/10/2007 - 18:59
User Badges:
  • Green, 3000 points or more

static (inside,DMZ) netmask

access-list DMZ_access_in extended permit ip host host

access-group DMZ_access_in in interface DMZ

In addition make sure the firewall has a route to via the Inside interface. I have assumed you aren't using this address on the DMZ if you are then substitute that address in the static and ACL.



sundar.palaniappan Wed, 10/10/2007 - 19:09
User Badges:
  • Green, 3000 points or more

oops there was a typo in the IP in my last post. Here's the correct syntax.

static (inside,DMZ) netmask


This Discussion