Allowing RDP into DMZ

Unanswered Question
Nov 15th, 2007
User Badges:

When I add a rule for an internal user to rdp into a server in our dmz, the implicit deny does not allow the rule. Below are the rules I currently have for traffic entering the DMZ.


access-list DMZ extended permit tcp host 172.16.110.4 any eq www

access-list DMZ extended permit tcp host 172.16.110.4 any eq https

access-list DMZ extended permit tcp host 172.16.110.4 any eq ftp

access-list DMZ extended permit tcp host 172.16.110.10 host 10.0.22.229

access-list DMZ extended permit tcp host 172.16.110.10 host 10.0.22.11 eq www

access-list DMZ extended permit tcp host ws-vwright-01 host 172.16.110.10 eq 3389

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
srue Thu, 11/15/2007 - 10:19
User Badges:
  • Blue, 1500 points or more

so that acl is applied to the dmz interface? egress or ingress?


what pix/asa OS?

is nat-control enabled?

do you have an inside/dmz nat rule for ws-vwright-01?

jgorman1977 Thu, 11/15/2007 - 10:37
User Badges:

It's an ASA5510. This is applied on the ingress side. Nat-control is enabled, but do not have a nat rule for the workstation. Not sure how to implement that.


Thanks

srue Thu, 11/15/2007 - 10:50
User Badges:
  • Blue, 1500 points or more

see if this works:


static (inside,dmz) ws-vwright-01 ws-vwright-01

jgorman1977 Thu, 11/15/2007 - 10:54
User Badges:

That was it. Thank you. Does this command just NAT his workstation to a DMZ ip address?

srue Thu, 11/15/2007 - 11:01
User Badges:
  • Blue, 1500 points or more

it nats it to itself. you could have just as easily nat'ed it to a dmz IP.


static (inside,dmz) dmz_ip ws-vwright-01

elparis Thu, 11/15/2007 - 11:07
User Badges:
  • Cisco Employee,

Dynamic NAT (or PAT) is also a possibility. For example:


nat (inside) 1 0 0

global(dmz) 1 interface


This will allow any machine on the inside (not just one) to access anything on the DMZ.

srue Thu, 11/15/2007 - 12:11
User Badges:
  • Blue, 1500 points or more

his original acl still only allows one host rdp access: ws-vwright-01

elparis Thu, 11/15/2007 - 12:28
User Badges:
  • Cisco Employee,

It doesn't matter - the ACE the original poster included is:


access-list DMZ extended permit tcp host ws-vwright-01 host 172.16.110.10 eq 3389


This ACE is not doing anything and can actually be removed - there is no 172.16.110.10 outside of the DMZ network, and since the original poster mentioned this is an ingress ACL ("access-group DMZ in interface DMZ"), this ACE will never be hit.


If the original poster wants to only allow the machine ws-vwright-01 to contact 172.16.110.10 on TCP port 3398 in the DMZ then an egress ACL on the DMZ interface or an ingress ACL on the inside interface that only allows this flow needs to be applied.


As it is right now the original poster can add the dynamic NAT statements that I mentioned and any machine on the inside will be able to RDP into 172.16.110.10, and this without changes to any ACL since traffic from high security interfaces going to lower security interfaces is allowed by default.

Actions

This Discussion