cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
583
Views
0
Helpful
3
Replies

ACLs and DMZ - Brain-freeze

John Blakley
VIP Alumni
VIP Alumni

All,

I'm setting up acls for the inside, dmz1, dmz2 and external.

My question is:

I have a host on the inside that needs to get to the dmz. I have an acl on the inside and I'll need to permit this host to the dmz. I'll also need to create an acl on the dmz interface that will allow the traffic back to that host, correct?

Thanks,

John

HTH, John *** Please rate all useful posts ***
1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

John

Assuming a firewall ie. a pix/asa then no because it is stateful so if you allow the traffic one way it will be allowed back in.

Note this applies to TCP/UDP. If you were using ICMP that is not stateful so pre v7.x code you had to allow it back in. v7.x code onwards you can also use ICMP inspection to achieve this.

Jon

View solution in original post

3 Replies 3

lm20ele
Level 1
Level 1

What device are you using?

Jon Marshall
Hall of Fame
Hall of Fame

John

Assuming a firewall ie. a pix/asa then no because it is stateful so if you allow the traffic one way it will be allowed back in.

Note this applies to TCP/UDP. If you were using ICMP that is not stateful so pre v7.x code you had to allow it back in. v7.x code onwards you can also use ICMP inspection to achieve this.

Jon

Thanks Jon :)

HTH, John *** Please rate all useful posts ***
Review Cisco Networking products for a $25 gift card