cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
968
Views
0
Helpful
2
Replies

DMZ with Single ASA 5510 Security Plus Firewall Edition

entaadmin
Level 1
Level 1

I'm working on a quick quote for a partner of ours.  I'm wondering if the Cisco ASA 5510 Security Plus Firewall Edition, is capable of doing a DMZ type configuration with just a single device, rather than an old school Internet -> Physical Firewall -> DMZ -> Physical Firewall -> Intranet.

My guess is it would be something simlar to VLAN 1 (DMZ) and VLAN 2 (Intranet).  With a NAT to VLAN1, but all traffic from outside must pass through the device, and any traffic passing from VLAN 1 to VLAN 1 must have Access Control rules.

Sorry if the question is routine, I just want to be 100% before I tell them to buy.  Here is a link to the product https://www.insight.com/search/ppp.web?fromSearch=true&materialId=ASA5510-SEC-BUN-K9

Thanks!

Cody

2 Replies 2

Kureli Sankar
Cisco Employee
Cisco Employee

With ASA5505 you will have vlans but, with ASA5510 you have enough physical interfaces to configure inside, outside and dmz.

Here is a link for ASA5510 sample config: http://www.howtocisco.com/cisco/samples/5510config1.htm

-KS

Panos Kampanakis
Cisco Employee
Cisco Employee

You can have vlan2 being the dmz, vlan1 the inside and when passing from out to dmz, or out to in have the firewall be in the middle.

Not sure if that is waht you were asking, but that is doable.

I hope it helps.

PK

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card