cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
543
Views
0
Helpful
2
Replies

help in confgure cisco asa 5540

CSCO11825412
Level 1
Level 1

hello

my senaro

lan 192.168.1.0/24

have exchange server 2010

tmg 2010

sharpoint 2010

DMZ

----

OUTSIDE

IP ADDRESS XX.XX.XX.XX/30

i need to configure asa 5540 to best secure

i want to puplish owa and sharpoint in dmz

some rule to block weak securty on lan

CAN ANY ONE HELP ME IN THIS

1 Accepted Solution

Accepted Solutions

llamaw0rksE
Level 1
Level 1

You have one public IP address from your provider.   

You have an internal private LAN structure of 192.168.1.0

You have three services you wish to place on the DMZ.

Assume you want access from lan to dmz but NOT dmz to lan.

We need to know which firmware version using.

__________________________________________________________________________

Basic concepts:

(1) Need to create a DMZ VLAN (give it a lower security than LAN VLAN ie  (50)

Automatically this will create implicity DENY DMZ to LAN ACL rules blocking traffic unless you create ACL rules allowing traffic.

(2) Need routing rule for both DMZ and LAN to the internet.

(3) Need dynamic pat rule for users on lan and dmz to be able to use internet connection (assuming users are allowed)

(4) Need static Nat rules for servers (port forwarding, so users on the external internet can reach the sever on the dmz)

(5) Not sure..... but probably a nat rule for lan users to reach servers on DMZ (hopefully others can clarify _ I would assume being behind the router not necessary but probably wrong).

(6)  ACL rules to narrow down which services external users can access and even better which users are allowed access to servers

View solution in original post

2 Replies 2

Amit Rai
Level 1
Level 1

Please provide a clear problem description with network diagram so that we can help you with this

llamaw0rksE
Level 1
Level 1

You have one public IP address from your provider.   

You have an internal private LAN structure of 192.168.1.0

You have three services you wish to place on the DMZ.

Assume you want access from lan to dmz but NOT dmz to lan.

We need to know which firmware version using.

__________________________________________________________________________

Basic concepts:

(1) Need to create a DMZ VLAN (give it a lower security than LAN VLAN ie  (50)

Automatically this will create implicity DENY DMZ to LAN ACL rules blocking traffic unless you create ACL rules allowing traffic.

(2) Need routing rule for both DMZ and LAN to the internet.

(3) Need dynamic pat rule for users on lan and dmz to be able to use internet connection (assuming users are allowed)

(4) Need static Nat rules for servers (port forwarding, so users on the external internet can reach the sever on the dmz)

(5) Not sure..... but probably a nat rule for lan users to reach servers on DMZ (hopefully others can clarify _ I would assume being behind the router not necessary but probably wrong).

(6)  ACL rules to narrow down which services external users can access and even better which users are allowed access to servers

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card