Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

WMZ help

Here is what im trying to do. I have a Web server on the DMZ and this is what I?m looking to do.

A. Allow DMZ Web server to communicate with my SQL on the internal network using port 1433

B. Allow my SUS server on the DMZ to have internet access so that it will collect security updates and push this updates out to my Web Server on the DMZ. SUS server will be off most of the time. The only time this server will be turn on is when collecting updates.

Below is the diagram and my configuration. Can you please help me out with the configuration?

2 REPLIES
Green

Re: WMZ help

A. This part looks fine. You have allowed the access in the acl and also have defined a static for the communication between the two networks.

B. What is the address of the SUS server? (if it's in the diagram I don't have visio right now). You could just do...

nat (dmz) 1 0 0

Re: WMZ help

is this your SQL server 192.168.0.12 inside? if so there is already a rule 172.16.128.5-WebServer DMZ 1433 looks ok.

for SUS server-172.16.128.6 DMZ access to internet syntax as:

nat (DMZ) 1 172.16.128.6 255.255.255.255 0 0

HTH

Jorge

142
Views
0
Helpful
2
Replies
CreatePlease to create content