11-17-2006 04:08 AM - edited 03-05-2019 12:52 PM
By default on a pix, can anything inside access anything on a dmz connection ?
11-17-2006 05:02 AM
by default any request initiated from inside will be allowed. PIX will inspect each packet and will allow to go out.
11-17-2006 05:10 AM
Hi Carl,
By default traffic from inside interface of the PIX to the DMZ is allowed but the returning traffic from the DMZ to the inside interface is not allowed. In order to have a communication you need bi-directional traffic.
Inside interface is the most secured zone on the PIX so when you are going from DMZ to inside interface you have to use NAT or Self Static from inside to DMZ interface. You alos have to use ACl's to allow traffic from DMZ to inside interface.
HTH, Please rate if it does.
-amit singh
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: