I have a cisco 520 pix firewall and have the inside, outside and dmz working well. The INSIDE was addded recently and now, I want the inside and dmz zones to communicate with each other. IS this possible. If then how?
can anyone help me out with some links or their own solutions?
Yes, this will definitely work. For simplicity purpose lets have an example:
Inside : 10.1.1.0/24 network inside interface of pix: 10.1.1.1
dmz: 172.16.171.0/24 network dmz interface of pix: 172.16.171.1
For connection from inside to dmz:
nat (inside) 1 10.1.1.0
global (dmz) 1 interface
If you have acl appalied on inside interface, pl. make sure to allow the traffic from iunside to dmz. Also, if you have an existing nat for the outside, then you may apply the same nat to the dmz interface.
For connection from dmz to inside:
static (inside, dmz) 10.1.1.50 10.1.1.50 (lets say web server has ip 10.1.1.50)
access-list 102 permit tcp any host 10.1.1.50 permit 80
access-group dmz in
Note: if you want to allow the communication from dmz to inside, the whole network then you can define " static (inside, dmz) 10.1.1.0 10.1.1.0), in that case, you will not need the nat/global for the inside to outside communication.
Once you define static, you will not need anyting else. If you define nat (inside) 0 ACL then, this will superce static and will perform the same job. So, either of this two options will work for you. So, define either static or nat 0 ACL.
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...