Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

dmz tunneled over WAN

Hi all, if I have a firewall on my central site, but want to host the DMZ on another site, would it be possible to get this across a wan link etc? would the only option be to bridge?

cheers

Carl

4 REPLIES
New Member

Re: dmz tunneled over WAN

If you did it this way you would be best with a LES link to a DMZ switch on the other site. It would be bridged, but you would need your Gateway out to the internet or the untrusted Network on the Remote site also.

New Member

Re: dmz tunneled over WAN

Are there any other options than this ?

New Member

Re: dmz tunneled over WAN

Carl,

You could actually do this with the Gateway on the same site as the firewall. On the outside interface of the firewall you could have a switch and then bridge to another switch on the remote site. Total of 2 switches in the DMZ.

If it's not possible to bridge between sites then you would need routed links and you would just have to NAT to remote site.

I am presuming you have servers on remote site which you cannot move to your firewall DMZ?

New Member

Re: dmz tunneled over WAN

A quick diagram of how I would do it, we do this a lot in our organistion.

120
Views
0
Helpful
4
Replies
CreatePlease to create content