Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PIX - Help routing from one DMZ to another

I have 2 DMZ's one has web servers on (DMZ1) it and the other is where all our regional networks come into (DMZ2). If I just base it on one regional network, I am just wondering what I need to first look at, I take it the PIX will do allthe routing?

5 REPLIES
New Member

Re: PIX - Help routing from one DMZ to another

If you are talking about routing between two different security zones (dmz1 and dmz2), pix will handle that.

New Member

Re: PIX - Help routing from one DMZ to another

Yeah, I can't get users on the DMZ2 to conenct to the DMZ1 servers. However the LAN users (were the PIX is based) can.

New Member

Re: PIX - Help routing from one DMZ to another

I hope you have rules setup correctly to let this traffic flow.

Thanks.

New Member

Re: PIX - Help routing from one DMZ to another

Remember that the PIX allows by default any sessions or data flows to pass from a higher security interface to a lower security interface without restrictions, but if you want to be able to communicate from a lower security interface to a higher security interface that needs to be configured. Also, the PIX is only aware of directly connected networks, if you have other networks behind what is directly connected to an interface you need route statements. Example:

route inside_edu 10.0.0.0 255.0.0.0 10.124.0.1

New Member

Re: PIX - Help routing from one DMZ to another

Hi,

When you are accessing network at higher security interface of a PIX from lower security interface you need access-lists setup to allow the access.

If DMZ1 is at a higher security level than DMZ2 thn you need a access-list applied to DMZ2 interface allowing traffic out to dmz1.

Hope this helps

103
Views
0
Helpful
5
Replies
CreatePlease login to create content