<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dmz to outside access issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675647#M1023031</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list on the DMZ as Adam suggested is the way to go. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For reference Pix v6.x does not support outbound access-lists but pix v7.0 does. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Mar 2007 19:02:45 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-03-16T19:02:45Z</dc:date>
    <item>
      <title>dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675641#M1023018</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a problem where I want to open up access to  servers in my DMZ to get outside while not giving the servers access to the inside (except in restricted situations)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example say I wanted to give full access to a server in the DMZ to reach the outside.  I might make the following rule...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static  (dmz,outside) x.x.x.x y.y.y.y netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list dmz permit ip any any&lt;/P&gt;&lt;P&gt;access-group in interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem with this is that the ?permit any any? will also grant access to the inside of my network as well.  Is there a way to make this work? I?ve been searching for a while and feel I?ve got a good grasp on how this all fits together, but have been unable to find the answer yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An example as to why I might want to do this is to have my servers in the DMZ get automatic windows updates.  In that case they would need to be able to make connections to Microsoft on their own.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX is Ver6.3(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675641#M1023018</guid>
      <dc:creator>jspringfield</dc:creator>
      <dc:date>2019-03-11T09:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675642#M1023019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to write the acl in the proper order. Allow what you want to allow to inside, deny everything else inside, then allow everything else. Make sense?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz permit tcp any &lt;INSIDE_NETWORK&gt; eq ???&lt;/INSIDE_NETWORK&gt;&lt;/P&gt;&lt;P&gt;access-list dmz deny ip any &lt;INSIDE_NETWORK&gt;&lt;/INSIDE_NETWORK&gt;&lt;/P&gt;&lt;P&gt;access-list dmz permit ip any any&lt;/P&gt;&lt;P&gt;access-group dmz in interface dmz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 18:47:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675642#M1023019</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-16T18:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675643#M1023022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right. Funny thing was I just sat back a sec and then drew a picture of what I wanted to do and came up with that answer as well.  Thanks for the reply acomiskey.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 18:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675643#M1023022</guid>
      <dc:creator>jspringfield</dc:creator>
      <dc:date>2007-03-16T18:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675644#M1023024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or, if you wanted to leave the ip any any you could create an acl "out interface inside" with the same process, but I like it better the other way. Now that you've got the concept down, you're good to go. Please rate if it helped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 18:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675644#M1023024</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-16T18:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675645#M1023026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was wondering if you could apply access-lists in the outboud direction on pix's.  I think your first answer works better because it blocks traffic at the source.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 18:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675645#M1023026</guid>
      <dc:creator>jspringfield</dc:creator>
      <dc:date>2007-03-16T18:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675646#M1023029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is absolutely better, just thought it might help explain the concept a little more.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 18:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675646#M1023029</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-16T18:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675647#M1023031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list on the DMZ as Adam suggested is the way to go. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For reference Pix v6.x does not support outbound access-lists but pix v7.0 does. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 19:02:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675647#M1023031</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-16T19:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: dmz to outside access issues</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675648#M1023033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;^ oops, thanks jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 19:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-outside-access-issues/m-p/675648#M1023033</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-16T19:04:32Z</dc:date>
    </item>
  </channel>
</rss>

