<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dmz to inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629400#M1028887</link>
    <description>&lt;P&gt;Added 4 port ethernet on a Pix 515e, ver: 6.3&lt;/P&gt;&lt;P&gt;So I have the following: &lt;/P&gt;&lt;P&gt;ip address outside 63.209.xxx.xx 255.255.255.192&lt;/P&gt;&lt;P&gt;ip address inside 172.16.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz 192.168.121.4 255.255.255.0&lt;/P&gt;&lt;P&gt;From a web server on the dmz interface I'm unable to ping inside hosts. Although from inside I can ping the dmz web server. Show icmp:&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any echo dmz&lt;/P&gt;&lt;P&gt;What am I missing. Thanks.  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:19:47 GMT</pubDate>
    <dc:creator>dhengste7</dc:creator>
    <dc:date>2019-03-11T09:19:47Z</dc:date>
    <item>
      <title>Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629400#M1028887</link>
      <description>&lt;P&gt;Added 4 port ethernet on a Pix 515e, ver: 6.3&lt;/P&gt;&lt;P&gt;So I have the following: &lt;/P&gt;&lt;P&gt;ip address outside 63.209.xxx.xx 255.255.255.192&lt;/P&gt;&lt;P&gt;ip address inside 172.16.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz 192.168.121.4 255.255.255.0&lt;/P&gt;&lt;P&gt;From a web server on the dmz interface I'm unable to ping inside hosts. Although from inside I can ping the dmz web server. Show icmp:&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any echo dmz&lt;/P&gt;&lt;P&gt;What am I missing. Thanks.  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629400#M1028887</guid>
      <dc:creator>dhengste7</dc:creator>
      <dc:date>2019-03-11T09:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629401#M1028888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To go from a lower security interface to a higher one, you need NAT translations. For example &lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.16.x.x 172.16.x.x netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will also need an ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_access permit icmp any any&lt;/P&gt;&lt;P&gt;access-group dmz_access in interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This example is NOT secure-- only allow access to what is needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH and please rate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 22:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629401#M1028888</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-15T22:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629402#M1028889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's what I have in place: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.0.0.0 172.0.0.0 netmask 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;access-group dmz_access_in in interface dmz&lt;/P&gt;&lt;P&gt;access-list dmz_access_in line 1 permit icmp any any (hitcnt=845)&lt;/P&gt;&lt;P&gt;access-list dmz_access_in line 2 permit tcp host 192.168.121.34 host 172.16.x.x eq 1433 (hitcnt=0)&lt;/P&gt;&lt;P&gt;Goal is to be able to communicate with a sql server on the inside. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 16:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629402#M1028889</guid>
      <dc:creator>dhengste7</dc:creator>
      <dc:date>2007-01-16T16:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629403#M1028890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you want to put 172.0.0.0/24 in your static (inside,dmz)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a 172.0.0.0/24 network inside?&lt;/P&gt;&lt;P&gt;If not, it should be&lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.0.0.0 172.0.0.0 netmask 255.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.16.x.0 172.16.x.0 netmask 255.255.255.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 16:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629403#M1028890</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-01-16T16:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629404#M1028891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I have a 172.0.0.0/24 on the inside interface. &lt;/P&gt;&lt;P&gt;My issue is unable to communicate with the inside from the dmz web server. With what I posted above how would I proceed? thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 19:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629404#M1028891</guid>
      <dc:creator>dhengste7</dc:creator>
      <dc:date>2007-01-16T19:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629405#M1028892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But the host on the inside you want to hit on 1433 is not part of 172.0.0.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to add another static (inside,dmz) for the 172.16.x.0 network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 20:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629405#M1028892</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-01-16T20:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629406#M1028893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have: &lt;/P&gt;&lt;P&gt;static (inside,dmz) tcp interface 1433 172.16.3.3 1433 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still having a problem connecting to a sql server on the inside. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2007 21:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629406#M1028893</guid>
      <dc:creator>dhengste7</dc:creator>
      <dc:date>2007-01-24T21:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629407#M1028894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried the suggested above? I don't think you want what you just posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can watch the logs you are probably getting "No translation group found". If 172.16.3.3 is you sql server, then add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.16.3.3 172.16.3.3 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post a sanitized config if you can.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2007 21:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629407#M1028894</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-01-24T21:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629408#M1028895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Watching the log, but not getting the "no translation error". Attached is the config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2007 18:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629408#M1028895</guid>
      <dc:creator>dhengste7</dc:creator>
      <dc:date>2007-01-25T18:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629409#M1028896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/mailserver.html" target="_blank"&gt;http://www.cisco.com/warp/public/110/mailserver.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pay close attention to the following line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 10.1.1.0 10.1.1.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need one except yours would be &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.16.3.0 172.16.3.0 netmask 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow anything on 172.16.3.0/24 network to communicate with dmz server and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also don't know what this line is supposed to do static (inside,dmz) tcp interface 1433 172.16.3.3 1433 netmask 255.255.255.255 0 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may have to "clear xlate" after the command is added. Just be aware of that. Also make sure your sql is running on 1433.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone correct me if I'm wrong here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2007 19:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629409#M1028896</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-01-25T19:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629410#M1028897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I removed: &lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.16.3.3 172.16.3.3 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;Added:&lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.16.3.0 172.16.3.0 netmask 255.255.255.0 0 0 &lt;/P&gt;&lt;P&gt;Right now would be happy just to ping from inside to dmz. Have the acl: &lt;/P&gt;&lt;P&gt;access-list dmz_access permit icmp any any &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 19:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629410#M1028897</guid>
      <dc:creator>dhengste7</dc:creator>
      <dc:date>2007-02-20T19:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629411#M1028898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As long as you are coming from inside 172.16.3.x you should be fine. Did you apply that acl with access-group dmz_access in interface dmz?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 19:53:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629411#M1028898</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-02-20T19:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629412#M1028899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, coming from 172.16.3.x and have the acl:&lt;/P&gt;&lt;P&gt;access-group dmz_access in interface dmz &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 19:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629412#M1028899</guid>
      <dc:creator>dhengste7</dc:creator>
      <dc:date>2007-02-20T19:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Dmz to inside</title>
      <link>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629413#M1028900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get rid of this line &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) tcp interface 1433 172.16.3.3 1433 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Might as well post current config and start logging.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 20:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-to-inside/m-p/629413#M1028900</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-02-20T20:04:34Z</dc:date>
    </item>
  </channel>
</rss>

