<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configuring DMZ host to access LAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346559#M1032332</link>
    <description>&lt;P&gt;Kindly share but do remember to remove sensitive information&lt;/P&gt;</description>
    <pubDate>Mon, 12 Mar 2018 08:42:55 GMT</pubDate>
    <dc:creator>adedipeopeoluwa</dc:creator>
    <dc:date>2018-03-12T08:42:55Z</dc:date>
    <item>
      <title>configuring DMZ host to access LAN</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346536#M1032329</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;i have ASA 5525 connected to DMZ server cisco2960 and core switch 4500 series(VSS configured on it) and i connected asa5525 with the core switch using port channel and i want the dmz network to access the internal core side network and vice versa so what should i do ?&lt;/P&gt;
&lt;P&gt;Internal network 172.20.x.x&lt;/P&gt;
&lt;P&gt;Dmz Network 192.168.x.x&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346536#M1032329</guid>
      <dc:creator>henokk601</dc:creator>
      <dc:date>2020-02-21T15:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: configuring DMZ host to access LAN</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346541#M1032330</link>
      <description>&lt;P&gt;Create an acl statement on the firewall to permit inside ip address to reach the dmz and vice versa.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;e.g&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DMZ&amp;nbsp;interface : access-group dmz_access_in in interface DMZ&lt;/P&gt;
&lt;P&gt;Inside interface:&amp;nbsp;access-group inside_access_in in interface&amp;nbsp;Inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp&amp;nbsp; 172.20.*.* 255.255.0.0 192.168.*.* 2555.255.0.0&lt;/P&gt;
&lt;P&gt;access-list dmz_access_in&amp;nbsp;&lt;SPAN&gt;extended permit tcp&amp;nbsp; 192.168.*.* 2555.255.0.0 172.20.*.* 255.255.0.0 192.168.*.* 2555.255.0.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;core switch 4500&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Create a route for the internal network to reach the dmz ip through the gateway btw the firewall and your core switch.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Though i think it is better you have specific servers on the inside network&amp;nbsp;you want specific servers on the dmz&amp;nbsp; to communicate with.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In this case, you can create an object group and grant permissions based on these object group.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 08:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346541#M1032330</guid>
      <dc:creator>adedipeopeoluwa</dc:creator>
      <dc:date>2018-03-12T08:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: configuring DMZ host to access LAN</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346554#M1032331</link>
      <description>can i share you the configuration i do the same however it won't work&lt;BR /&gt;</description>
      <pubDate>Mon, 12 Mar 2018 08:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346554#M1032331</guid>
      <dc:creator>henokk601</dc:creator>
      <dc:date>2018-03-12T08:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: configuring DMZ host to access LAN</title>
      <link>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346559#M1032332</link>
      <description>&lt;P&gt;Kindly share but do remember to remove sensitive information&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 08:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-dmz-host-to-access-lan/m-p/3346559#M1032332</guid>
      <dc:creator>adedipeopeoluwa</dc:creator>
      <dc:date>2018-03-12T08:42:55Z</dc:date>
    </item>
  </channel>
</rss>

