<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Client w/ a DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-client-w-a-dmz/m-p/745045#M1054181</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot just add the acl line to the existing nat exemption acl because the nat statement is nat ("inside") 0, not DMZ. The best thing to do is to create a second acl for the dmz nat exemption&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_nat0_outbound permit ip &lt;DMZ_NETWORK&gt; &lt;MASK&gt; &lt;VPNCLIENT_NETWORK&gt; &lt;MASK&gt;&lt;/MASK&gt;&lt;/VPNCLIENT_NETWORK&gt;&lt;/MASK&gt;&lt;/DMZ_NETWORK&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list dmz_nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Apr 2007 19:37:43 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-04-16T19:37:43Z</dc:date>
    <item>
      <title>VPN Client w/ a DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-w-a-dmz/m-p/745044#M1054174</link>
      <description>&lt;P&gt;I have a PIX 515 with 3 interfaces (inside,outsize,dmz)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When connecting using the Cisco Client VPN, I can access the inside no problem, however, I cannot access anything on the DMZ.  I added the NAT 0 ACL line to include DMZ_network and the VPN_CLIENT_POOL network.  I also added the split-tunnel respectively with no success.  Any clues what to check?  I connect to the PIX w/ the client and try to ping an IP and looking at the NAT 0 ACL, I don't see any hits on that line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-w-a-dmz/m-p/745044#M1054174</guid>
      <dc:creator>jfinley</dc:creator>
      <dc:date>2020-02-21T09:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client w/ a DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-w-a-dmz/m-p/745045#M1054181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot just add the acl line to the existing nat exemption acl because the nat statement is nat ("inside") 0, not DMZ. The best thing to do is to create a second acl for the dmz nat exemption&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_nat0_outbound permit ip &lt;DMZ_NETWORK&gt; &lt;MASK&gt; &lt;VPNCLIENT_NETWORK&gt; &lt;MASK&gt;&lt;/MASK&gt;&lt;/VPNCLIENT_NETWORK&gt;&lt;/MASK&gt;&lt;/DMZ_NETWORK&gt;&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list dmz_nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2007 19:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-w-a-dmz/m-p/745045#M1054181</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-04-16T19:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client w/ a DMZ</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-w-a-dmz/m-p/745046#M1054184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DOH!  You're right.  I sat there for like 20-30 minutes knowing I was overlooking something and as soon as I read  "nat('inside') it clicked!  Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2007 19:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-w-a-dmz/m-p/745046#M1054184</guid>
      <dc:creator>jfinley</dc:creator>
      <dc:date>2007-04-16T19:52:35Z</dc:date>
    </item>
  </channel>
</rss>

