<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic DMZ question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837802#M1100497</link>
    <description>&lt;P&gt;only make the ACL&amp;nbsp; traffic to DMZ above other ACL line, then put the ACL traffic to IN below DMZ.&amp;nbsp;&lt;BR /&gt;it only which one come first.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;NOTE:- I check your config I dont see any access-group, what I see is ACL of S2S VPN&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2023 17:06:43 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-05-17T17:06:43Z</dc:date>
    <item>
      <title>Basic DMZ question</title>
      <link>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837703#M1100483</link>
      <description>&lt;P&gt;I have a 5515 and am trying to setup a dmz.&amp;nbsp; I guess my question is pretty basic.&amp;nbsp; I have the firewall setup basic outside and inside.&amp;nbsp; I have an access list and an access group in interface outside.&amp;nbsp; If the dmz port is also supposed to be attached to the in interface outside access group how do I split my traffic to go to the dmz or inside? Do I just use the same access list I already have going into the internal network?&lt;/P&gt;&lt;P&gt;ge0/0 is 184.177.71.146 255.255.255.248&lt;/P&gt;&lt;P&gt;ge0/1 is 192.9.200.7 255.255.240.0&lt;/P&gt;&lt;P&gt;ge0/2 would be 192.9.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;thank you in advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 13:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837703#M1100483</guid>
      <dc:creator>jbrister</dc:creator>
      <dc:date>2023-05-17T13:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Basic DMZ question</title>
      <link>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837709#M1100484</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you have an interface nameif dmz, you need to create ACL for this interface the same way you do for Inside and Outside.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-group xxx &amp;lt;in/out&amp;gt; interface dmz&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 13:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837709#M1100484</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-05-17T13:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: Basic DMZ question</title>
      <link>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837712#M1100485</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1514590"&gt;@jbrister&lt;/a&gt; to explictly allow traffic inbound from outside to DMZ or Inside you would permit traffic on the ACL inbound on the outside interface.&lt;/P&gt;
&lt;P&gt;To control traffic from DMZ to outside, this would be permitted as default (without an ACL) if the security-level of the DMZ interface is higher than the outside interface. Ideally though you would restrict outbound access from DMZ to outside with an ACL on inbound on the DMZ interface. You must configure an ACL inbound on the DMZ interface to permit traffic from DMZ to the inside interface.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 13:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837712#M1100485</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-17T13:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Basic DMZ question</title>
      <link>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837802#M1100497</link>
      <description>&lt;P&gt;only make the ACL&amp;nbsp; traffic to DMZ above other ACL line, then put the ACL traffic to IN below DMZ.&amp;nbsp;&lt;BR /&gt;it only which one come first.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;NOTE:- I check your config I dont see any access-group, what I see is ACL of S2S VPN&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 17:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-dmz-question/m-p/4837802#M1100497</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-17T17:06:43Z</dc:date>
    </item>
  </channel>
</rss>

