<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Assuming you are running 8.3+ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-zone/m-p/2430730#M268387</link>
    <description>&lt;P&gt;Assuming you are running 8.3+, you need:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;An ACL on the outside interface allowing the needed traffic (example for allowing Web-traffic to your DMZ-host with IP 1.2.3.4):&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host 1.2.3.4 eq 80&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If your NAT for internal clients is setup correctly and there is no ACL on the inside interface you are good to go. If you have an ACL on the inside, then you also need an entry to allow the traffic. That could look like the following if you want to allow all traffic from inside to the DMZ:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;access-list INSIDE-IN permit ip any 1.2.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Mar 2014 07:24:17 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2014-03-12T07:24:17Z</dc:date>
    <item>
      <title>DMZ  Zone</title>
      <link>https://community.cisco.com/t5/network-security/dmz-zone/m-p/2430729#M268383</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please&amp;nbsp; advice&amp;nbsp; the command&amp;nbsp; to&amp;nbsp; configure&amp;nbsp; a DMZ Zone&amp;nbsp; in the&amp;nbsp; cisco&amp;nbsp; Asa 5510 Firewall.&lt;/P&gt;&lt;P&gt;i have&amp;nbsp; already&amp;nbsp; inside and&amp;nbsp; outside interfaces.&amp;nbsp; All the users&amp;nbsp; need to&amp;nbsp; access the servers&amp;nbsp; in the DMZ Zone&amp;nbsp; and from&amp;nbsp; internet as well.&lt;/P&gt;&lt;P&gt;All&amp;nbsp; the servsers in the DMZ are&amp;nbsp; configured&amp;nbsp; with public&amp;nbsp; IP Address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please advice.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saroj&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:55:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-zone/m-p/2430729#M268383</guid>
      <dc:creator>saroj pradhan</dc:creator>
      <dc:date>2019-03-12T03:55:54Z</dc:date>
    </item>
    <item>
      <title>Assuming you are running 8.3+</title>
      <link>https://community.cisco.com/t5/network-security/dmz-zone/m-p/2430730#M268387</link>
      <description>&lt;P&gt;Assuming you are running 8.3+, you need:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;An ACL on the outside interface allowing the needed traffic (example for allowing Web-traffic to your DMZ-host with IP 1.2.3.4):&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host 1.2.3.4 eq 80&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If your NAT for internal clients is setup correctly and there is no ACL on the inside interface you are good to go. If you have an ACL on the inside, then you also need an entry to allow the traffic. That could look like the following if you want to allow all traffic from inside to the DMZ:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;access-list INSIDE-IN permit ip any 1.2.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2014 07:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-zone/m-p/2430730#M268387</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-03-12T07:24:17Z</dc:date>
    </item>
  </channel>
</rss>

