<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to config firewall if accessing from dmz to inside lan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190517#M358417</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is dmz the name you have for that interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you cn do &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input ? to check the available names and then set the one required&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Apr 2013 22:46:02 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-04-11T22:46:02Z</dc:date>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190510#M358410</link>
      <description>&lt;P&gt;Hi everyone, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you can help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a ASA with IOS 8.44. We just configured a dmz zone. Now we try to access a share of a windows server in INSIDE interface from another windows server in dmz,&amp;nbsp; So on the server in DMZ, I will type \\INSIDE_Server\SharedName (or \\ip_of_inside server\SharedName) to access the share.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the firewall, I open tcp port 137, 138, 139, and 445 to allow from DMZ to access to Inside server. But I failed. So what do I need to configure so that I can complete my task?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, we have some internal DNS in INSIDE interface. How do I make my DMZ server to use the inside DNS servers for dns resolution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you can help. Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Takami Chiro&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190510#M358410</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2019-03-12T01:27:05Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190511#M358411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wihtout seeing the current configuration its hard to say what the problem is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you monitored the ASA logs while connecting from DMZ to INSIDE? Have you tried to test the connection by first allow all traffic between the servers in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the actual servers configured so that this connection is even possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to the DNS use since we are talking about servers I would imagine that you define the INSIDE DNS server in the settings of the actual DMZ server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 21:46:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190511#M358411</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-11T21:46:15Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190512#M358412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ho Jouni, thank you for your response. In fact, you are right, I should have checked my syslog as well.... how dumb I am.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean the question "Are the actual servers configured so that this connection is even possible"? I do not understand what means....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Takami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190512#M358412</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2013-04-11T22:02:16Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190513#M358413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean that could the INSIDE server have some own firewall software that blocks the attempt from the DMZ to open the shared folder or something along those lines?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the best bet is to check the logs through the ASDM and see if anything gets blocked when you try to form the connection. If you cant see anything blocked on the firewall then the problem might be somewhere else than the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But again I have to say since we dont see the ASA configurations we cant confirm all the settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should confirm atleast that&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The routing between the hosts is ok&lt;/LI&gt;&lt;LI&gt;That NAT doesnt stop the communication between the networks&lt;/LI&gt;&lt;LI&gt;That no ACL blocks the traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190513#M358413</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-11T22:08:48Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190514#M358414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni, I will definitely reveiw my syslog in a moment.&amp;nbsp; The ping from the dmz to the inside server ip is ok.... and we also have some other servers in there so I think the route should be fine. One thing for sure.... is that I am not sure if the ports I open for this connection is correct. It is because I could nto see any counters rolling for the ports... HOpefully I can review the syslog info and see what is being blocked...that way everything should be clear. Thank you for reminding me that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will keep posted here. Thank you again for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Takami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190514#M358414</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2013-04-11T22:24:44Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190515#M358415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you are using a domain name, first thing would be to check that DNS resolution is working fine from dmz to inside,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A packet-tracer would let us know that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input dmz udp x.x.x.x ( DMZ client ip address) y.y.y (inside DNS) server 53&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;post the results to check them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also just to check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input dmz udp x.x.x. y.y.y 139&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190515#M358415</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-11T22:31:22Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190516#M358416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JCarvaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response. I tried to run the packet tracer command. It did not let me input the inside ip.Here is the result&lt;/P&gt;&lt;P&gt;##############&lt;/P&gt;&lt;P&gt;packet-tracer input dmz udp 172.20.0.49 10.10.0.9 server 53&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;##############&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.10.0.9 is one of our internal dns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please correct me if I mistype something... thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190516#M358416</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2013-04-11T22:41:59Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190517#M358417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is dmz the name you have for that interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you cn do &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input ? to check the available names and then set the one required&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190517#M358417</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-11T22:46:02Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190518#M358418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JCarvaja...sorry keep bugging you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok... You are correct. My interface is dmz2 indeed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if I type in "&lt;/P&gt;&lt;P&gt;packet-tracer input dmz udp 172.20.0.49 10.10.0.9 ?". It will tell me unrecognized command. If I typed in "&lt;/P&gt;&lt;P&gt;packet-tracer input dmz udp 172.20.0.49 ?"...I see a bunch of commands, including udp port numbers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what do I need to type after the ip address there? My guess is "&lt;/P&gt;&lt;P&gt;packet-tracer input dmz udp 172.20.0.49 purt_number destination_ip port_number" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190518#M358418</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2013-04-11T22:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190519#M358419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input dmz udp 172.20.0.49 1025 10.10.0.9 53&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first port is the random port &lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 22:55:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190519#M358419</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-11T22:55:52Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190520#M358420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jcarvaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much. Finally I could run the command for the troubleshoot. And the following is the result:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;esult of the command: "packet-tracer input dmz2 udp 172.20.0.49 1025 10.10.0.9 53"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.10.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group dmz2_acl in interface dmz2&lt;/P&gt;&lt;P&gt;access-list dmz2_acl extended deny ip any 10.0.0.0 255.0.0.0 &lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: dmz2&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; #########################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to do so...does it mean I need to allow tcp&amp;nbsp; 53 from dmz that server to inside the DNS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much again...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 23:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190520#M358420</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2013-04-11T23:20:19Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190521#M358421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above output tells us that you have a rule/ACL that blocks any traffic to the network 10.0.0.0/8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please share the ACL named &lt;STRONG&gt;dmz2_acl&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the command &lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show access-list dmz2_acl&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or you can just allow DNS traffic with the following commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list dmz2_acl line 1 remark Permit DNS from DMZ to INSIDE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list dmz2_acl line 2 permit udp host 172.20.0.49 host 10.10.0.9 eq 53&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow DNS between the 2 host IP addresses. Do notice that this just allows DNS and it might be that further configurations might be needed for your connections to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 23:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190521#M358421</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-11T23:42:36Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190522#M358422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bobson,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great to see that we ran the command,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz2_acl extended deny ip any 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As we can see here you might be permitting icmp traffic and some of the SMB traffic but at least UDP/53 is being denied so that being said you must modify the acl as Jouni said,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Afterwards DNS should work, run the packet tracer after the changes and post the results &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 23:48:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190522#M358422</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-11T23:48:12Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190523#M358423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Jouni, and Jcarvaja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the details. I will add the accesslist to fix the DNS issue. But may I ask....how I can do so that my server in dmz can access the share in one of the server in INSDE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No matter what, thank you very much for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Takami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 15:27:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190523#M358423</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2013-04-12T15:27:19Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190524#M358424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could always consider allow all traffic between the 2 servers and then trying the connection if it works. This would atleast tell if the problem is on the firewall settings or actually on the servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And again, we cant take everything into consideration when we dont have any idea how your network is built and how the firewall is configured. It would help to see the configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 15:38:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190524#M358424</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-12T15:38:10Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190525#M358425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bobson,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;exactly, what Jouni said is what is need it to allow full communication,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now to test the config you could also run a packet-tracer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input dmz2 tcp &lt;SPAN style="font-size: 10pt;"&gt;172.20.0.49 1025&amp;nbsp; 10.10.0.9 137&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Also remember to rate all of the helpful posts, that is as important as a thanks, let us know if you do not know how &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 16:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190525#M358425</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-12T16:44:38Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190526#M358426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni and JCarvaja, thank you very much again for your tips. Little overwhelming here... I really appreciate it. At this point, I will be fine. If I need help I will definitely post another question. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I will rate you both too! Have a great weekend!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Takami&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190526#M358426</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2013-04-12T21:05:23Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190527#M358427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear (if its indeed working now?) &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And likewise!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190527#M358427</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-12T21:08:38Z</dc:date>
    </item>
    <item>
      <title>How to config firewall if accessing from dmz to inside lan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190528#M358428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear sr.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:18:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-firewall-if-accessing-from-dmz-to-inside-lan/m-p/2190528#M358428</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-12T21:18:11Z</dc:date>
    </item>
  </channel>
</rss>

