<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 DMZ configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635841#M567576</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Asa version is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ASA5510&amp;gt; show version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.0(4)&lt;BR /&gt;Device Manager Version 6.1(5)51"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ Web server IP address is 10.30.30.14. I draw it wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to access web server from Inside and Internet. On the web server i manually configured 2 IP addresses and 2 gateways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Feb 2011 09:27:35 GMT</pubDate>
    <dc:creator>Amarsanaa_a</dc:creator>
    <dc:date>2011-02-07T09:27:35Z</dc:date>
    <item>
      <title>ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635839#M567574</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm in newbie in CISCO firewalls. I have a problem with DMZ configuration. Our web server is using inside IP address and DMZ ip address also port is using 83. When i type from inside interface &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://192.168.14:83" target="_blank"&gt;http://192.168.14:83&lt;/A&gt;&lt;SPAN&gt; i can access to web server. Now i want it to enable access from internet using firewall public ip address(for example &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://202.165.200.225:83" target="_blank"&gt;http://202.165.200.225:83&lt;/A&gt;&lt;SPAN&gt;). Please check below schema.&lt;/SPAN&gt;&lt;BR /&gt;&lt;IMG alt="http://img546.imageshack.us/img546/8219/191634.jpg" class="jive-image" src="http://img546.imageshack.us/img546/8219/191634.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:45:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635839#M567574</guid>
      <dc:creator>Amarsanaa_a</dc:creator>
      <dc:date>2019-03-11T19:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635840#M567575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which version of ASA are you using? and also is there typo in the ip address (web server dmz ip address you have 10.10.30.14), however, dmz interface ip address of the ASA is 10.30.30.1 (they are not in the same subnet), please kindly advise which is the correct subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, assuming that you would like to access the web server from the Internet via its DMZ interface instead of the inside interface, right? You have default gateway on the web server pointing towards the ASA dmz interface ip address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Feb 2011 08:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635840#M567575</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-07T08:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635841#M567576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Asa version is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ASA5510&amp;gt; show version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.0(4)&lt;BR /&gt;Device Manager Version 6.1(5)51"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ Web server IP address is 10.30.30.14. I draw it wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to access web server from Inside and Internet. On the web server i manually configured 2 IP addresses and 2 gateways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Feb 2011 09:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635841#M567576</guid>
      <dc:creator>Amarsanaa_a</dc:creator>
      <dc:date>2011-02-07T09:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635842#M567577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so i assume that you would like to use the DMZ ip address for access from the Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, then here is the configuration:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (dmz,outside) tcp interface 83 10.30.30.14 83 netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, on the access-list applied to your outside interface, you will have to add the following:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list &lt;ACL-NAME-APPLIED-TO-OUTSIDE-INTERFACE&gt; permit tcp any interface outside eq 83&lt;/ACL-NAME-APPLIED-TO-OUTSIDE-INTERFACE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, would applying 2 default gateways on the web server work? Does it detect automatically where the traffic is coming from and send the traffic towards the correct default gateway? Because if traffic is routed from ASA DMZ towards the web server DMZ interface, and if the reply goes outbound from web server inside interface towards ASA inside interface, ASA will drop the packet because of assymetric routing. Traffic needs to come in and out of the same interface pair as ASA keeps track of the connection state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Feb 2011 09:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635842#M567577</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-07T09:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635843#M567578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sometimes our inside network is down. When i restart web server. network is come back. I suspect this problem related using 2 gateways on web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current situation is: all salesmen come to office and synchronize their data via wireless using &lt;A class="postlink" href="http://192.168.14:83/"&gt;http://192.168.14:83&lt;/A&gt;. Now when they are out of office they want to synchronize data via internet &lt;A class="postlink active_link" href="http://202.165.200.225:83/"&gt;http://202.165.200.225:83&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will test your configration and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appriciate your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;Amaraa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Feb 2011 09:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635843#M567578</guid>
      <dc:creator>Amarsanaa_a</dc:creator>
      <dc:date>2011-02-07T09:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635844#M567579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From my experience, having 2 default gateways might not work.&lt;/P&gt;&lt;P&gt;I would recommend that you configure default gateway towards the ASA DMZ interface ip address as this will be for inbound access from the Internet.&lt;/P&gt;&lt;P&gt;For the inside NIC of the web server, if the wireless ip subnet is also in 192.168.1.0/24 then you don't need to configure default gateway for that inside NIC because they are in the same subnet, so it will arp for the ip address. Otherwise, if your wireless is in different subnet, then you can configure static route for routing towards the inside NIC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Feb 2011 10:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635844#M567579</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-07T10:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635845#M567580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our web server is also sending data over VPN via 192.168.1.14. If i remove gateway it cannot send data over VPN.&lt;/P&gt;&lt;P&gt;That's mean:&lt;/P&gt;&lt;P&gt;1st. I need to remove default gateway of 192.168.1.0/24 range&lt;/P&gt;&lt;P&gt;2n I need to write static route on 192.168.1.0/24 range. Is that correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"route add -p 192.168.1.14 mask 255.255.255.255 192.168.1.1"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Feb 2011 10:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635845#M567580</guid>
      <dc:creator>Amarsanaa_a</dc:creator>
      <dc:date>2011-02-09T10:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635846#M567581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1st/ yes, you are correct. You have to removed the default gateway for the 192.168.1.0/24 (inside subnet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd/ no, you don't configure static route for 192.168.1.0/24 because that is directly connected subnet. What is your vpn ip pool? you will need to add route for your vpn ip pool subnet to point to 192.168.1.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Feb 2011 10:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635846#M567581</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-09T10:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635847#M567582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How to configure IP Pools and route on the firewall. Please kindly advice for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Amaraa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 07:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635847#M567582</guid>
      <dc:creator>Amarsanaa_a</dc:creator>
      <dc:date>2011-02-10T07:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635848#M567583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, you mentioned that it's also sending traffic towards the VPN, so you would need to find out what is the VPN remote LAN subnets, and configure route on the web server itself for the VPN remote LAN subnet to point towards the firewall inside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 07:30:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635848#M567583</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-10T07:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635849#M567584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/3/9/10939-Firewall.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;I think this is remote VPN address. Now how to configure route on web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Amaraa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 07:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635849#M567584</guid>
      <dc:creator>Amarsanaa_a</dc:creator>
      <dc:date>2011-02-10T07:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635850#M567585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;route add -p 10.2.16.0 mask 255.255.254.0 192.168.1.1&lt;/P&gt;&lt;P&gt;route add -p 10.2.2.0 mask 255.255.255.0 192.168.1.1&lt;/P&gt;&lt;P&gt;route add -p 10.2.5.0 mask 255.255.255.0 192.168.1.1&lt;/P&gt;&lt;P&gt;route add -p 166.166.0.0 mask 255.255.0.0 192.168.1.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 07:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-configuration/m-p/1635850#M567585</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-10T07:50:58Z</dc:date>
    </item>
  </channel>
</rss>

