<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic inside and DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951833#M937707</link>
    <description>&lt;P&gt;Hi, all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some question regarding to the communication between inside and DMZ. Cisco configure example the link: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;according to this document.&lt;/P&gt;&lt;P&gt;DMZ IP: 192.168.1.0/24&lt;/P&gt;&lt;P&gt;inside IP: 172.20.1.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the example gives configure communication from DMZ to inside by using static nat:&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 192.168.2.20 172.20.1.5 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here the ip given is 192.168.2.20. why is  192.168.2.20. not 192.168.1.20? Is that misatke?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not in this example but another: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt; when configuring communication from inside to DMZ by using real ip address: &lt;/P&gt;&lt;P&gt;static (inside,dmz) 10.1.1.0 10.1.1.0 netmask 255.255.255.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is reason using real ip? just easy? Does this give less security than by using PAT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shawn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:45:19 GMT</pubDate>
    <dc:creator>xiangdongbi</dc:creator>
    <dc:date>2019-03-11T12:45:19Z</dc:date>
    <item>
      <title>inside and DMZ</title>
      <link>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951833#M937707</link>
      <description>&lt;P&gt;Hi, all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some question regarding to the communication between inside and DMZ. Cisco configure example the link: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;according to this document.&lt;/P&gt;&lt;P&gt;DMZ IP: 192.168.1.0/24&lt;/P&gt;&lt;P&gt;inside IP: 172.20.1.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the example gives configure communication from DMZ to inside by using static nat:&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 192.168.2.20 172.20.1.5 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here the ip given is 192.168.2.20. why is  192.168.2.20. not 192.168.1.20? Is that misatke?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not in this example but another: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt; when configuring communication from inside to DMZ by using real ip address: &lt;/P&gt;&lt;P&gt;static (inside,dmz) 10.1.1.0 10.1.1.0 netmask 255.255.255.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is reason using real ip? just easy? Does this give less security than by using PAT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shawn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951833#M937707</guid>
      <dc:creator>xiangdongbi</dc:creator>
      <dc:date>2019-03-11T12:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: inside and DMZ</title>
      <link>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951834#M937708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is no mistake in this document.  Might be some  users to access it through the real address and some through the natted one. So they are using real ip.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 21:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951834#M937708</guid>
      <dc:creator>owillins</dc:creator>
      <dc:date>2008-05-20T21:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: inside and DMZ</title>
      <link>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951835#M937709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My questiion has two parts. The first part is that in first example documents. the DMZ ip is:192.168.1.0/24, when they use nat they use static (inside,DMZ) 192.168.2.20 172.20.1.5 netmask 255.255.255.255.  the ip is 192.168.2.0. it is 192.168.2.20 not 192.168.1.20 different sub net.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the seocnd question I have is: is that best practice to use real ip when you want to configure communcation from inside to DMZ? is using nat more scurity that real ip?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shawn      &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 21:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951835#M937709</guid>
      <dc:creator>xiangdongbi</dc:creator>
      <dc:date>2008-05-20T21:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: inside and DMZ</title>
      <link>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951836#M937710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shawn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"here the ip given is 192.168.2.20. why is 192.168.2.20. not 192.168.1.20? Is that misatke?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;most likely it is a typo mistake. Having said that as long as routing is configured correctly  192.168.2.20 could also be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" what is reason using real ip? just easy? Does this give less security than by using PAT? "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command (inside,dmz) 10.1.1.0 10.1.1.0 netmask 255.255.255.0.  is basically providing space for 254 static nats in one single instruction which otherwise would have to be entered one by one. In some scenarios you require to access the REAL IP address from the DMZ segment towards the internal and so in that situation you would use this type of instruction. Of course you can control that access by applying appropriate ACL entries to the dmz interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps   .. please rate helpful posts !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 23:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-and-dmz/m-p/951836#M937710</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2008-05-20T23:23:36Z</dc:date>
    </item>
  </channel>
</rss>

