<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DMZ Config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861333#M959104</link>
    <description>&lt;P&gt;I need a sample DMZ config for a 515. I am placing a FTP server in my dmz running SFTP&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:41:04 GMT</pubDate>
    <dc:creator>rmwhite59</dc:creator>
    <dc:date>2019-03-11T11:41:04Z</dc:date>
    <item>
      <title>DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861333#M959104</link>
      <description>&lt;P&gt;I need a sample DMZ config for a 515. I am placing a FTP server in my dmz running SFTP&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861333#M959104</guid>
      <dc:creator>rmwhite59</dc:creator>
      <dc:date>2019-03-11T11:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861334#M959105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Elliot, were you aware of sftp not supported in pix, refer to this Q&amp;amp;A document for the sftp  support through firewall,  you may also  wannt to do forum search or google  Firewalls in generals and sftp support  to see how others have done it as I have seen many threads on this.      &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a0080094874.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a0080094874.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Dec 2007 21:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861334#M959105</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-08T21:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861335#M959106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge,&lt;/P&gt;&lt;P&gt;      I the sftp not supported in all cisco security appliances, i.e. ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raymond&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Dec 2007 23:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861335#M959106</guid>
      <dc:creator>rmwhite59</dc:creator>
      <dc:date>2007-12-08T23:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861336#M959107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raymond, sorry for calling Elliot!  on your question on asa it is not about that but I think it is about the mechanism of sftp/ftps and ftp  and how firewall handles ports and inspection and this seems to be the common denominator on sftp, doing some brief reading there seems to be two ways for ftp dat security .. the sftp and ftp over ssh, you may be able  to get ftp over ssh implemented on pix but the only way to find out is by implementing it to see if it does work.. you may need to look into an ftp client that suports secure ftp.. like global scape.. here is a link , &lt;A class="jive-link-custom" href="http://www.cuteftp.com/cuteftppro" target="_blank"&gt;http://www.cuteftp.com/cuteftppro&lt;/A&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;B&gt;forms of securre ftp&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.process.com/tcpip/sft.pdf" target="_blank"&gt;http://www.process.com/tcpip/sft.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could start with somthing like this, say we have the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local FTP server in DMZ: 172.16.1.1&lt;/P&gt;&lt;P&gt;Public NAT for FTP server 10.20.20.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 10.20.20.20 172.16.1.1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt; access-list outside_access_in  permit tcp any  host 10.20.20.20 eq 21&lt;/P&gt;&lt;P&gt; access-list outside_access_in  permit tcp any  host 10.20.20.20 eq 20&lt;/P&gt;&lt;P&gt; access-list outside_access_in  permit tcp any  host 10.20.20.20 eq 22&lt;/P&gt;&lt;P&gt; access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know how this works if suitable, and if you decide to implement you may want to turn on fw syslog  or setup syslog to see the traffic in the event it fails. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;pls rate any helpful post if it helps!&lt;/I&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 17:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861336#M959107</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-09T17:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861337#M959108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jorge,&lt;/P&gt;&lt;P&gt;     I have attached my config. The public ip for the ftp server is xx.xxx.xxx.51 Here is what I added which did not work. It also shut down traffic to the inside network from the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 66.xxx.xxx.51 172.16.1.10 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 172.16.1.10 eq 21 access-list outside_access_in permit tcp any host 172.16.1.10 eq 20 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 172.16.1.10 eq 22 &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 19:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861337#M959108</guid>
      <dc:creator>rmwhite59</dc:creator>
      <dc:date>2007-12-09T19:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861338#M959109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Before looking at config, what type of FTP server are you using  e.g. Microsoft IIS or 3rd party ftp server if 3rd  what type.? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 20:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861338#M959109</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-09T20:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861339#M959110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;WS-FTP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 20:25:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861339#M959110</guid>
      <dc:creator>rmwhite59</dc:creator>
      <dc:date>2007-12-09T20:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861340#M959111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They access it using this application that is web base. WS-FTP is running on the server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A class="jive-link-custom" href="http://www.jscape.com/sftpapplet/" target="_blank"&gt;http://www.jscape.com/sftpapplet/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 20:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861340#M959111</guid>
      <dc:creator>rmwhite59</dc:creator>
      <dc:date>2007-12-09T20:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861341#M959112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are using outside interface IP as suppose to spare public IP I thought you had spare pub ip, did you added  in your current &lt;B&gt;incoming&lt;/B&gt; acl, as well as static nat as bellow? to be on the same page this is for ftp over SSH which Jscale supports based on docs.. as long you allow passive mode on ftp this should work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(dmz,outside) tcp interface 20 172.16.1.X 20 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static(dmz,outside) tcp interface 21 172.16.1.X 21 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static(dmz,outside) tcp interface 22 172.16.1.X 22 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where X is your ftp server in DMZ subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host xx.xxx.xxx.53 eq 20&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host xx.xxx.xxx.53 eq 21&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host xx.xxx.xxx.53 eq 22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group incoming in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 21:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861341#M959112</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-09T21:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861342#M959114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Outside interface ip is xx.xxx.xxx.53&lt;/P&gt;&lt;P&gt;spare public ip is xx.xxx.xxx.51&lt;/P&gt;&lt;P&gt;xx.xxx.xxx.51 is the public address used for the ftp server in the dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raymond&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 22:25:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861342#M959114</guid>
      <dc:creator>rmwhite59</dc:creator>
      <dc:date>2007-12-09T22:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Config</title>
      <link>https://community.cisco.com/t5/network-security/dmz-config/m-p/861343#M959115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok , then your above static is correct but add additional three lines to "incoming" acl  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 66.xxx.xxx.51 172.16.1.10 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host xx.xxx.xxx.51 eq 20 &lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host xx.xxx.xxx.51 eq 21 &lt;/P&gt;&lt;P&gt;access-list incoming permit tcp any host xx.xxx.xxx.51 eq 22 &lt;/P&gt;&lt;P&gt;access-group incoming in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also make sure the ftp server in dmz is&lt;/P&gt;&lt;P&gt;indeed listening on those ports,by testing&lt;/P&gt;&lt;P&gt;from an outside source with a telnet test as bellow example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g &lt;/P&gt;&lt;P&gt;c:\telnet 66.xxx.xxx.51 20  ...  and do the same for 21 and 22  if get black screen on each of telnet test  means you are hitting the server in dmz on each of those ports.. then test ftps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Dec 2007 23:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-config/m-p/861343#M959115</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-09T23:33:25Z</dc:date>
    </item>
  </channel>
</rss>

