cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
443
Views
0
Helpful
1
Replies

ASA dmz and secure server

cmuench
Level 1
Level 1

Hello,

I have a DMZ network and then also an internal network.

I have 2 servers on my internal network that need to be accessible from the public internet.

However I don't want to do a NAT and blindly open those ports up.

so my thinking is

public ip -> dmz vip -> internal ip

I have never had the need for this before so what do you experts recomend without me opening up my firewall like swiss cheese?

I was thinking of some sort of proxy type thing maybe?

1 Reply 1

Collin Clark
VIP Alumni
VIP Alumni

Yup a reverse proxy in a DMZ is the proper design. There are quite a few out there. WebSeal is one example. A google search should result a pretty good list of them.

Review Cisco Networking for a $25 gift card