cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
745
Views
0
Helpful
1
Replies

DMZ Importance with a PIX firewall?

lcortex
Level 1
Level 1

I am going to be setting up a PIX 525 for my company and I had a question regarding the technology behind a DMZ. It was suggested that we set up a DMZ for our web server, and have it reside between two routers and the PIX on it's own DMZ LAN. Couldn't I achieve the same results by giving my web server an internal (192.168.x.x) address, and telling the router to do port forwarding to it?

Thanks,

Ross

1 Reply 1

jtnim
Level 1
Level 1

It's always a good practice to separate web servers, or any other service that you provide to the internet, into its own subnet. I'm not sure what the point is in having the PIX in the its own DMZ LAN, though. Simply put your web servers in the DMZ interface and your internal network in the inside interface. Configure a static NAT for the web servers, and NAT/PAT for the internal LAN.

-- Rubio

Review Cisco Networking for a $25 gift card