cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2137
Views
0
Helpful
3
Replies

DMZ Through Internal (Private) Network

pauzi123@
Level 1
Level 1

Hello guys,

Currently i have set up DMZ zone for my network. The system is being tested using external GSM Network, the connection and the synchronization are successful. Currently the server is directly connected to the DMZ Port at the Firewall.

Can i move the server into my internal network and connect the server using network switch?


Firewall (5508-X)
Router ( ISR 2912/K9)
Switch ( WS-C3850-48P-S ) 

I have attached current network topology

2 Accepted Solutions

Accepted Solutions

Can i move the server into my internal network and connect the server using network switch?

of course you can, infact I would recommend it for scaleability.  If the switch you will be using is a shared switch with the other VLANs in  your network then just create a new VLAN, place two ports in this new VLAN and connect the firewall DMZ interface to one port and the server to the other.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

So long as the VLANs are trunked to the access switches this should work.  Be careful about putting the default gateway on the core switch.  If you have any other IP configured on the core then these will be routed directly to eachother.  If you want the subnets to be seperate then set the ASA IP as the default gateway with no IP configured on the core switch for the new VLAN.  Or, if your core switch supports it, configure VRFs on the core switch and place the new VLAN in a VRF.  If the subnets don't need to be seperated then this is not relevant.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

3 Replies 3

Can i move the server into my internal network and connect the server using network switch?

of course you can, infact I would recommend it for scaleability.  If the switch you will be using is a shared switch with the other VLANs in  your network then just create a new VLAN, place two ports in this new VLAN and connect the firewall DMZ interface to one port and the server to the other.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

Thanks, does this configuration work if i connect the DMZ & Server at different switches? The switches has the assigned VLAN and i have configured gateway at my Core Switch

So long as the VLANs are trunked to the access switches this should work.  Be careful about putting the default gateway on the core switch.  If you have any other IP configured on the core then these will be routed directly to eachother.  If you want the subnets to be seperate then set the ASA IP as the default gateway with no IP configured on the core switch for the new VLAN.  Or, if your core switch supports it, configure VRFs on the core switch and place the new VLAN in a VRF.  If the subnets don't need to be seperated then this is not relevant.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card