cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

628
Views
40
Helpful
19
Replies
Highlighted
VIP Advisor

Re: Firewalls in DMZ

The error you're getting is on internal or internet firewall? Can you share the command you're typing?

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Highlighted
Beginner

Re: Firewalls in DMZ

 route outside 0.0.0.0 0.0.0.0 172.20.57.2

Highlighted
Beginner

Re: Firewalls in DMZ

and the error is on internal FW, thats where im trying to add the route

Highlighted
VIP Advisor

Re: Firewalls in DMZ

Can you share output of "show int ip bri" and "show route" from both firewalls please?

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Highlighted
Contributor

Re: Firewalls in DMZ

If you are insisting on using two firewalls, static routing on a firewall would be pretty easy.

Internet firewall
Route outside 0.0.0.0 0.0.0.0 gatewayIP
Route inside allInternalSubnets insideFirewallOutsideIp
Example
Route inside 172.16.0.0 255.255.0.0 172.16.254.1

Inside firewall example
Route outside 0.0.0.0 0.0.0.0 172.16.254.2

This is just an example. One consideration would be that having two firewalls in one DMZ subnet can be an issue because there are two possible gateways. Are you going to have a router in the DMZ? The issue with two gateways is that a server will only have one default gateway configured. You can resolve this with static routes on the servers.

Please rate helpful posts.