10-05-2011 06:27 AM - edited 03-11-2019 02:34 PM
Hi,
What is the recommended approach for the traffic from DMZ to Inside
1. Do you apply access-list from lower security to higher OR
2. Do you apply NAT
Any other views for the traffic pattern security are most welcomed.
Thanks,
Kunal
Solved! Go to Solution.
10-05-2011 06:40 AM
Hi Kunal,
You woudl definitely need an ACL when you are going from dmz to inside.
Nat depends, if you have a nat-control enabled then you woudl need it, other wise not. But if you are accessing any server on its public ip then you would need nat, irrespective of if you have nat-control or no nat-control
How to check nat-control:
show run nat-control.
Hope that helps.
Thanks,
Varun
10-05-2011 06:40 AM
Hi Kunal,
You woudl definitely need an ACL when you are going from dmz to inside.
Nat depends, if you have a nat-control enabled then you woudl need it, other wise not. But if you are accessing any server on its public ip then you would need nat, irrespective of if you have nat-control or no nat-control
How to check nat-control:
show run nat-control.
Hope that helps.
Thanks,
Varun
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide