cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
334
Views
0
Helpful
3
Replies

Fault-tolerant DMZ design

lev.luvishis
Level 1
Level 1

I have a DMZ (off the DMZ-port of the PIX 525 firewall) with the customer routers sitting there. We are using dynamic NAT and static routes on the PIX-firewall. The application we run is FTP - out to the customer servers. The PIX has static ip route for each customer network that uses the customer's router Ethernet which sits in our DMZ as the next hop. What we would like to accomplish now is a fault-tolerant solution, so that if the leased line to the customer router in our DMZ fails we will be still able to connect to the customer's server through our internet connection. What could you recommed me to do to implement this solution?

3 Replies 3

ciscomoderator
Community Manager
Community Manager

Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center (http://www.cisco.com/tac) or speak with a TAC engineer. You can open a TAC case online at http://www.cisco.com/tac/caseopen

If anyone else in the forum has some advice, please reply to this thread.

Thank you for posting.

msenko
Level 1
Level 1

You might try a router with weighted routes to your customer site, the primary route being the leased line and the secondary route for the internet.

Thank you for your answer Mike. I still have a question:

1. If I have more than one customer - should I still use a single router and ACL's to keep the traffic from the different users separate?

2. Which routing protocol should I run between the customer's router and my router?

Thank you in advance

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: