09-21-2017 08:02 AM - edited 03-05-2019 09:10 AM
We are using Cisco 2921 routers and have to connect Vlans to DMZ server and to ISP. We have done vlan interconnectivity using router at Access layer. Now we have to use router firewall between DMZ, internal Network. We have to connect to ISP and DMZ server with HTTP,FTP and TFTP services. Can you tell me about setting up router firewall , setting up NAT & PAT and getting access of Vlans to ISP and DMZ server.
09-21-2017 03:39 PM
Hi,
Basic steps:
Create an access-list with DMZ network
access-list 1 permit 192.168.0.0 0.0.0.255
ip nat inside source list 1 interface fa 0/1 overload
inft fa 0/0 - DMZ
ip nat inside
int fa 0/1 - ISP
ip nat outside
10-01-2017 10:03 PM
10-02-2017 05:30 AM
You can create an Access List denying port 21 and 69.
access-list 101 permit tcp IP DA VLAN any eq 21
access-list 101 permit tcp IP DA VLAN any eq 69
10-08-2017 10:53 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide