Configuring The Dmz - Cisco ISA500 Series Administration Manual

Integrated security appliance
Hide thumbs Also See for ISA500 Series:
Table of Contents

Advertisement

Networking

Configuring the DMZ

Configuring the DMZ
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
A DMZ (Demarcation Zone or Demilitarized Zone) is a subnetwork that is behind
the firewall but that is open to the public. By placing your public services on a
DMZ, you can add an additional layer of security to the LAN. The public can
connect to the services on the DMZ but cannot penetrate the LAN. You should
configure your DMZ to include any hosts that must be exposed to the WAN (such
as web or email servers).
The DMZ configuration is identical to the VLAN configuration. There are no
restrictions on the IP address or subnet assigned to the DMZ port, except it cannot
be identical to the IP address given to the predefined VLANs.
Figure 4 Example DMZ with One Public IP Address for WAN and DMZ
www.example.com
Internet
Public IP Address
209.165.200.225
ISA500
LAN Interface
192.168.75.1
User
192.168.75.10
DMZ Interface
172.16.2.1
Web Server
Private IP Address: 172.16.2.30
Public IP Address: 209.165.200.225
User
192.168.75.11
Source Address Translation
209.165.200.225
172.16.2.30
4
123

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Isa550Isa570Isa570wIsa550w

Table of Contents