Advertisement

04.28.2008 at 04:07PM PDT, ID: 23360530
[x]
Attachment Details

Multiple Public Subnets Behind 1 DMZ

Asked by CreditSoupTech in Network Operations, Cisco PIX Firewall, Network Design & Methodology

Tags: SonicWALL, Pro 2040

Ok I have a complete public class C network that is subnetted and distibuted into vlan's at a core router. The first half of the class C is carved out into Subnets of 255.255.255.224 and thus have 30 useable hosts on each subnet. So my problem is that i've ran out of IP addresses on one of the vlans that goes to a SonicWall Pro 2040. I have created the new subnet and assigned it to a vlan on the switch. The new vlan has a network address of 123.123.123.128 and subnet of 255.255.255.224. I combined the two vlans so they are both coming into a single WAN interface on the SonicWALL. Here is were I ran into my first problem, the firewall will give you an invalid pair error if you try adding a range to your DMZ that is outside of your firewall's subnet. So in order for it to accept the traffic from both networks I had to change the firewalls' WAN interfaces subnet to 255.255.255.0 so it would take the whole Class C. I then made static routes to route the traffic for the other unneeded vlans. Does anyone know a better way to do this??? I can now successfully connect to the new IP address's From the WAN and LAN sides of the firewall, but not from the DMZ. So my already in place servers in the DMZ can not communicate with the servers in the same DMZ that I just added from a diffrent subnet. I am thinking my already in place servers traffic is hitting the firewall and the firewall is saying yeah that IP is in my DMZ but with a subnet of 255.255.255.0 (which is how the sonicwall's WAN see's the class C network). Does anyone know how I can get the servers on the DMZ to be able to communicate??  Start Free Trial
[+][-]04.28.2008 at 08:43PM PDT, ID: 21459524

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.29.2008 at 10:09AM PDT, ID: 21464131

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.29.2008 at 10:33AM PDT, ID: 21464335

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.29.2008 at 12:56PM PDT, ID: 21465612

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.29.2008 at 01:04PM PDT, ID: 21465691

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.29.2008 at 01:05PM PDT, ID: 21465700

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.29.2008 at 01:09PM PDT, ID: 21465729

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Network Operations, Cisco PIX Firewall, Network Design & Methodology
Tags: SonicWALL, Pro 2040
Sign Up Now!
Solution Provided By: mikebernhardt
Participating Experts: 2
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628