Solved

Cisco Pix 515E - dmz configuration

Posted on 2003-11-13
5
1,311 Views
Last Modified: 2013-11-16
Hi,

I have a Cisco Pix 515e fire wall and comleted all basic configurations along with DMZ.

Inside IP range 192.168.X.X
DMZ IP rang   172.16.X.X

I want to access(read and wriite files) the systems in the DMZ from the inside network systemalso access the systems(read and write files) inside the local network from the system within the DMZ

What is the command line configuration to do this.

Can comeone help me


Thanks
Deva
0
Comment
Question by:deva_rajesh
5 Comments
 
LVL 18

Accepted Solution

by:
chicagoan earned 250 total points
ID: 9739138
You don't need any PIX configuration to access the DMZ from the inside unless you're filtering outbound traffic.


I'd be very cautious about setting up a share on a windoze machine in the DMZ and would heartily suggest FTP for that purpose as the IP filtering on the server will be much more straightforward and the protocol is subject to a lot fewer vulnerabilities.

If you want to address a host on a higher security interface, assign an address in the DMZ, create a static NAT and appropriate access lists *dbl chk syntax*
static (inside, DMZ) 192.168.xxx.xxx 172.16.x.x  255.255.255.255
access-list dmz_in permit tcp any host <host address> eq (service - ftp, any, etc.)  
access-group dmz_in in interface insode
 
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/bafwcfg.htm#26921
would be some good bedtime reading
;-)
0
 
LVL 2

Expert Comment

by:skyfreedomdotnet
ID: 9884679
Deva do you have PIX Device Manager installed? What is the version of your IOS on the PIX?
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this increasingly digital world, security hacks are no longer just a threat, but a reality. As we've witnessed with Target's big identity hack 2013, Heartbleed in 2015, and now Cloudbleed, companies and their leaders need to prepare for the unthi…
As cyber crime continues to grow in both numbers and sophistication, a troubling trend of optimization has emerged over the last year.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question