DMZ ASA5505

I am trying to set a dmz. Here is how the traffic will travel:
Internet (inside) ---> ASA ----> Router (outside interface) ----> back to the ASA to interface vlan50 (dmz) ((where the servers are located))...

An outside vender needs to VPN into there router on our outside interface... from there they can manage there servers in out dmz....

On my inside interface access-list I should just allow esp port 50 to there router.  Then I would allow the router to only get to the dmz... I have created an access-list for the dmz, but I am not able to put it on the dmz interface... Any suggestions... Thanks
axl13Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

axl13Author Commented:
I calso cannot nameif the dmz vlan....
0
lrmooreCommented:
Can you post result of "show version" from the ASA? have you tried using VLAN3 instead of VLAN50?
Can you post your config?
0
JimmyLarssonCommented:
Hello

Besides the fact that I don really understand the topology You are describing...

If it is the IPSEC-protocoll "ESP" you want to allow it[ not a port but a Ip-protocol. Make sure that you are allowing IP protocol 50 and not a tcp or udp port.

ie:
access-list outside extended permit ip any host 1.2.3.4 50

Please post your entire configuration after hiding sensible data.

Br Jimmy
0
axl13Author Commented:
Here is the config as well as a net diagram...
Drawing3.jpg
asa5505-2.TXT
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
VPN

From novice to tech pro — start learning today.