Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

DMZ ASA5505

Posted on 2008-10-20
4
Medium Priority
?
541 Views
Last Modified: 2012-05-05
I am trying to set a dmz. Here is how the traffic will travel:
Internet (inside) ---> ASA ----> Router (outside interface) ----> back to the ASA to interface vlan50 (dmz) ((where the servers are located))...

An outside vender needs to VPN into there router on our outside interface... from there they can manage there servers in out dmz....

On my inside interface access-list I should just allow esp port 50 to there router.  Then I would allow the router to only get to the dmz... I have created an access-list for the dmz, but I am not able to put it on the dmz interface... Any suggestions... Thanks
0
Comment
Question by:axl13
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 

Author Comment

by:axl13
ID: 22760138
I calso cannot nameif the dmz vlan....
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 22762089
Can you post result of "show version" from the ASA? have you tried using VLAN3 instead of VLAN50?
Can you post your config?
0
 
LVL 2

Expert Comment

by:JimmyLarsson
ID: 22765606
Hello

Besides the fact that I don really understand the topology You are describing...

If it is the IPSEC-protocoll "ESP" you want to allow it[ not a port but a Ip-protocol. Make sure that you are allowing IP protocol 50 and not a tcp or udp port.

ie:
access-list outside extended permit ip any host 1.2.3.4 50

Please post your entire configuration after hiding sensible data.

Br Jimmy
0
 

Accepted Solution

by:
axl13 earned 0 total points
ID: 22766694
Here is the config as well as a net diagram...
Drawing3.jpg
asa5505-2.TXT
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

661 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question