Link to home
Start Free TrialLog in
Avatar of kesslerkare
kesslerkare

asked on

Configure the DMZ port on a Sonicwall TZ190 for LAN access

I need to allow access from the DMZ port on a TZ190 to a specific host on the private LAN port. I only need 4 TCP ports open. I can ping from LAN side to the serveron the DMZ but not the other way despite my access rules.  This can be done, right, or is the DMZ by design not allowed to get to the LAN side?
Avatar of ok123jump
ok123jump

By design, the DMZ port is isolated from the other ports in the network. Otherwise, your DMZ computer becomes a vulnerability to the rest of the LAN computers in the network.

As long as you understand the risks, you need to set the DMZ port to operate in Transparent Mode and map:

http://www.gnswireless.com/Sonicwall_OPT_Port.htm

Cheers!
Mike
Avatar of Dk_guru
I would simply "forward" the ports to the desired LAN IP address and keep the system out of the DMZ (especially if you are only utilizing 4 TCP ports!) Definitly set the IP to static or "reserved" via DHCP.  
SOLUTION
Avatar of Cas Krist
Cas Krist
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Very strange, I have this setup in use for quite some time, I don't have a NAT policy for this. Could you show us the NAT policy you had to create?!