Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Configuring Cisco ASA rules to allow DMZ 2 servers to see internal network

Posted on 2014-04-25
4
Medium Priority
?
668 Views
Last Modified: 2015-06-01
ASA Firewall Rules need to do the following. (Using Cisco ASDM 6.3 console)

DMZ
1 x ADFS Proxy server (192.168.x.x) needs to see the internal ADFS server (172.x.x.x)
(I can't currently join the ADFS Proxy server to the domain)
1 x Front End Web server (192.168.x.x) needs to see the internal CRM server (172.x.x.x)
(I can't currently join the Front End Web server to the domain)

Objective
External end users with AD accounts to enter a CRM URL (crm.domain.co.uk) via browser on tablet
URL points to Front End Web server in the DMZ, then redirects to the ADFS server via the ADFS proxy in the DMZ
ADFS authenticates the user against the internal DC, and then the Front End Web server in the DMZ redirects to the internal CRM SQL boxes rendering CRM to the external users/s.
0
Comment
Question by:CTCRM
  • 2
4 Comments
 
LVL 28

Expert Comment

by:asavener
ID: 40023675
I would suggest putting a read-only domain controller in the DMZ that your proxy server can use.  Then open up the appropriate ports to allow the domain replication to occur.
0
 
LVL 2

Accepted Solution

by:
CTCRM earned 0 total points
ID: 40090864
I have added the NAT rule and Access Rules which has resolved my issue.
0
 
LVL 2

Author Closing Comment

by:CTCRM
ID: 40102439
After adding the correct rules my issue was resolved.
0
 
LVL 1

Expert Comment

by:CyberGar
ID: 40806931
care to share your ACL?  I have the NAT, but not sure where the ACL goes...
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Suggested Courses

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question