Solved

ASA Scenario-1-DMZ-to-Internet access

Posted on 2014-09-17
4
184 Views
Last Modified: 2014-10-12
How can I stop internet to DMZ servers.  From internet DMZ server should be reached but DMZ servers should not get internet.

Regards
ramu
0
Comment
Question by:RAMU CH
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 25

Assisted Solution

by:Ken Boone
Ken Boone earned 150 total points
ID: 40330284
You can put an ACL on the DMZ interface to block this.
0
 
LVL 22

Accepted Solution

by:
eeRoot earned 250 total points
ID: 40335623
Make sure your firewall rules are allowing inbound connections, but not outbound connections.  For a DMZ, any/any rules or rules allowing outbound connections are bad.
0
 
LVL 3

Assisted Solution

by:Johneil1
Johneil1 earned 100 total points
ID: 40351376
0
 
LVL 1

Author Closing Comment

by:RAMU CH
ID: 40376379
Thanks
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question