Solved

Adding a DMZ network in my Cisco ASA 5520 network

Posted on 2014-09-20
4
505 Views
Last Modified: 2014-10-02
Dear All,

  I have two Cisco ASA 5520 with configured as LAN and WAN interfaces only with Clustered configured.

LAN IP: 192.168.1.x., WAN 62.11.11.x
I need to configure a new DMZ range 172.30.30.x n the third ASA interfaces  and make sure that the cluster config will still working.

can someone please advise the steps and the required route to be added.

Thanks
0
Comment
Question by:ITMaster1979
  • 2
  • 2
4 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 40334614
ASA 5500 Adding a DMZ Step By Step

The only difference for you is, if you are in active standby, you need to add an active and standby IP to the DMZ interface i.e

!
interface Ethernet0/2
 speed 100
 duplex full
 nameif DMZ
 security-level 0
 ip address 123.123.123.123 255.255.255.248 standby 123.123.123.124
!

Carry out all configuration on the primary active firewall, connect the same interfaces of both, to the DMZ, and Bobs yer uncle

PL
0
 
LVL 1

Accepted Solution

by:
ITMaster1979 earned 0 total points
ID: 40334985
Do I have to create the dmz vlan in my core switch?
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 40335191
That prety much depends on your topology, Im my case I prefer a DMZ to have its own switch, rather than relying on VLAN seperation. If I was deplying the solution to a government body, then I would have to have a physical seperation. But if you are not as concerned about security VLAN separation is adequate.
0
 
LVL 1

Author Closing Comment

by:ITMaster1979
ID: 40356563
good
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Hit router interface limit 7 64
VOIP gateways - feedback 23 63
adjusting startup config 6 48
cisco asa proxy arp 2 25
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question