Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 156
  • Last Modified:

ASA Firewall Access Rule for Web Servers

In ASA 5520 I have configured an Access Rule so that outside client can reach the Webserver in the DMZ. It worked with no problem. However , so far I have only one Webserver in the DMZ and the access rule is permitting from outside to the destination (Webserver object) which has an IP address 10.10.10.20
In real world there should be redundant Webservers in the DMZ, so that they can "Load Balance" the load.
I wonder if I need to create separate Access Rule for each Webserver or there is a simpler way to do it ?

Any help will be very much appreciated.

Thank you

dmz
0
jskfan
Asked:
jskfan
  • 3
2 Solutions
 
Pete LongConsultantCommented:
The firewall is not a load balancer, if you want load balancing buy a load balancer?

You would need to set each web server with its own public IP address then you could load balance using DNS round robin.

Or if you are using  server 2012 - you could reverse proxy and use NLB.


Pete
0
 
jskfanAuthor Commented:
Sorry...
I am not saying I need to Load balance with Firewall.

Usually companies do not use just one web server in the DMZ. They use a bunch of them and I believe in DNS they create CNAME so that all webservers will have the same name but different IP addresses...

Well... the way I configured ASA in the LAB, was not complicated because I just allowed HTTP from outside to go to that single webserver IP address. in the case when there are several webservers, how do you change the access rules so that it will apply to all webservers in the DMZ?
hope the Question is clear now..
0
 
Don JohnstonCommented:
Usually companies do not use just one web server in the DMZ. They use a bunch of them and I believe in DNS they create CNAME so that all webservers will have the same name but different IP addresses...
I believe that what you're referring to is "content switching".
0
 
jskfanAuthor Commented:
PeteLong:

in your comment above you mentioned Load Balancer, I believe that would work if you put it in the DMZ (Of course), that way you Load balance between WebServers, and the WebServers will have a common Virtual IP address.
I believe that Virtual IP address is the IP address that will be used in ASA Firewall Access Rule. It makes more sense to me this way.
0
 
jskfanAuthor Commented:
Thank you
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now