Solved

ASA Firewall Access Rule for Web Servers

Posted on 2014-12-24
5
60 Views
Last Modified: 2015-11-07
In ASA 5520 I have configured an Access Rule so that outside client can reach the Webserver in the DMZ. It worked with no problem. However , so far I have only one Webserver in the DMZ and the access rule is permitting from outside to the destination (Webserver object) which has an IP address 10.10.10.20
In real world there should be redundant Webservers in the DMZ, so that they can "Load Balance" the load.
I wonder if I need to create separate Access Rule for each Webserver or there is a simpler way to do it ?

Any help will be very much appreciated.

Thank you

dmz
0
Comment
Question by:jskfan
  • 3
5 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 250 total points
ID: 40516905
The firewall is not a load balancer, if you want load balancing buy a load balancer?

You would need to set each web server with its own public IP address then you could load balance using DNS round robin.

Or if you are using  server 2012 - you could reverse proxy and use NLB.


Pete
0
 

Author Comment

by:jskfan
ID: 40517004
Sorry...
I am not saying I need to Load balance with Firewall.

Usually companies do not use just one web server in the DMZ. They use a bunch of them and I believe in DNS they create CNAME so that all webservers will have the same name but different IP addresses...

Well... the way I configured ASA in the LAB, was not complicated because I just allowed HTTP from outside to go to that single webserver IP address. in the case when there are several webservers, how do you change the access rules so that it will apply to all webservers in the DMZ?
hope the Question is clear now..
0
 
LVL 50

Accepted Solution

by:
Don Johnston earned 250 total points
ID: 40517044
Usually companies do not use just one web server in the DMZ. They use a bunch of them and I believe in DNS they create CNAME so that all webservers will have the same name but different IP addresses...
I believe that what you're referring to is "content switching".
0
 

Author Comment

by:jskfan
ID: 40517689
PeteLong:

in your comment above you mentioned Load Balancer, I believe that would work if you put it in the DMZ (Of course), that way you Load balance between WebServers, and the WebServers will have a common Virtual IP address.
I believe that Virtual IP address is the IP address that will be used in ASA Firewall Access Rule. It makes more sense to me this way.
0
 

Author Closing Comment

by:jskfan
ID: 41205064
Thank you
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
SSL RA VPN 7 78
Cisco Layer 2 Switches 6 52
Network Config 9 58
Cisco CUCM 10.5: password recovery 2 9
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now