8-5
Cisco ASA 5500 Series Getting Started Guide
78-19186-01
Chapter 8 Scenario: DMZ Configuration
Example DMZ Network Topology
Figure 8-3
An Outside User Visits the DMZ Web Server
When a user on the Internet requests an HTTP page from the DMZ web server,
traffic flows through the adaptive security appliance as follows:
1.
A user on the outside network requests a web page from the DMZ web server
using the public IP address of the adaptive security appliance
(209.165.200.225, the IP address of the outside interface).
2.
The adaptive security appliance receives the packet and, because it is a new
session, verifies that the packet is allowed.
U
s
er
192.16
8
.1.2
In
s
ide
DMZ
191
8
00
www.ex
a
mple.com
Internet
P
ub
lic IP Addre
ss
209.165.200.225
(o
u
t
s
ide interf
a
ce)
In
s
ide interf
a
ce
192.16
8
.1.1
DMZ interf
a
ce
10.
3
0.
3
0.1
We
b
S
erver
Priv
a
te IP Addre
ss
: 10.
3
0.
3
0.
3
0
P
ub
lic IP Addre
ss
: 209.165.200.225
De
s
tin
a
tion Addre
ss
Tr
a
n
s
l
a
tion
209.165.200.225
10.
3
0.
3
0.
3
0