Chapter 8 Scenario: DMZ Configuration
Configuring the Adaptive Security Appliance for a DMZ Deployment
8-8
Cisco ASA 5500 Series Getting Started Guide
78-19186-01
2.
The internal client requests a web page from the public IP address of the DMZ
web server. The adaptive security appliance receives the request on its inside
interface.
3.
The adaptive security appliance translates the public IP address of the DMZ
web server to its real address (209.165.200.225 -> 10.30.30.30) and forwards
the request out of its DMZ interface to the web server.
4.
When the DMZ web server responds to the request, the adaptive security
appliance receives the data on its DMZ interface and forwards the data out of
its inside interface to the user.
The procedures for creating this configuration are detailed in the remainder of this
chapter.
Configuring the Adaptive Security Appliance for a
DMZ Deployment
This section describes how to use ASDM to configure the adaptive security
appliance for the configuration scenario shown in
Figure 8-1
. The procedure uses
sample parameters based on the scenario.
This configuration procedure assumes that the adaptive security appliance already
has interfaces configured for the inside interface, the outside interface, and the
DMZ interface. Be sure that the DMZ interface security level is set between 0 and
100. (A common choice is 50.)
Note
If you need to set up interfaces on the adaptive security appliance, you can use the
Startup Wizard in ASDM. For more information about using the Startup Wizard,
see
Chapter 7, “Configuring the Adaptive Security Appliance.”
The section includes the following topics:
•
Configuration Requirements, page 8-9
•
Information to Have Available, page 8-10
•
Enabling Inside Clients to Communicate with Devices on the Internet,
page 8-10
Содержание 5510 - ASA SSL / IPsec VPN Edition
Страница 10: ...Contents x Cisco ASA 5500 Series Getting Started Guide 78 19186 01 ...
Страница 42: ...Chapter 3 Installing the ASA 5550 What to Do Next 3 20 Cisco ASA 5500 Series Getting Started Guide 78 19186 01 ...
Страница 106: ...Chapter 8 Scenario DMZ Configuration What to Do Next 8 24 Cisco ASA 5500 Series Getting Started Guide 78 19186 01 ...
Страница 182: ...Chapter 13 Configuring the AIP SSM What to Do Next 13 16 Cisco ASA 5500 Series Getting Started Guide 78 19186 01 ...