Networking
Configuring the DMZ
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
124
4
In this scenario, the business has one public IP address, 209.165.200.225, which is
used for both the security appliance’s public IP address and the web server’s
public IP address. The administrator configures the configurable port to be used
as a DMZ port. A firewall access rule allows inbound HTTP traffic to the web
server at 172.16.2.30. Internet users enter the domain name that is associated with
the IP address 209.165.200.225 and can then connect to the web server. The
same IP address is used for the WAN interface.
Figure 5 Example DMZ with Two Public IP Addresses
In this scenario, the ISP has supplied two static IP addresses: 209.165.200.225
and 209.165.200.226. The address 209.165.200.225 is used for the security
appliance’s public IP address. The administrator configures the configurable port
to be used as a DMZ port and created a firewall access rule to allow inbound
User
192.168.75.10
235610
www.example.com
Internet
Public IP Addresses
209.165.200.225 (router)
209.165.200.226 (web server)
LAN Interface
192.168.75.1
ISA500
DMZ interface
172.16.2.1
Web Server
Private IP Address: 172.16.2.30
Public IP Address: 209.165.200.226
Source Address Translation
209.165.200.226
172.16.2.30
User
192.168.75.11