Three Interface Configuration with DMZ

router(config)# router(config)# router(config)# router(config)# router(config)# router(config)# router(config)# router(config)# router(config)# router(config)# router(config)# router(config)#

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

ip

inspect

name

IN_to_OUT smtp IN_to_OUT ftp IN_to_OUT tcp IN_to_OUT udp IN_to_OUT sqlnet IN_to_OUT realaudio IN_to_OUT h323 OUT_to_IN tcp OUT_to_IN ftp OUT_to_IN vdolive OUT_to_IN netshow OUT to IN h323

■ IN_to_OUT is configured for traffic destined for the internet or the DMZ. Inspection is configured inbound on the inside interface (Fa0/0)

■ OUT_to_IN is setup for traffic heading from the internet. This traffic can go ONLY to the dMz. Inspection is configured inbound on the outside interface (S0)

© 2007 Cisco Systems, Inc. All rights reserved SNRS V2.0—5-1E

The example above specifies the protocols to be inspected using two different inspection rules that will be applied to two interfaces.

The IN_to_OUT inspection rule instructs the firewall to inspect smtp, ftp, tcp, usdp, sqlnet, realausdio, and H323 coming from the internal network that is exiting.

The OUT_to_IN inspection rule will inspect traffic coming from the Internet and bound for the DMZ.

Securing Networks with Cisco Routers and Switches (SNRS) v2.0

5-54

Three Interface Configuration with DMZ (Cont.)

router(config)# access-list 101 deny ip any any router(config)# access-list 111 permit udp host 192.168.1.11 any eq domain router(config)# access-list 112 permit tcp any host 192.168.1.12 eq www router(config)# access-list 112 permit tcp any host 192.168.1.12 eq ftp router(config)# access-list 112 permit tcp any host 192.168.1.12 eq smtp router(config)# access-list 112 permit tcp any host 192.168.1.12 eq 1755

router(config)# access-list 112 permit tcp any host 192.168.1.12 eq 1720

router(config)# access-list 121 permit tcp any host 192.168.1.12 eq www router(config)# access-list 121 permit tcp any host 192.168.1.12 eq ftp router(config)# access-list 121 permit tcp any host 192.168.1.12 eq smtp router(config)# access-list 121 permit tcp any host 192.168.1.12 eq 1755

router(config)# access-list 121 permit tcp any host 192.168.1.12 eq 1720

• ACL 101 locks down traffic heading to the inside.

• ACL 111 permits DNS requests from the DNS server on the DMZ.

• ACL 112 permits internet traffic inspected by the firewall destined to the DMZ.

• ACL 121 corresponds to acl 112. it allows internet traffic inspected by the firewall to the server on the DMZ.

©2007 Cisco Systems, Inc. All rights reserved. SNRS v2.0—5-19

The example above defines the access lists that will be applied to the appropriate interfaces to control access in and out of the network.

Note the following:

■ ACL 101 is usually called the "lock down" ACL because it should deny all traffic that is not being inspected to enter the network. ACL 101 will be applied to the internal interface in the outbound direction in this case.

■ ACL 111 is applied to the DMZ interface in the inbound direction. ACL 111 allows DNS traffic from the web server in the DMZ to the Internet.

■ ACL 112 is applied to the DMZ interface in the outbound direction. ACL 112 allows traffic from the Internet to the DMZ.

■ ACL 121 is applied to inbound traffic on the outside interface (s0/0). ACL 121 corresponds to acl 112, it allows internet traffic inspected by the firewall to the server on the DMZ.

© 2007 Cisco Systems, Inc. Adaptive Threat Defense 5-55

Three Interface Configuration with DMZ (Cont.)

Fa0/0 is the inside interface to the Corp network.

router(config)# interface fastEthernet0/0 | Lock-down router(config-if)# ip address 10.0.1.2 255.2 router(config-if)# ip access-group 101 out

router (config-if)# ip inspect IN to OUT ii firewall ¡nspection

3 for internally generated traffic

S0/0 is the interface closest to the internet. The outside interface.

router(config)# interface Serial0

router (config-if)# ip address 172.30.1.2 2 55.255.255.1 allows internet router(config-if)# ip access-group 121 in initiated traffic router(config-if)# ip inspect OUT_to_IN in ^ ___I

firewall inspection for traffic coming from the internet

Fa0/1 is the DMZ interface. router(config)# interface fastEthernet0/1 router(config-if)# ip address 192.168.1.2 255.255.255.0 router(config-if)# ip access-group 111 in —^^^^^^^^ DNS traffic router(config-if)# ip access-group 112 out allows specific traffic to the DMZ server.

©2007 Cisco Systems, Inc. All rights reserved.SNRS v2.0—5-20

The two inspection rules and all of the ACLs are applied to the appropriate interfaces in the example above.

Note the following:

■ Interface Fa0/0 (the inside interface) has ACL 101 applied outbound and the inspection rule applied inbound.

■ Interface Serial 0 (the outside interface) has ACL 121 applied inbound from Internet and the inspection rule also applied inbound.

■ Interface Fa0/1 (the DMZ interface) has no inspection rule applied but has two ACLs applied both inbound and outbound to restrict access to and from the Internet and the DMZ.

Securing Networks with Cisco Routers and Switches (SNRS) v2.0

5-56

Continue reading here: Application Firewall Policy for HTTP

Was this article helpful?

0 0

Readers' Questions

  • tiblets fesahaye
    Which dmz configuration uses one firewall with three interfaces?
    8 months ago
  • A single firewall with three interfaces can be used to configure a perimeter network, or DMZ, which serves as a buffer between the internal network and the external network (Internet). The firewall's three interfaces are typically configured as Internal, DMZ, and External. All traffic between the internal network and the external network must pass through the firewall, and can only be allowed or denied based on the firewall's security rules.