An Inside User Visits a Web Server on the DMZ
Figure 15-4 shows an inside user accessing the DMZ web server.
Figure 15-4 Inside to DMZ
Figure 15-4 Inside to DMZ

- User Web Server
The following steps describe how data moves through the security appliance (see Figure 15-4):
1. A user on the inside network requests a web page from the DMZ web server using the destination address of 10.1.1.3.
2. The security appliance receives the packet and because it is a new session, the security appliance verifies that the packet is allowed according to the terms of the security policy (access lists, filters, AAA).
For multiple context mode, the security appliance first classifies the packet according to either a unique interface or a unique destination address associated with a context; the destination address is associated by matching an address translation in a context. In this case, the interface is unique; the web server IP address does not have a current address translation.
3. The security appliance then records that a session is established and forwards the packet out of the DMZ interface.
4. When the DMZ web server responds to the request, the packet goes through the fast path, which lets the packet bypass the many lookups associated with a new connection.
5. The security appliance forwards the packet to the inside user.
An Outside User Attempts to Access an Inside Host
Figure 15-5 shows an outside user attempting to access the inside network. Figure 15-5 Outside to Inside
www.example.com
Figure 15-5 shows an outside user attempting to access the inside network. Figure 15-5 Outside to Inside
www.example.com

- 10.1.2.27
The following steps describe how data moves through the security appliance (see Figure 15-5):
1. A user on the outside network attempts to reach an inside host (assuming the host has a routable IP address).
If the inside network uses private addresses, no outside user can reach the inside network without NAT. The outside user might attempt to reach an inside user by using an existing NAT session.
2. The security appliance receives the packet and because it is a new session, the security appliance verifies if the packet is allowed according to the security policy (access lists, filters, AAA).
3. The packet is denied, and the security appliance drops the packet and logs the connection attempt.
If the outside user is attempting to attack the inside network, the security appliance employs many technologies to determine if a packet is valid for an already established session.
A DMZ User Attempts to Access an Inside Host
Figure 15-6 shows a user in the DMZ attempting to access the inside network.
Figure 15-6 DMZ to Inside
Figure 15-6 DMZ to Inside
User Web Server
User Web Server
The following steps describe how data moves through the security appliance (see Figure 15-6):
1. A user on the DMZ network attempts to reach an inside host. Because the DMZ does not have to route the traffic on the internet, the private addressing scheme does not prevent routing.
2. The security appliance receives the packet and because it is a new session, the security appliance verifies if the packet is allowed according to the security policy (access lists, filters, AAA).
3. The packet is denied, and the security appliance drops the packet and logs the connection attempt.
Continue reading here: Passing Traffic Not Allowed in Routed Mode
Was this article helpful?