Cisco SA520-K9 Administration Guide - Page 65

Networking, Configuring a Firewall Rule for, Inbound Traffic, Reserved IPs,

Page 65 highlights

Networking Configuring a DMZ 2 • Starting IP Address and Ending IP Address: Enter the range of addresses in the IP address pool for this security appliance. Any new DHCP client that joins the DMZ is assigned an IP address in this range. • Primary DNS Server and Secondary DNS Server (Optional): Enter the IP address of the primary DNS server for the DMZ. Optionally, enter the IP address of a secondary DNS server. • Primary Tftp Server and Secondary Tftp Server (Optional): Enter the IP address of the primary and secondary Tftp servers for the DMZ • WINS Server (Optional): Enter the IP address for the WINS server or, if present in your network, the Windows NetBios server. • Lease Time: Enter the maximum connection time in hours that a dynamic IP address is "leased" to a network user. When the time elapses, the user is automatically assigned a new dynamic IP address. The default is 24 hours. • Relay Gateway: If you chose DHCP Relay as the DHCP mode, enter the IP address of the relay gateway. STEP 5 In the DMZ Proxies section, check the box to allow the DMZ to act as a proxy for all DNS requests and to communicate with the DNS servers of the ISP. When this feature is disabled, all DHCP clients on the DMZ receive the DNS IP addresses of the ISP. STEP 6 Click Apply to save your settings. NOTE Next steps: • If you are using the Getting Started (Advanced) page, click Getting Started > Advanced to continue with the list of configuration tasks. • Required: You must configure a firewall rule to allow inbound traffic to access your DMZ. Also use the firewall rule to specify a public IP address for a server on your DMZ, if applicable. To get started, click Firewall on the menu bar. For more information, see Configuring a Firewall Rule for Inbound Traffic, page 110. • If you want to reserve certain IP addresses for specified devices, click Optional Port > DMZ Reserved IPs. For more information, see DMZ Reserved IPs, page 66. Cisco SA500 Series Security Appliances Administration Guide 65

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Networking
Configuring a DMZ
Cisco SA500 Series Security Appliances Administration Guide
65
2
Starting IP Address
and
Ending IP Address
: Enter the range of addresses
in the IP address pool for this security appliance. Any new DHCP client that
joins the DMZ is assigned an IP address in this range.
Primary DNS Server
and
Secondary DNS Server (Optional)
: Enter the IP
address of the primary DNS server for the DMZ. Optionally, enter the IP
address of a secondary DNS server.
Primary Tftp Server
and
Secondary Tftp Server (Optional)
: Enter the IP
address of the primary and secondary Tftp servers for the DMZ
WINS Server (Optional):
Enter the IP address for the WINS server or, if
present in your network, the Windows NetBios server.
Lease Time:
Enter the maximum connection time in hours that a dynamic IP
address is “leased” to a network user. When the time elapses, the user is
automatically assigned a new dynamic IP address. The default is 24 hours.
Relay Gateway:
If you chose DHCP Relay as the DHCP mode, enter the IP
address of the relay gateway.
STEP
5
In the
DMZ Proxies
section, check the box to allow the DMZ to act as a proxy for
all DNS requests and to communicate with the DNS servers of the ISP. When this
feature is disabled, all DHCP clients on the DMZ receive the DNS IP addresses of
the ISP.
STEP
6
Click
Apply
to save your settings.
NOTE
Next steps:
If you are using the Getting Started (Advanced) page, click
Getting Started
> Advanced
to continue with the list of configuration tasks.
Required:
You must configure a firewall rule to allow inbound traffic to
access your DMZ. Also use the firewall rule to specify a public IP address
for a server on your DMZ, if applicable. To get started, click
Firewall
on the
menu bar. For more information, see
Configuring a Firewall Rule for
Inbound Traffic, page 110
.
If you want to reserve certain IP addresses for specified devices, click
Optional Port > DMZ Reserved IPs
. For more information, see
DMZ
Reserved IPs, page 66
.