Dmz Deployment - Cisco ASA 5505 Getting Started Manual

Adaptive security appliance
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Chapter 3
Planning a VLAN Configuration

DMZ Deployment

78-18003-02
The only deployments that require three VLANs are those in which there is a
DMZ to protect as well as the Inside network. If you have a DMZ in your
configuration, the DMZ must be on its own VLAN.
Figure 3-3
Deployment Requiring Three VLANs
Adaptive Security
Appliance
Printer
Personal computers
Private
(Inside) Network
In this example, three physical switch ports are allocated to the Inside VLAN, two
switch ports are allocated to the DMZ VLAN, and one switch port is allocated to
the Outside VLAN. Two switch ports are left unused.
Outside Network
(Internet Connection)
Internet
ISP
Router
PO
WE
Cis
48
R
co
VD
C
AS
A SS
C-0
5
7
Sta
tus
POW
Sec
uri
ER
ove
ty
r ETH
Ser
vic
ERN
ET
es
6
Ca
rd
5
Slo
t
4
3
2
co ns
ole
1
0
1
2
RE
SE
T
ASA 5505 Getting Started Guide
Deployment Scenarios Using VLANs
DMZ
Web Server
Email Server
3-7

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents