LAN to DMZ

Hi All I need your inputs with this, thanks in advance for the inputs.

I have a device (sophos UTM 9) as you can see above we have a lan and DMZ set on different NIC on the device.

the problem is I can connect from DMZ to LAN Physical Server but I cannot connect vice versa.

hope you can help me guys with this

  • Hi Jessie,

    can you activate the log of your firewall rule and show us the log entry of the connection you trying to establish?

    Best Regards
    DKKDG

  • In reply to DKKDG:

    Hi Dk 

    Please see below image

  • In reply to Jessie Earl ClarenceNotarte1:

    Hi Jessie,

    I do not see the accepted Packet from 192.168.20.254 to 10.10.0.251.

    Are you sure the routing for the network 10.10.0.0 is correct?
    Have you intrusion prevention enabled?

    Best Regards
    DKKDG

  • In reply to DKKDG:

    Hi Dk Thanks for reply.

    1. that's why I'm not getting it i as you can see I allow the both to ping each other. how come that the LAN cannot ping the 10.10.0?

    2. what routing are your referring? kindly check if my setup for interfaces is correct 

    3.yes IP is enabled

     

  • In reply to Jessie Earl ClarenceNotarte1:

    Hi Jessie,

    I mean the routing of ther Server 192.168.20.254.

    When Intrusion Prevention is enabled did you see any entries there?

    The configuration of the interface for 192.168.20.1 seems to be incorrect.
    In your drawing you say that 192.168.20.1 is eth1 here in the screenshot it is eth0.

    Best Regards
    DKKDG

  • I agree with DKKDG, Jessie, that this feels like a routing problem on the server.  Do a route print on the server and paste here the line related to your DMZ.

    Cheers - Bob