Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Configuring Firewall with LAN with private IPs and DMZ with public IPs

Hello

I want to configure my Firewall to have a private LAN with private IP Addresses and a DMZ Zone with our public range (255.255.255.224).

In the public zone it must be possible to reach the devices directly by public IP address and to connect via VPN to have access to data in a secure way.

How it could be done?

I created a simple picture for illustration.

Thank you for replying.

Regards

Chris



This thread was automatically locked due to age.
Parents Reply Children
  • I can't even ping the gateway, let alone an upstream address like Google's 8.8.8.8.

    I have tried with routing enabled, and with routing disabled--though I assume that 'enabled' is what it should be set at. Before I create the bridge (that is, just a LAN and WAN interface) pings and DNS resolution work fine from the LAN segment. The bridge bungles it all.

    This is on an ESXi VM, with the LAN and DMZ connected to isolated vSwitch networks.

    -----------------------
    SG210/UTM 9.407-3

  • Chris,

         I can confirm functionality of this does work with creating the interface bridge and selecting both the WAN and DMZ zones with routing enabled on the bridged interface pair. lferrara has a good suggestion for splitting up your IP blocks, however if you need all of your public IP's why not just assign your servers private IP's, put them on a different subnet in the DMZ and just create the NAT's to the DMZ using the Business Application Firewall Rule's? 

    -Alan

  • I have resolved my issue. Because I am testing XG in a VMware ESXi VM, I needed to enable Forged Transmits and Promiscuous mode on the vSwitch attached to my WAN interface. Once these changes were made, the WAN-DMZ bridge started forwarding traffic as desired.

    I hope this helps others, and thanks to all who responded on this issue.

    -----------------------
    SG210/UTM 9.407-3

  • Matthew,

    nice to know you have fixed it. On Community you find other article on how to deploy UTM and XG (bridge mode) inside Vmware.

    [:D]