Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

DNS Inquiry

Status
Not open for further replies.

rtiv

IS-IT--Management
Mar 12, 2002
142
US
My external W2K DNS server sits in a DMZ. Can someone tell me what other ports aside from TCP/UDP 53 (DNS) need to be opened up on my PIX firewall going from my DMZ to the internal network?

Thanks
 
HI.

You don't need to open any specific port for traffic from DMZ to internal network.
You only need to define "nat" and "global" commands for translation. The same "nat 1" command used for inside to outside traffic can be used, so all you need is a
global (dmz) 1 ...

No ACL is needed because of the pix default behaviour that allows traffic from inside to dmz and the return traffic by statefull inspection.

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top