My external W2K DNS server sits in a DMZ. Can someone tell me what other ports aside from TCP/UDP 53 (DNS) need to be opened up on my PIX firewall going from my DMZ to the internal network?
You don't need to open any specific port for traffic from DMZ to internal network.
You only need to define "nat" and "global" commands for translation. The same "nat 1" command used for inside to outside traffic can be used, so all you need is a
global (dmz) 1 ...
No ACL is needed because of the pix default behaviour that allows traffic from inside to dmz and the return traffic by statefull inspection.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.