User's Manual

Table Of Contents
Networking
Configuring the DMZ
Cisco ISA500 Series Integrated Security Appliance Administrator Guide 123
4
Configuring the DMZ
A DMZ (Demarcation Zone or Demilitarized Zone) is a subnetwork that is behind
the firewall but that is open to the public. By placing your public services on a
DMZ, you can add an additional layer of security to the LAN. The public can
connect to the services on the DMZ but cannot penetrate the LAN. You should
configure your DMZ to include any hosts that must be exposed to the WAN (such
as web or email servers).
The DMZ configuration is identical to the VLAN configuration. There are no
restrictions on the IP address or subnet assigned to the DMZ port, except it cannot
be identical to the IP address given to the predefined VLANs.
Figure 4 Example DMZ with One Public IP Address for WAN and DMZ
235140
www.example.com
Internet
Public IP Address
209.165.200.225
ISA500
User
192.168.75.10
LAN Interface
192.168.75.1
DMZ Interface
172.16.2.1
Web Server
Private IP Address: 172.16.2.30
Public IP Address: 209.165.200.225
User
192.168.75.11
Source Address Translation
209.165.200.225 172.16.2.30