Adding a firewall for the MC FW which is located on the outside area

Hi all

Is it possible to add a firewall for the FW MC that is located on the external interface of the firewall? If so, what commands do you need on the firewall?

Thank you and best regards,

Hello

In principle might be possible, what need the VMS Svr (FW MC) is a communication channel to the target, the outside Firewall (firewall EXTERNAL) device.

You can try the following, to confrm.

Your topology/flow very probably as follows:

inside intf: EXTERNAL Firewall: ouside intf<->INTERNET CLOUD<->internet router<->router internet<->outside intf:PERIMETER Firewall: inside intf<->VMS:FW MC

A. for the EXTERNAL firewall, configure:

1 activate https & ssh access to/from the server of virtual machines. Access to the Svr VMS must be via a public IP address that mapped to the firewall's PERIMETER server.

2. open access HTTPS & ssh (tcp 443 & 22). SSH may be optional, but you can activate it as well. HTTPS is required to communicate with the virtual Svr computers.

Enable http server

255.255.255.255 out http

2. for ssh, generate a key for the firewall. The condition is as follows:

-set the host name: "abc123 hostname.

-define the domain name: "domain name xyz".

-generate the key: "ca generate rsa key. The button of the module is between 512 and 768, 1024, 2048

-Save the key: "ca save all."

B. for the PERIMETER firewall, configure:

1 static machines card virtual FW MC Svr to address external public IP for firewall mgt traffic

public static xx.xx.xx.10 (Interior, exterior) aa.aa.aa.50 netmask 255.255.255.255

2. open the ACLs on the external interface to the public IP address of external firewalls VM FW MC

outside permit tcp host yy.yy.yy.100 host xx.xx.xx.10 eq https access list

access-list outside allow host yy.yy.yy.100 host xx.xx.xx.10 eq ssh tcp

outside access-group in external interface

* yy.yy.yy.100 is an EXTERNAL firewall outside interface IP

3. by default, the configuration of the VMS OPR statically with a public IP address, it should be able to go internet. But if you have ACLs on the inside interface, you need to enable access to the EXTERNAL firewall via https and ssh (tcp 443 & 22).

inside permit tcp host xx.xx.xx.100 host yy.yy.yy.10 eq https access list

access-list inside allow host xx.xx.xx.100 host yy.yy.yy.10 eq ssh tcp

group-access to the Interior in the interface inside

Also, enable/add ICMP on the two outside & inside to test accessibility for both devices. If you have ACLs on internet router, make sure that you allow the two firewall EXTERNAL and VMS Svr pass-through.

It is a purely theoretical Setup. It may not work or need some changes.

Rgds,

AK

Tags: Cisco Security

Similar Questions

  • update my settings of firewall for the installation of google chrome

    Unlock my firewall for the installation of google chrome settings

    Hi khurrambeg,

    (1) what is the exact cause?
    (2) which is the version of Windows installed on the computer?
    (3) what do you intend to do with the firewall settings on the computer?

    I would like more information about the issue.

    Method-

    I would have you look at the article-

    Suggestions for a question on the help forums

    In addition, you can view the article-

    Open a port in Windows Firewall

    Note: Make sure that you put on the firewall after you have done all the troubleshooting steps.

    Hope this helps!

  • laptop for the mining area

    What is the best laptop for the mining area?

    Ask the mining company.

  • How to connect a scanner of network including the Windows 7 firewall is blocking and adding an exception for the associated program to access the scanned files has no effect?

    Hello

    I have recently upgraded to Windows 7 and the process for adding some of my old material has been an interesting question. Who made me stuck is to be able to access my network scanners "mailboxes shared" in order to recover my scans.

    The product in question is a large format Xerox 6204 printer/scanner. The installation process for the basic print server run the 6204 as a network printer went relatively smoothly and seems to work as expected. However, the problem arises when I want to use the functionality of scan of the 6204. Scans are stored in mailbox store ' ' on the 6204 and must be retrieved by a piece of software Xerox called "wide Format Scan Service. This program essentially connects to mailboxes mailbox via the IP address of the 6204 on the network and from there should allow me to download the scans on my Windows 7 computer. Unfortunately, in order to connect to the mailbox store I am currently disable the firewall of Windows 7 altogether.

    I tried to add the Service to Scan large Format to the list of allowed programs, which gives an "impossible to connect to 6204' error. I tried to add the program to inbound and outbound rules manually, even though my experience with this is limited, with the same error. So leave the default settings in the wizard, I also tried to use the technical netstat to find out what are the ports, the software used and adding them to specific ports in the properties of the rules - all without success.

    For now, I'm stuck the point of having to run my installation of Windows 7 without a firewall to use my scanner large format, which is obviously an undesirable situation. If anyone can offer help or advice on how I can solve this problem it would be greatly appreciated.

    Try this... This solves the problem

    netsh advfirewall set global disable StatefulFTP

  • adding gmail account for the purposes of schedule in Windows 8

    When I try to add my gmail account to the calendar application in Windows 8 on my laptop, I get an error message.  I checked and rechecked the account credentials and everything is correct.  Can someone tell me why it does not work?  Thank you

    Hello

    Thanks for posting your question on the Forums of community of Microsoft.

    According to the description, I see that you are unable to add your gmail account in the calendar app in Windows 8.

    To help you better, please answer these questions:

    1. What is the full error message that you receive?

    2 have you tried to use any other account?

    I suggest you to follow the article to resolve the problem:

    What to do if you have problems with a soft

    http://Windows.Microsoft.com/en-in/Windows-8/what-troubleshoot-problems-app

    Note: Kindly run the app store has provided at the end of the article.

    Check out the link:

    Calendar for Windows application: frequently asked questions

    http://Windows.Microsoft.com/en-in/Windows-8/calendar-FAQ

    For the related issue of Windows or anything related to the Windows operating system, do not hesitate to contact us and we will be happy to help you.

  • Cisco ISA disable antivirus for the specified area

    Hi I want an option to turn analysis antivirus for a specified area.

    'Political IPS and control protocol' has this feature where I can choose what areas to include.

    I noticed that I couldn't update my ps3 and download a 100% and never collapsed. I tried like 5 times.

    After that I have disabled the antivirus download scan went well. But I don't want to disable it for all areas, just the area my ps3 is in.

    Please consider adding this feature to the next version of the firmware.

    BR

    Hello

    Could you try with these two options disabled in the advanced settings of the antivirus?

    (1) disable the HTTP resume

    (2) turn off the FTP resume

    Kind regards

    Wei

  • Configure Manager node for the two areas in weblogic

    Hi friends,

    I'm kinda new to weblogic. I need help to configure nodemanager to two areas.

    I created two areas

    1 Classicdomain

    2 RPMdomain

    For classic field, I created the machine and all the server has added to this machine.

    MachineName: localmachine

    Port: 5556

    Plain

    For RPMdomain I created the machine with the same name and the port and all servers added to this machine.

    I registered both server using nmroll().

    First domain has been configured with nodemanager.

    In the second area, I am not able to start a stop managed server via the console.

    Could someone please let me know how to configure the nodemanager.

    Kind regards

    Prates

    Are able to launch those instances successfully from the command line using the command startManagedWeblogic.sh? Once you have started it, try stopping through the node Manager and then start it upward.

    Also, do you have JSSE enabled in your case and/or disabled hostname verification? These errors indicate fundamentally flawed SSL handshakes with the node Manager.

  • Containment for the toolbar area

    Hi all

    I use the Instrument of toolbar for the first time and I am not successfully keep the toolbar free of windows 'child '.

    I would like to have a toolbar in a parent window that isn't overlappable by a child window. In other words, I looking for a situation similar to CVI environment behaviuor, where the 'children' windows are blocked under the toolbar and have no chance to ride it.

    Any suggestion?

    Thank you

    Sergio

    The design of CVI IDE window is slightly different. In your case, you can restrict the panels of the child to hinder it in the parts of the toolbar in the recall of Panel, as follows:

    public static int CVICALLBACK ChildPanelCallback(int panel, int e, void *cb, int e1, int e2)
    {
    #define MY_TOOLBAR_HEIGHT 50
     
    If (e == EVENT_PANEL_MOVING | e == EVENT_PANEL_SIZING)
    {
    Rect r;
    GetPanelEventRect(e2, &r);)
    If (r.top<>
    {
    r.Top = MY_TOOLBAR_HEIGHT;
    SetPanelEventRect (e2, r);
    }
    }
    return 0;
    }

  • Is it possible to simply exchange the PSU 850w OEM for the inside area 51 R2 OEM 1500w PSU without the entire system rewired?

    I know as a rule of thumb, one should always use the cables provided with a power supply. However, considering that both the 850w & the 1500w are the two Dell OEM power supplies manufactured by the same company to meet identical specifications for the same system, are the cables between the two interchangeable?

    I am interested in buying for my R2 1500w PSU. However, rewiring the entire system seems too complicated. I know I'll bumble, especially since the case is divided and it is not possible to see clearly where all the cables.

    Thanks in advance for any help.

    Yes, but why pay for such a ugly piece of hardware? To replace Delta, PSU with an EVGA is so easy and is a better option. It takes literally 10 minutes to change

    Here is my page on the R2

    http://en.community.Dell.com/Owners-Club/Alienware/f/3746/t/19675279

  • Signed up for the beta area. never had a confirmation email. What now?

    I've never had the confirmation email when I signed up for the beta of the Playbook box.  I am convinced he didn't end up in my spam filter, and the email confirmation for this forum does so very well.  How should I proceed?  Is it possible to send again?  Or is there a reason any he not would not have been sent to all?

    Ahh, nevermind. Just got the confirmation e-mail. I should have been more patient.

  • BlackBerry smartphones update AND EVERYTHING to LOSE! Warnings for the updates are necessary

    I was and am still sort of next to me.

    I received an announcement / notice on my blackberry Curve today that I needed an update, now being the novice user to the technology in the sense of phone I did as he asked. I've updated, woooohoooo, fine, now my phone will be even better, right?

    WRONG!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    I LOST EVERYTHING, MY PHOTOS (3 TAKES JUST 2 HOURS PREVIOUS) MY VIDEOS AND BUSINESS CONTACTS...

    So what I did? Well, first of all, I cried (it has been a month really incredibly bad), so I'm crazy and cussed and almost taken over my van and drove my phone because how I just lost all the evidence, I would need to win in an upcoming trial. I felt that all hope was lost.

    Well, instead of flipping out that I was going I thought ok, I'll call T-Mobile and speak to a REP Smartberry Blackberry, they will know what to do as always, right? Well, it was a loss of 12 minutes on hold. He said once you update, unless you have made a backup on the computer or have a memory card and saved individually for every single photo and video on what then everythings gone.

    I said I just moved last week and a half and have not been able to download my stuff to the computer and don't know where my cord is, besides I said since when do I need to download everything and worry about losing things due to an update. I update my computer all the time and do not lose photos and others.

    He said to update your BlackBerry is like defragment your computer, you will lose information. Well, I guess ignorance is a blessing because I defragment often and have never lost a file. (I know in all cases)

    Anyway that I felt that he put the nail in my coffin, he don't mind not connect me to a 'specialist blackberry' waisting their time when I don't have back up before an update. I tried to inform him that the update didn't state that I could lose all the data, it didn't care. Let's say I was a little rude with my frustrations and hung up.

    And then I contemplated driving on my new phone and then some.

    I then started my own investigations in my phone. I can't tell you how or where I found it exactly. But I found a way to cancel my download and return to my original settings.

    Well, I thought that I is not got nothing else to lose literally so I tried.

    Guess what?

    I'M A HAPPY CAMPER! No mind thanks to you, T-Mobile or Blackberry forums. But my pictures and my video evidence is back.

    And I can tell you this much, as I fear, the new update can puke!

    For the brief time I got it, he stunk. To now record videos of it tells me to insert a memory card, there is already one in there? And it seemed not so good.

    Technicians of Blackberry, creative or what you have, thanks to include a warning to your customers that they SHOULD back UP THEIR DATA before the UPGRADE IF THEY CARE TO KEEP THEIR FILES.

    IT IS IMPARITIVE FOR NOVICE USERS LIKE ME!

    Signed,

    Sighing a slight sigh of relief in Illinois!

    nothappyatall wrote:

    I'm curious. After spending the last two hours of reading more keep me normally never to read on this subject, is implemented one of the creators of Blackberry, updated, or in fact anyone involved in the success of blackberry never consult or contribute to the issues of standard users? Or is their expertise-oriented only to those also knowledgeable than them?

    Hi and welcome to the forums!

    First of all I'm not an employee of or associated products Blackberry, RIM

    I am a user of devices such as you, I

    I'm glad to hear that you did a good job on your phone! Bravo for you!

    I have two questions:

    I see two posts listed for you, both in this thread,

    "I'M A HAPPY CAMPER! The spirit of no thanks to you two T-Mobile or Blackberry forums. "But my pictures and my video evidence is back... »

    You asked for help in another forum or are you referring to this forum of Blackberry?

    Also, please, let us know what version of the Desktop Manager you have, what kind of PC or MAC, and what version of device operating system that you are using. (on the blackberry, click the icon options)

    Scroll to all on the first page, look for the version in this format vX.X.X.XXX... P; lease send it with your Blackberry model, OK? ')?

    Now second question, do you need manuals, software, or procedures? I want to assure you, that you can access all the correct information for other upgrades. If we can help you with any outstanding issues please let me know.

    A point for you to consider in the future. Just because there is a new version of the software whether 3rd party or device OS, you decide when or if you want to install it. If your phone works well, you can install if necessary when you have the time, a good backup and read about it here. If your phone does not work well (come here first) we can help you solve the two problems or say if you need to upgrade you differently.

    Yes, there are some members of staff who stop every day and works behind the scenes and with users in messages, other that expressing the frustration was there any specific information you need of them?  An article on the upgrade, or by using the desktop software?

    Thank you

    Bifocals

  • Adding new partition in the table are

    Hello

    Oracle 9i
    Windows 2003 operating system

    The main entry/exit table is one of the base tables that has a large number of records and a very high success rate, and to avoid poor performance that may occur in such cases, Oracle Table partitioning technique has been examined in the early stages of the implementation of the system.

    Unfortunately, the technique used to divide data based on the year of the transaction considered the year 2010 as the last specific partition, so all records created after this year is gathered in a single partition and this may cause poor performance in the years to come.

    Are required to add another 10 partitions; up to the year 2020 taking into account that the downtime should be close to zero.

    Ground:

    According to my knowledge

    for this, so we can create a new table with the same columns and add required 10 more partitions, and if we take 2 scenarios like

    export/imp
    insertion in the new table select * from < table > old

    What is the best, and if we take exp/imp, if her take a few hours of time to complete a task... what will happen for the updates as insert, update, and delete in this time what will be the impact on the import... I mean if all committed tarnscations... These tarnscations automatically add to the table are not.

    Please tell me what is the best and the tarnscations should not effect... pls tell me how excatly we can complete the task.

    Concerning
    873393

    In my script, I have a DROP TABLE because I'll put up a reproducible demonstration. I can run the script repeatedly and regenerate the same demo data!
    In your environment you would not fall off the table!
    To simplify the demo for you: IGNORE the DROP TABLE command. Pretend it does not exist.

    Hemant K Collette

  • The keyboard shortcuts for the brightness are incorrect in 10.11.4

    Just a mention. Shortcut keys to increase or decrease the brightness are incorrect. They should be F1 and F2.

    F1 and F2 are working correctly. Shortcuts are listed just wrong. And no, I didn't change them.

    Now I don't know if they should even be listed. I checked my MacBook Air and my MacBook, as well running 10.11.4 and shortcuts display 12 "are not listed.

  • Adding missing icon in the notification area of the taskbar

    Volume icon is missing from the notification area of the taskbar.  I did the procedure recommended by accessing the properties, select the notification tab.  Problem is that the check box and the volume of speech can not be selected.  They are grayed out.  How can I reinstall this icon?  Thank you.

    Volume icon is missing from the notification area of the taskbar.  I did the procedure recommended by accessing the properties, select the notification tab.  Problem is that the check box and the volume of speech can not be selected.  They are grayed out.  How can I reinstall this icon?  Thank you.

    Use this tutorial. Depending on the version of Vista, you have, use the method two or three.
    http://www.Vistax64.com/tutorials/106787-notification-area-system-icons.html

    Note: the tutorial is NOT to display the missing icons. It is not gray box so that you can go and check now.

    t-4-2

  • different scheme for the staging area

    Could you please give me a scenario where the transit area must be defined in a different pattern of sources or target

    Hi, even if it is not usual to worm, you have:

    a source file, a picture of RDBMS (oracle, sqlserver, db2...) in your stage area with a transformation and another file in the target.

    a file in your source, a table oracle in your scene and Hyperion Planning and essbase in your target.

    a hyperion planning and essbase in your source, RDBMS in your scene and a file in your target.

    You can even have a file, db2, SQL Server in your source, a join between the 3 sources you RDBMS performance space and a file in your target.

    Also, you may have some file in your source, oracle in your stage of transformation and a db2 into your target.

    Because I normally creates additional steps to manage data, only to have more options can do this whole process into a single interface, but it is possible to have those and many other scenarios to 100%.

    I hope this can help you.

Maybe you are looking for