|
Can't access devices in DMZ
Symptoms: The client installed Windows 2008 server as firewall to protect
their network in DMZ. In their Cisco ASA firewall between LAN and DMZ, there
is a rule to allow LAN users to access the computers in DMZ. It used to
work. After they setup the RAS server, the Internet user can access the
Windows 2008 server using RDP from outside but not LAN users can't access
the same server from the LAN.
Cause: The DMZLAN is setup without default gateway and the server use WAN
as default gateway. Since the DMZLAN has not router return so that no remote
network device can access DMZLAN. If we add the default gateway to DMZLAN,
then we can access it.
Similar case can be found here:
Re: Solved: Black screen when accessing TS using RDC.
Note: If we add default gateway to the DMZLAN, it will work, but it is
not recommended because we don't recommend to run a server with two default
gateways. Also the server is setup as firewall and DMZLAN as private LAN. If
we assign default gateway to DMZLAN, that will open door for public.
Contact a consultant
Related Topics
|