Chapter8 Create Firewall
Advanced Firewall Configuration Wizard
8-6
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Check outside or inside to identify each interface as an outside or an inside
interface. Outside interfaces connect to your organizations’s WAN or to the
Internet. Inside interfaces connect to your LAN.

Allow secure Cisco SDM access from outside interfaces checkbox

Check this box if you want users outside the firewall to be able to access the router
using Cisco SDM. The wizard will display a screen that allows you to specify a
host IP address or a network address. The firewall will be modified to allow access
to the address you specify. If youspecify a network address, all hosts on that
network willbe allowed through the firewall.

DMZ Interface

Select the router interface that connects to a DMZ network, if one exists. A DMZ
network is a buffer zone used to isolate traffic that comes from an untrusted
network. If you have a DMZ network, select the interface that connects to it.
Advanced Firewall DMZ Service Configuration
This window allows you to view rule entries that specify which services available
inside the DMZ you want to make available through the router’s outside
interfaces. Traffic of the specified service types will be allowed through the
outside interfaces into the DMZ network.

DMZ Service Configuration

This area shows the DMZ service entries configured on the router.
Start IP Address
The first IP address in the range that specifies the hosts in the DMZ network.
End IP Address
The last IP address in the range that specifies the hosts in the DMZ network. If
there is no value listed in this column, the IP address in the Start IP address
column is presumed to be the only host in the DMZ network. The range can
specify a maximum of 254 hosts.