5-5
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter5 Create Firewall
Advanced Firewall Configuration Wizard
Source Host/Network
If you want to allow a single host access through the firewall, choose Host
Address and enter the IP address of a host. Choose Network Address and enter
the address of a network and a subnet mask to allow hosts on that network access
through the firewall. The host or network must be accessible from the interfa ces
that you specified. Choose Any to exempt any host connected to the specified
interfaces from NAC validation.
Advanced Firewall Configuration Wizard
SDM will help you create an Internet firewall by asking you for information about
the interfaces on the router, whether you want to configure a DMZ network, and
what rules you want to use in the firewall.
Click Next to begin configuration.

Advanced Firewall Interface Configuration

Identify the routers inside and outside interfaces and the interface that connects
to the DMZ network.
Check outside or inside to identify each interface as an outside or an inside
interface. Outside interfaces connect to your organizationss WAN or to the
Internet. Inside interfaces connect to your LAN.

DMZ Interface

Select the router interface that connects to a DMZ network, if one exists. A DMZ
network is a buffer zone used to isolate traffic that comes from an untrusted
network. If you have a DMZ network, select the interface that connects to it.