5-7
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter5 Create Firewall
Advanced Firewall Configuration Wizard

DMZ Service Configuration

Create or edit a DMZ service entry in this window.

Host IP Address

Enter the address range that will specify the hosts in the DMZ that this entry
applies to. The firewall will allow traffic for the specified TCP or UDP service to
reach these hosts.
Start IP Address
Enter the first IP address in the range; for example, 172.20.1.1. If Network
Address Translation (NAT) is enabled, you must enter the NAT-translated address,
known as the inside global address.
End IP Address
Enter the last IP address in the range; for example, 172.20 .1.254. If NAT is
enabled, you must enter the NAT-translated address.
Service
TCP
Click this option if you want to allow traffic for a TCP service.
UDP
Click this option if you want to allow traffic for a UDP service.
Service
Enter the service name or number in this field. If you do n ot know the name or
number, click the button and select the service from the list displayed.
Advanced Firewall Inspection Rule Configuration
Access rules in the firewall may deny return traffic on sessions started inside the
firewall because of the type of service they use. Outgoing traffic can leave the
router, but if return traffic of the same type is not explicitly permitted, it will not
be allowed on the LAN. Inspection rules provide a means to allow such return