I have a DMZ. It is a 2950T hanging off of a firewall interface. I have another 2950T hanging off of that with a wireless access point on it.
What I want to do, and haven't quite figured out yet, is:
- allow access to only 1 IP (preferably on certain ports) in the DMZ subnet, and block access to the other IPs.
-Allow no access to the IP range of our internal network
-Allow access to the Internet.
If it was a router, than there would be no problem. However, there is the nasy restriction of only one subnet mask per ACL.
Similar problems? Suggestions?