Cisco ASA DMZ Configuration Example Design Principle. The network diagram below describes common network requirements in a corporate environment. A Cisco ASA is deployed as an Internet gateway, providing outbound Internet access to all internal hosts. There are four security levels configured on the ASA, LAN, DMZ1, DMZ2 and outside.

Create local VLANs for the Internal and DMZ networks, as shown below. Ensure that the LAN port connecting to the downstream switch is configured to correctly handle the two VLANs. In this case, VLAN 1 (Internal) is native and untagged, while VLAN 2 (DMZ) is tagged.

