<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone based firewall setup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996665#M132409</link>
    <description>Hi,&lt;BR /&gt;This link refers to traffic zones within ASA code. This allows you to assign multiple interfaces to a traffic zone, which lets traffic from an existing flow exit or enter the ASA on any interface within the zone. Zones on the ASA does not work the same as they do on Juniper firewalls.&lt;BR /&gt;&lt;BR /&gt;If you are licensed to run FTD code on the ASA hardware, the FTD does allow you to assign interfaces to security Zones, you can then use the zecurity zones within the Access Control Policy. This would be similar to configuring Juniper firewalls.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
    <pubDate>Tue, 10 Dec 2019 17:14:18 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-12-10T17:14:18Z</dc:date>
    <item>
      <title>Zone based firewall setup</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996243#M132390</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I have &lt;STRONG&gt;Cisco ASA 5525-X&lt;/STRONG&gt; with following images&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;STRONG&gt;asa922-4-smp-k8&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;STRONG&gt;asdm 7.2(2)1&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333399"&gt;&lt;STRONG&gt;asasfr-5500x-boot-5.4.0&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to deploy the firewall in Datacentre environment. For this purpose , i want to create zones/zone pairs and assign interfaces to different zones, and apply bi-directional policies to control traffic. With my past experience of Juniper Netscreen/SRX firewalls , doing all this was so simple and straight forward. But i am unable to find any commands relevant to Zone based configuration in&amp;nbsp; my current setup. Do i need image upgrade or something else?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 06:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996243#M132390</guid>
      <dc:creator>AZKhan</dc:creator>
      <dc:date>2019-12-10T06:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall setup</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996263#M132400</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;The cisco equivalent Zone Based Firewall is a feature found on cisco routers not ASAs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ASA uses the concept of security level (0 - 100) applied to routed interfaces. There is an implicit permit of traffic from a higher level to a lower level in the absence of ACLs. On an SRX you would group IRBs under the same zone, on an ASA something similar could be achieved by having a set of SVIs all have the same security level and configuring&amp;nbsp;&lt;STRONG&gt;same-security-traffic permit&amp;nbsp;inter-interface .&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 07:36:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996263#M132400</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2019-12-10T07:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall setup</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996632#M132405</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324976"&gt;@Seb Rupik&lt;/a&gt;&amp;nbsp;, Thanks for reply. Someone have suggested me to follow the given below link, which shows that Zones could be configure in ASA.&amp;nbsp;&lt;/P&gt;&lt;H1&gt;CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide, 9.3&lt;/H1&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-zones.html#65622" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/general/asa-general-cli/interface-zones.html#65622&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Visiting this link and going through all the config, i haven't found even these commands on my ASA 5525X.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am really confused, what to do now?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 16:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996632#M132405</guid>
      <dc:creator>AZKhan</dc:creator>
      <dc:date>2019-12-10T16:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall setup</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996665#M132409</link>
      <description>Hi,&lt;BR /&gt;This link refers to traffic zones within ASA code. This allows you to assign multiple interfaces to a traffic zone, which lets traffic from an existing flow exit or enter the ASA on any interface within the zone. Zones on the ASA does not work the same as they do on Juniper firewalls.&lt;BR /&gt;&lt;BR /&gt;If you are licensed to run FTD code on the ASA hardware, the FTD does allow you to assign interfaces to security Zones, you can then use the zecurity zones within the Access Control Policy. This would be similar to configuring Juniper firewalls.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 10 Dec 2019 17:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996665#M132409</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-12-10T17:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall setup</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996975#M132411</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oohh, It mean mine ASA is just a box, cannot use it as a firewall at all. Even the security Zones config need licenses. As compare to Juniper Netscreen/SRX and Fortinet Fortigate, its not gonna help in creating security zones.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will FTD replace the current ASA image? or it will run in parallel and just increase the security capabilities of the ASA?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 06:38:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-setup/m-p/3996975#M132411</guid>
      <dc:creator>AZKhan</dc:creator>
      <dc:date>2019-12-11T06:38:15Z</dc:date>
    </item>
  </channel>
</rss>

