<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi all, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zbf-firewall-and-grc-shieldsup/m-p/3073228#M146522</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The solution was to add the following lines.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;policy-map type inspect Internet_to_Self&lt;BR /&gt;class class-default&lt;BR /&gt;drop&lt;/P&gt;
&lt;P&gt;zone-pair security Internet-&amp;gt;Self source Internet destination self&lt;BR /&gt;service-policy type inspect Internet_to_Self&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This question can be marked as answered.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2017 20:11:27 GMT</pubDate>
    <dc:creator>MJB_Cisco</dc:creator>
    <dc:date>2017-02-14T20:11:27Z</dc:date>
    <item>
      <title>ZBF firewall and GRC ShieldsUP!</title>
      <link>https://community.cisco.com/t5/network-security/zbf-firewall-and-grc-shieldsup/m-p/3073227#M146520</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I moved from a CBAC firewall to a ZBF firewall today on my 1841 and for some reason when I run GRC ShieldsUP it shows all ports as closed instead of stealth as it did with CBAC. Here is my config, can someone point me to what i'm doing wrong? Many thanks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;DIV class="replytext bodytext" data-replyid="52818273" data-uname="mikeyjb77"&gt;
&lt;P&gt;zone security Internet&lt;BR /&gt;zone security Untrusted&lt;BR /&gt;zone security Trusted&lt;/P&gt;
&lt;P&gt;interface Dialer0&lt;BR /&gt;zone-member security Internet&lt;/P&gt;
&lt;P&gt;interface FastEthernet0/0&lt;BR /&gt;zone-member security Trusted&lt;/P&gt;
&lt;P&gt;interface FastEthernet0/1&lt;BR /&gt;zone-member security Untrusted&lt;/P&gt;
&lt;P&gt;class-map type inspect match-any Trusted_Protocols&lt;BR /&gt;match protocol tcp&lt;BR /&gt;match protocol udp&lt;BR /&gt;match protocol icmp&lt;/P&gt;
&lt;P&gt;class-map type inspect match-any Untrusted_Protocols&lt;BR /&gt;match protocol http&lt;BR /&gt;match protocol https&lt;BR /&gt;match protocol dns&lt;/P&gt;
&lt;P&gt;policy-map type inspect Untrusted_to_Internet&lt;BR /&gt;class type inspect Untrusted_Protocols&lt;BR /&gt;inspect&lt;BR /&gt;class class-default&lt;BR /&gt;drop&lt;/P&gt;
&lt;P&gt;policy-map type inspect Trusted_to_Internet&lt;BR /&gt;class type inspect Trusted_Protocols&lt;BR /&gt;inspect&lt;BR /&gt;class class-default&lt;BR /&gt;drop&lt;/P&gt;
&lt;P&gt;zone-pair security Trusted-&amp;gt;Internet source Trusted destination Internet&lt;BR /&gt;service-policy type inspect Trusted_to_Internet&lt;/P&gt;
&lt;P&gt;zone-pair security Untrusted-&amp;gt;Internet source Untrusted destination Internet&lt;BR /&gt;service-policy type inspect Untrusted_to_Internet&lt;/P&gt;
&lt;P class="tripleclick"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:55:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-firewall-and-grc-shieldsup/m-p/3073227#M146520</guid>
      <dc:creator>MJB_Cisco</dc:creator>
      <dc:date>2019-03-12T08:55:51Z</dc:date>
    </item>
    <item>
      <title>Hi all,</title>
      <link>https://community.cisco.com/t5/network-security/zbf-firewall-and-grc-shieldsup/m-p/3073228#M146522</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The solution was to add the following lines.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;policy-map type inspect Internet_to_Self&lt;BR /&gt;class class-default&lt;BR /&gt;drop&lt;/P&gt;
&lt;P&gt;zone-pair security Internet-&amp;gt;Self source Internet destination self&lt;BR /&gt;service-policy type inspect Internet_to_Self&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This question can be marked as answered.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 20:11:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-firewall-and-grc-shieldsup/m-p/3073228#M146522</guid>
      <dc:creator>MJB_Cisco</dc:creator>
      <dc:date>2017-02-14T20:11:27Z</dc:date>
    </item>
    <item>
      <title>Please see the link below it</title>
      <link>https://community.cisco.com/t5/network-security/zbf-firewall-and-grc-shieldsup/m-p/3073229#M146524</link>
      <description>&lt;P&gt;Please see the link below it might help to solve the problem:-&lt;/P&gt;
&lt;P&gt;&lt;A href="https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/51"&gt;https://forum.networklessons.com/t/zone-based-firewall-configuration-example/1024/51&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;#Rate if it helps&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 22:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-firewall-and-grc-shieldsup/m-p/3073229#M146524</guid>
      <dc:creator>Farhan Mohamed</dc:creator>
      <dc:date>2017-02-14T22:13:29Z</dc:date>
    </item>
  </channel>
</rss>

