<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You can use a class-map that in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855997#M158135</link>
    <description>&lt;P&gt;You can use a class-map that references an ACL. This ACL allows the traffic to the real IP/Port of the server.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2016 09:54:57 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2016-03-31T09:54:57Z</dc:date>
    <item>
      <title>Help in configuring zone based firewall</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855996#M158133</link>
      <description>&lt;P&gt;Can anybody help me in configuring the following?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a router with zone based firewall configured.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have the following port redirect:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;ip nat inside source static tcp 192.168.1.100 80 172.24.10.100 8888 extendable&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;172.24.10.x is my pool of outside addresses.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;I need to reach the server 192.168.1.100:80 from any outside address &amp;nbsp; &amp;nbsp;(by the address 172.24.10.100:8888 )&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;which class map type inspect do I have to configure?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Thanks&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Johnny&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855996#M158133</guid>
      <dc:creator>l.buschi</dc:creator>
      <dc:date>2019-03-12T07:33:39Z</dc:date>
    </item>
    <item>
      <title>You can use a class-map that</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855997#M158135</link>
      <description>&lt;P&gt;You can use a class-map that references an ACL. This ACL allows the traffic to the real IP/Port of the server.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 09:54:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855997#M158135</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-03-31T09:54:57Z</dc:date>
    </item>
    <item>
      <title>do you mean the following?</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855998#M158137</link>
      <description>&lt;P&gt;do you mean the following?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list 101 permit tcp any host 192.168.1.100 eq 80&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;in the policy map do I have to put an inspect or a pass statement?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Johnny&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 10:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855998#M158137</guid>
      <dc:creator>l.buschi</dc:creator>
      <dc:date>2016-03-31T10:10:40Z</dc:date>
    </item>
    <item>
      <title>Yes, the ACL is ok, although</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855999#M158138</link>
      <description>&lt;P&gt;Yes, the ACL is ok, although I would use a named ACL.&lt;/P&gt;
&lt;P&gt;The action "pass" is for unidirectional flows. If you want that your server&amp;nbsp;can send answers back to the client (probably yes &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ) then you need to "inspect" that traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 10:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-zone-based-firewall/m-p/2855999#M158138</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-03-31T10:17:44Z</dc:date>
    </item>
  </channel>
</rss>

