<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Gmail and Yahoo not accessible after zbfw implementation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600476#M234355</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have implemented zbfw on Cisco 1800 series router. But after the implementation I could see that Gmail/Yahoo is not loading.Please could some one look into my config and advise. I can access all other websites without any issues.&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ICMP&lt;BR /&gt;&amp;nbsp;match protocol icmp&lt;BR /&gt;class-map type inspect match-all SMTP&lt;BR /&gt;&amp;nbsp;match protocol smtp&lt;BR /&gt;class-map type inspect match-all HTTP-ACCESS&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;class-map type inspect match-all UDP&lt;BR /&gt;&amp;nbsp;match protocol udp&lt;BR /&gt;class-map type inspect match-all HTTPs-ACCESS&lt;BR /&gt;&amp;nbsp;match protocol https&lt;BR /&gt;class-map type inspect match-all TCP&lt;BR /&gt;&amp;nbsp;match protocol tcp&lt;BR /&gt;class-map type inspect match-all DNS&lt;BR /&gt;&amp;nbsp;match protocol dns&lt;BR /&gt;class-map type inspect match-all POP3&lt;BR /&gt;&amp;nbsp;match protocol pop3&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect in-to-out-policy&lt;BR /&gt;&amp;nbsp;class type inspect HTTPs-ACCESS&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;&amp;nbsp;class type inspect HTTP-ACCESS&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect UDP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect TCP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect DNS&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect SMTP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect POP3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect ICMP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;policy-map type inspect out-to-in-policy&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;!&lt;BR /&gt;zone security inside&lt;BR /&gt;zone security outside&lt;BR /&gt;zone-pair security in-to-out source inside destination outside&lt;BR /&gt;&amp;nbsp;service-policy type inspect in-to-out-policy&lt;BR /&gt;zone-pair security out-to-in source outside destination inside&lt;BR /&gt;&amp;nbsp;service-policy type inspect out-to-in-policy&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:57:44 GMT</pubDate>
    <dc:creator>Yadhu Tony</dc:creator>
    <dc:date>2019-03-12T04:57:44Z</dc:date>
    <item>
      <title>Gmail and Yahoo not accessible after zbfw implementation</title>
      <link>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600476#M234355</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have implemented zbfw on Cisco 1800 series router. But after the implementation I could see that Gmail/Yahoo is not loading.Please could some one look into my config and advise. I can access all other websites without any issues.&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ICMP&lt;BR /&gt;&amp;nbsp;match protocol icmp&lt;BR /&gt;class-map type inspect match-all SMTP&lt;BR /&gt;&amp;nbsp;match protocol smtp&lt;BR /&gt;class-map type inspect match-all HTTP-ACCESS&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;class-map type inspect match-all UDP&lt;BR /&gt;&amp;nbsp;match protocol udp&lt;BR /&gt;class-map type inspect match-all HTTPs-ACCESS&lt;BR /&gt;&amp;nbsp;match protocol https&lt;BR /&gt;class-map type inspect match-all TCP&lt;BR /&gt;&amp;nbsp;match protocol tcp&lt;BR /&gt;class-map type inspect match-all DNS&lt;BR /&gt;&amp;nbsp;match protocol dns&lt;BR /&gt;class-map type inspect match-all POP3&lt;BR /&gt;&amp;nbsp;match protocol pop3&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect in-to-out-policy&lt;BR /&gt;&amp;nbsp;class type inspect HTTPs-ACCESS&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;&amp;nbsp;class type inspect HTTP-ACCESS&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect UDP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect TCP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect DNS&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect SMTP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect POP3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect ICMP&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;policy-map type inspect out-to-in-policy&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;!&lt;BR /&gt;zone security inside&lt;BR /&gt;zone security outside&lt;BR /&gt;zone-pair security in-to-out source inside destination outside&lt;BR /&gt;&amp;nbsp;service-policy type inspect in-to-out-policy&lt;BR /&gt;zone-pair security out-to-in source outside destination inside&lt;BR /&gt;&amp;nbsp;service-policy type inspect out-to-in-policy&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600476#M234355</guid>
      <dc:creator>Yadhu Tony</dc:creator>
      <dc:date>2019-03-12T04:57:44Z</dc:date>
    </item>
    <item>
      <title>Hi,I think the configuration</title>
      <link>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600477#M234356</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think the configuration looks good. Would you be able to try to enable logging for dropped packets and see if you see any packets being dropped ?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip inspect log drop-pkt&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Also , as a test , try to change class class-default in policy-map type inspect in-to-out-policy and see if this makes it work ?&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 09:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600477#M234356</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-10-21T09:13:11Z</dc:date>
    </item>
    <item>
      <title>HiI think the problem is</title>
      <link>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600478#M234357</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think the problem is:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;policy-map type inspect in-to-out-policy&lt;BR /&gt;&amp;nbsp;class type inspect HTTPs-ACCESS&lt;BR /&gt;&amp;nbsp; pass&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The HTTPS traffic is allowed out, but the return traffic will be blocked. Gmail is HTTPS, but I would think that any HTTPS website would not work.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 09:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600478#M234357</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2014-10-21T09:29:59Z</dc:date>
    </item>
    <item>
      <title>Hi Thanks for your reply</title>
      <link>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600479#M234358</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Sorry, I have put the &lt;STRONG&gt;pass&lt;/STRONG&gt;&amp;nbsp;command only for testing and wrongly copied the config with that. The actual configuration contain &lt;STRONG&gt;inspect&amp;nbsp;&lt;/STRONG&gt;for HTTPS. It is quite strange that all other HTTPS websites are working without any issue.&lt;/P&gt;&lt;P&gt;We are running&amp;nbsp;version 12.3(8r)YH12 . Would this&amp;nbsp;be the issue?&lt;/P&gt;&lt;P&gt;Appreciate your help on this.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 11:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600479#M234358</guid>
      <dc:creator>Yadhu Tony</dc:creator>
      <dc:date>2014-10-21T11:24:31Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor,Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600480#M234359</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN style="font-size: 14px; background-color: rgb(249, 249, 249);"&gt;Vibhor,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; background-color: rgb(249, 249, 249);"&gt;Thanks for&amp;nbsp;your reply. I doubt whether the issue is due to the IOS version&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 14px;"&gt;12.3(8r)YH12 which is loaded in our router as I could see that Cisco introduced zbfw in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; white-space: pre-wrap;"&gt;12.4(6)T ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I will try &lt;STRONG style="font-size: 14px; background-color: rgb(249, 249, 249);"&gt;ip inspect log drop-pkt&amp;nbsp;&lt;/STRONG&gt;and will let you know the outcome.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; white-space: pre-wrap;"&gt;Many thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 11:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gmail-and-yahoo-not-accessible-after-zbfw-implementation/m-p/2600480#M234359</guid>
      <dc:creator>Yadhu Tony</dc:creator>
      <dc:date>2014-10-21T11:41:18Z</dc:date>
    </item>
  </channel>
</rss>

