<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ZoneBased Firewall target:class identified as :none: in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zonebased-firewall-target-class-identified-as-none/m-p/3923530#M24535</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone Based Firewall is dropping packets from one interface to another and I cannot understand why.&lt;/P&gt;&lt;P&gt;1) There is a zone-pair between both interfaces&lt;/P&gt;&lt;P&gt;2) All IP traffic is allowed&lt;/P&gt;&lt;P&gt;3) In the log says (target:class) - (none:none). Not event &lt;U&gt;class-default&lt;/U&gt; is detected. Why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;zone security VPN&lt;/P&gt;&lt;P&gt;zone security USUARIOS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!------------------------&lt;BR /&gt;!VPN=&amp;gt;USUARIOS&lt;BR /&gt;!------------------------&lt;BR /&gt;ip access-list extended VPN-TO-USUARIOS&lt;BR /&gt;&amp;nbsp; &amp;nbsp;permit ip any any&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map type inspect match-all VPN-TO-USUARIOS-CLASS&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match access-group name VPN-TO-USUARIOS&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect VPN-TO-USUARIOS-POLICY&lt;BR /&gt;&amp;nbsp; class type inspect VPN-TO-USUARIOS-CLASS&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;drop log&lt;BR /&gt;!&lt;BR /&gt;zone-pair security VPN-TO-USUARIOS source VPN destination USUARIOS&lt;BR /&gt;&amp;nbsp; &amp;nbsp;service-policy type inspect VPN-TO-USUARIOS-POLICY&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;int Vlan35&lt;BR /&gt;&amp;nbsp; zone-member security VPN&lt;/P&gt;&lt;P&gt;int Gi0/0/1.2&lt;BR /&gt;&amp;nbsp; zone-member security USUARIOS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ip Address&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;GigabitEthernet0/0/1.2 : 10.65.48.1&lt;/P&gt;&lt;P&gt;Vlan35 : 10.68.168.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Drop Log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;002001: Sep 12 07:29:33.212 BRASIL: %IOSXE-6-PLATFORM: SIP1: cpp_cp: QFP:0.0 Thread:000 TS:00000084879874157576 %FW-6-LOG_SUMMARY: 1 udp packet was dropped from &lt;STRONG&gt;Vlan35 10.5.0.64:53 =&amp;gt; 10.65.48.15:61404&lt;/STRONG&gt; &lt;FONT color="#FF0000"&gt;(target:class)-(none:none)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why ZBFW cannot identify target:class? Why is it dropping packets from this source and destination?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Sep 2019 19:57:48 GMT</pubDate>
    <dc:creator>leonardomachado</dc:creator>
    <dc:date>2019-09-12T19:57:48Z</dc:date>
    <item>
      <title>ZoneBased Firewall target:class identified as :none:</title>
      <link>https://community.cisco.com/t5/network-security/zonebased-firewall-target-class-identified-as-none/m-p/3923530#M24535</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zone Based Firewall is dropping packets from one interface to another and I cannot understand why.&lt;/P&gt;&lt;P&gt;1) There is a zone-pair between both interfaces&lt;/P&gt;&lt;P&gt;2) All IP traffic is allowed&lt;/P&gt;&lt;P&gt;3) In the log says (target:class) - (none:none). Not event &lt;U&gt;class-default&lt;/U&gt; is detected. Why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;zone security VPN&lt;/P&gt;&lt;P&gt;zone security USUARIOS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!------------------------&lt;BR /&gt;!VPN=&amp;gt;USUARIOS&lt;BR /&gt;!------------------------&lt;BR /&gt;ip access-list extended VPN-TO-USUARIOS&lt;BR /&gt;&amp;nbsp; &amp;nbsp;permit ip any any&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map type inspect match-all VPN-TO-USUARIOS-CLASS&lt;BR /&gt;&amp;nbsp; &amp;nbsp;match access-group name VPN-TO-USUARIOS&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect VPN-TO-USUARIOS-POLICY&lt;BR /&gt;&amp;nbsp; class type inspect VPN-TO-USUARIOS-CLASS&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;drop log&lt;BR /&gt;!&lt;BR /&gt;zone-pair security VPN-TO-USUARIOS source VPN destination USUARIOS&lt;BR /&gt;&amp;nbsp; &amp;nbsp;service-policy type inspect VPN-TO-USUARIOS-POLICY&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;int Vlan35&lt;BR /&gt;&amp;nbsp; zone-member security VPN&lt;/P&gt;&lt;P&gt;int Gi0/0/1.2&lt;BR /&gt;&amp;nbsp; zone-member security USUARIOS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ip Address&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;GigabitEthernet0/0/1.2 : 10.65.48.1&lt;/P&gt;&lt;P&gt;Vlan35 : 10.68.168.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Drop Log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;002001: Sep 12 07:29:33.212 BRASIL: %IOSXE-6-PLATFORM: SIP1: cpp_cp: QFP:0.0 Thread:000 TS:00000084879874157576 %FW-6-LOG_SUMMARY: 1 udp packet was dropped from &lt;STRONG&gt;Vlan35 10.5.0.64:53 =&amp;gt; 10.65.48.15:61404&lt;/STRONG&gt; &lt;FONT color="#FF0000"&gt;(target:class)-(none:none)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why ZBFW cannot identify target:class? Why is it dropping packets from this source and destination?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 19:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zonebased-firewall-target-class-identified-as-none/m-p/3923530#M24535</guid>
      <dc:creator>leonardomachado</dc:creator>
      <dc:date>2019-09-12T19:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: ZoneBased Firewall target:class identified as :none:</title>
      <link>https://community.cisco.com/t5/network-security/zonebased-firewall-target-class-identified-as-none/m-p/4488868#M1084485</link>
      <description>&lt;P&gt;Did you ever figure this out. I have a similar issue.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 01:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zonebased-firewall-target-class-identified-as-none/m-p/4488868#M1084485</guid>
      <dc:creator>garrettc134</dc:creator>
      <dc:date>2021-10-20T01:29:33Z</dc:date>
    </item>
  </channel>
</rss>

