<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSM - Bug deploying ZoneBased Firewall Rules to Router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401336#M306814</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to deploy ZBFW rules to my router, CSM gives me the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;%No specific protocol or access-group configured in class CSM_ZBF_CLASS_MAP_6 for inspection. All packets will be dropped&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;CSM_ZBF_CLASS_MAP_6 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is also deploying strange commands like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;class-map type inspect match-all CSM_ZBF_CLASS_MAP_4&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; match access-group name ###CMAP_ACLNAME6&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; no match access-group name CSM_ZBF_CMAP_ACL_4&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;exit&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you ever seen it before? Why is it asking about and ACL that does not exist? Why is it issuing strange commands?&lt;/P&gt;&lt;P&gt;I may provide you with further information, if you wish.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:20:46 GMT</pubDate>
    <dc:creator>leonardomachado</dc:creator>
    <dc:date>2019-03-12T03:20:46Z</dc:date>
    <item>
      <title>CSM - Bug deploying ZoneBased Firewall Rules to Router</title>
      <link>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401336#M306814</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to deploy ZBFW rules to my router, CSM gives me the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;%No specific protocol or access-group configured in class CSM_ZBF_CLASS_MAP_6 for inspection. All packets will be dropped&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;CSM_ZBF_CLASS_MAP_6 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is also deploying strange commands like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;class-map type inspect match-all CSM_ZBF_CLASS_MAP_4&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; match access-group name ###CMAP_ACLNAME6&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; no match access-group name CSM_ZBF_CMAP_ACL_4&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;exit&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you ever seen it before? Why is it asking about and ACL that does not exist? Why is it issuing strange commands?&lt;/P&gt;&lt;P&gt;I may provide you with further information, if you wish.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:20:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401336#M306814</guid>
      <dc:creator>leonardomachado</dc:creator>
      <dc:date>2019-03-12T03:20:46Z</dc:date>
    </item>
    <item>
      <title>CSM - Bug deploying ZoneBased Firewall Rules to Router</title>
      <link>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401337#M306816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Leonardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will never recommend to do any Firewall Configuration via SDM, CCP or SDM. Things will just not work as they should (All of this based on my experience).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen both of them in the past.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend to provide us the config and then we will tell you if we see something strange but try to do this via CLI (Trust me, U need this)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Dec 2013 01:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401337#M306816</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-21T01:02:25Z</dc:date>
    </item>
    <item>
      <title>CSM - Bug deploying ZoneBased Firewall Rules to Router</title>
      <link>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401338#M306819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But that is the main reason of CSM product existence! It should centralize security configuration. I have 40 routers to manage and I definitely cannot manage Zone Based Firewall and ACL via CLI in this scenario. I have never faced any problem with ASDM while managing my ASA and FWSM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Dec 2013 11:05:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401338#M306819</guid>
      <dc:creator>leonardomachado</dc:creator>
      <dc:date>2013-12-24T11:05:31Z</dc:date>
    </item>
    <item>
      <title>CSM - Bug deploying ZoneBased Firewall Rules to Router</title>
      <link>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401339#M306820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So my answer was sort of useful hahaha.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration of ZBFW is pretty complex and involves the definition of multiple parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said my recommendation will always be do it from CLI, if you do not know how or need assitance with that then get Cisco TAC on the line or get someone that knows about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the first log you posted&amp;nbsp; I have seen it in the past when using an ACL to match traffic and have not cause any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now for this:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;class-map type inspect match-all CSM_ZBF_CLASS_MAP_4&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;match access-group name ###CMAP_ACLNAME6&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;no match access-group name CSM_ZBF_CMAP_ACL_4&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;exit&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's just removing the use of an ACL to then match another traffic with a different ACL so not big deal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to detemrine whether the configuration is good or not is to analize the entire configuration with what you are trying to do!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Dec 2013 17:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401339#M306820</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-24T17:06:14Z</dc:date>
    </item>
    <item>
      <title>CSM - Bug deploying ZoneBased Firewall Rules to Router</title>
      <link>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401340#M306822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem was that INSPECT rules need INSPECT protocols to be specified ! Otherwise it must me PASS flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion it's a bug or bad programing in CSM interface. If inspect NEED a protocol it should be forced to input this information before deploying it!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, thks for helping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 13:29:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csm-bug-deploying-zonebased-firewall-rules-to-router/m-p/2401340#M306822</guid>
      <dc:creator>leonardomachado</dc:creator>
      <dc:date>2014-02-19T13:29:23Z</dc:date>
    </item>
  </channel>
</rss>

