<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ip inspect name -Router interface does not gets ip from ISP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244246#M350873</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add this to your config because by default CBAC won't inspect traffic generated by the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER dns &lt;STRONG&gt; router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER ntp&amp;nbsp; &lt;STRONG&gt;router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER bootps &lt;STRONG&gt;router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER bootpc&lt;STRONG&gt; router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Apr 2013 08:17:11 GMT</pubDate>
    <dc:creator>cadet alain</dc:creator>
    <dc:date>2013-04-29T08:17:11Z</dc:date>
    <item>
      <title>ip inspect name -Router interface does not gets ip from ISP</title>
      <link>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244245#M350872</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My router interface gets ip from ISP modem.&lt;/P&gt;&lt;P&gt;router interface has command&lt;/P&gt;&lt;P&gt;ip address dhcp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I applied ACL to deny all incoming traffic to router interface fa0/0 which connects to ISP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have applied CBAC on router and currently allow this traffic to go outside&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER tcp&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER udp&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER icmp&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER dns&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER ntp&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER bootps&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER bootpc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know what inspect i should allow so that router can get ip,dns,gateway address from ISP?&lt;/P&gt;&lt;P&gt;if i need to access the http or https websites do i need to add the inspect http or https?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also am i missing something under inspection to allow from inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: mahesh parmar&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244245#M350872</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:36:09Z</dc:date>
    </item>
    <item>
      <title>ip inspect name -Router interface does not gets ip from ISP</title>
      <link>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244246#M350873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add this to your config because by default CBAC won't inspect traffic generated by the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER dns &lt;STRONG&gt; router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER ntp&amp;nbsp; &lt;STRONG&gt;router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER bootps &lt;STRONG&gt;router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER bootpc&lt;STRONG&gt; router-traffic&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 08:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244246#M350873</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-04-29T08:17:11Z</dc:date>
    </item>
    <item>
      <title>ip inspect name -Router interface does not gets ip from ISP</title>
      <link>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244247#M350874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will test this today and will update you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 18:51:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244247#M350874</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-29T18:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: ip inspect name -Router interface does not gets ip from ISP</title>
      <link>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244248#M350875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems my router has no option for router traffic&lt;/P&gt;&lt;P&gt;ip inspect name REMEMBER&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bootpc ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; alert&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Turn on/off alert&lt;/P&gt;&lt;P&gt;&amp;nbsp; audit-trail&amp;nbsp; Turn on/off audit trail&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Specify the inactivity timeout time&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i applied ACL on inside to allow &lt;/P&gt;&lt;P&gt; permit udp any any eq bootpc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that fixed the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for answering the questions and letting me know about router traffic option.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 00:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244248#M350875</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-30T00:37:34Z</dc:date>
    </item>
    <item>
      <title>ip inspect name -Router interface does not gets ip from ISP</title>
      <link>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244249#M350876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;don't forget the DNS and the NTP traffic too as you mentioned in your first post.&lt;/P&gt;&lt;P&gt;theree's also a router trick to make the CBAC take into account this router generated traffic: make it a transit traffic by sending it to a loopback interface with a local PBR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 07:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-inspect-name-router-interface-does-not-gets-ip-from-isp/m-p/2244249#M350876</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2013-04-30T07:08:05Z</dc:date>
    </item>
  </channel>
</rss>

