<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ZBFW not blocking traffic from DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204300#M391878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Karien,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;(I do not have the configs right now (I am working GMT times, so currently @ home)&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Any idea?&lt;/P&gt;&lt;P&gt; Does not make any sense, should not be possible,&lt;/P&gt;&lt;P&gt;I want to doble-check that &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; , can you share the config, maybe the results of the PING as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2-CSM Questions,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I consider myself not the right person to talk about CSM as I have not played with that a lot, so I cannot say Yes go for it or No, don't do it,&lt;/P&gt;&lt;P&gt;All I can say is I have heard that for security configuration/ managment purposes is not a good option &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. That's as important as a Thanks. &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jul 2013 21:27:28 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-07-08T21:27:28Z</dc:date>
    <item>
      <title>ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204291#M391869</link>
      <description>&lt;P&gt;OK, I have a 2921 on 15.3-2T. ZBFW is working from the inside to the outside, but the DMZ is not being blocked at all to the inside. I am currently running with subinterfaces. All interfaces have zones attached. I have policies from inside to outside and DMZ to outside, those work fine. Without any policy from DMZ to inside, it can pass traffic freely from DMZ to inside. I have tried making an explicit policy to drop all to inside, still passes. I ended up just having to put an ACL on the interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already tried upgrading the IOS, that is how I ended up on the newest version. This is connected to a 2960S with a trunk port. Everything else works perfectly except for the DMZ security. I haven't had time to try to lab it up yet, but wanted to see if anyone knows of any reasons this shouldn't work, as all documentation says it should drop all traffic unless you make a policy to pass traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attached my running config, sensitive information was removed or changed.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204291#M391869</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2019-03-12T01:33:31Z</dc:date>
    </item>
    <item>
      <title>ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204292#M391870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you attach the config when you have the problems you are describring.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204292#M391870</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2013-04-24T19:32:17Z</dc:date>
    </item>
    <item>
      <title>ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204293#M391871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already have, it is in the initial posting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:34:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204293#M391871</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2013-04-24T19:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204294#M391872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I thought that the config when you have set an ACL on the interface to fix the problem because ZBF isn't working as expected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds really weird the problem you are experiencing, never encountered it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to be sure, do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no zone-pair security InDMZ source DMZ destination Inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface GigabitEthernet0/1.197&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; no ip access-group DMZ in&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Can the DMZ still communicate with the inside after this?&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Apr 2013 08:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204294#M391872</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2013-04-25T08:41:03Z</dc:date>
    </item>
    <item>
      <title>ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204295#M391873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have already done that as explained in the initial posting. The config you reference was explained as part of my attempts to block the traffic, which ended with me just using an ACL cause the other methods failed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 19:26:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204295#M391873</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2013-04-26T19:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204296#M391874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool post,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hmm, I think I have not played with Zone-based and Sub-interfaces before ( although I have worked on a huge amount of cases with ZBFW) but logically speaking is the same thing &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So here is what I want you to do ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all remove the zone-pair from dmz to inside before taking the outputs I am going to provide you ( I KNOW you already post that you are testing new things, that is why you add that )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Create an ACL to match traffic that is being allowed right now from DMZ to Inside, this just to test purposes&lt;/P&gt;&lt;P&gt;2) debug policy-firewall list ACL_CREATED_TO_MATCH_TRAFFIC&lt;/P&gt;&lt;P&gt;3) &lt;SPAN style="font-size: 10pt;"&gt;debug cce dp feature inspect detail&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Be careful with the debugs &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;May I know the traffic flow that is being allowed right now?? Source IP destination IP &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 21:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204296#M391874</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-26T21:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204297#M391875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;I have exactly the same issue. Was this solved in a meanwhile ? &lt;/P&gt;&lt;P&gt;thx Karien &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 19:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204297#M391875</guid>
      <dc:creator>karien.depyper</dc:creator>
      <dc:date>2013-07-08T19:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204298#M391876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Karien,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did not receive any information,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's your scenario/issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. &lt;BR /&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 20:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204298#M391876</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-08T20:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204299#M391877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thansk for the quick respone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured zbfw between 2 subinterfaces on a lan,&lt;/P&gt;&lt;P&gt;1 interface in zone production&lt;/P&gt;&lt;P&gt;1 subinterface in zone tda, &lt;/P&gt;&lt;P&gt;inspecting tcp, udp and icmp, only in 1 direction :production to tda&lt;/P&gt;&lt;P&gt;However, icmp from test to production is possible. &lt;/P&gt;&lt;P&gt;ISR 2900, 15.2 software&lt;/P&gt;&lt;P&gt;(I do not have the configs right now (I am working GMT times, so currently @ home) &lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 other questions, as you seem a big fan of ZBFW &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- I am working on a&amp;nbsp; Proof of concept with CSM4.4SP1 and ZBFW (1000+ routers). Is this recommended ? I read a post where they don't recommend it (&lt;A _jive_internal="true" href="https://community.cisco.com/message/3944461#3944461"&gt;https://supportforums.cisco.com/message/3944461#3944461&lt;/A&gt;) &lt;/P&gt;&lt;P&gt;- I have a flex vpn setup: do i have to put the tunnel source addresses into a vpn zone ?&lt;/P&gt;&lt;P&gt;Many thanks Karien &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 20:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204299#M391877</guid>
      <dc:creator>karien.depyper</dc:creator>
      <dc:date>2013-07-08T20:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204300#M391878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Karien,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;(I do not have the configs right now (I am working GMT times, so currently @ home)&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Any idea?&lt;/P&gt;&lt;P&gt; Does not make any sense, should not be possible,&lt;/P&gt;&lt;P&gt;I want to doble-check that &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; , can you share the config, maybe the results of the PING as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2-CSM Questions,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I consider myself not the right person to talk about CSM as I have not played with that a lot, so I cannot say Yes go for it or No, don't do it,&lt;/P&gt;&lt;P&gt;All I can say is I have heard that for security configuration/ managment purposes is not a good option &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. That's as important as a Thanks. &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 21:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204300#M391878</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-08T21:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204301#M391879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello again,&lt;/P&gt;&lt;P&gt;- I have access the configs again in about 9 hours, then I can share them with you. (what time zone are you in ?). I am planning to use a class-map with match access-group instead of mach protocol icmp as a first thing ..&lt;/P&gt;&lt;P&gt;- OK, I will talk to a CSM expert.&lt;/P&gt;&lt;P&gt;- How would you then 2BFW rulebase of 1000 ASR and ISR routers ?&lt;/P&gt;&lt;P&gt;many thanks Karien&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 21:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204301#M391879</guid>
      <dc:creator>karien.depyper</dc:creator>
      <dc:date>2013-07-08T21:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204302#M391880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Karien,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am on MST,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure send the configs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ZBFW rulebase: They all work the same... They try to accomplish the same goal so configuration speaking, same thing,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. That's as important as a Thanks. &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 21:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204302#M391880</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-08T21:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204303#M391881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks you Julio,&lt;/P&gt;&lt;P&gt;Last question for today &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;ZBFW for 1000 routers: how to manage them with an alternative to CSM ?&lt;/P&gt;&lt;P&gt;thx Karien &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 21:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204303#M391881</guid>
      <dc:creator>karien.depyper</dc:creator>
      <dc:date>2013-07-08T21:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204304#M391882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Karien,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would always say CLI for configuration purposes (100 % of the times) and for monitoring you could use either a GUI ( SDM,CCP,SDM) or the CLI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have several options to use depend on what you want to accomplish&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. That's as important as a Thanks. &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 22:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204304#M391882</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-08T22:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204305#M391883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was not solved, I haven't had time to do any testing but another person verified it worked on 12.4 just fine. I am starting to wonder if it is related to the new platform or licensing as I don't have the data license on that box, not sure. Starting to look like an issue with that platform though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 22:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204305#M391883</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2013-07-08T22:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204306#M391884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hello, i opened a case for it, lets seet what comes out&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 08:47:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204306#M391884</guid>
      <dc:creator>karien.depyper</dc:creator>
      <dc:date>2013-07-09T08:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204307#M391885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please let me know what becomes of it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 13:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204307#M391885</guid>
      <dc:creator>Keith McElroy</dc:creator>
      <dc:date>2013-07-09T13:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204308#M391886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;Issue identified: The problem exists with icmp only, other tcp/udp sessions work fine.&lt;/P&gt;&lt;P&gt;Related to bug : &lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCsz36217" target="_blank"&gt;CSCsz36217&lt;/A&gt; Bug Details &lt;/P&gt;&lt;P&gt; Zone Based Firewall leaks for ICMP inspected Traffic &lt;/P&gt;&lt;P&gt;Status: Open/postponed&lt;/P&gt;&lt;P&gt;Rgards Karien &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 20:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204308#M391886</guid>
      <dc:creator>karien.depyper</dc:creator>
      <dc:date>2013-07-09T20:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: ZBFW not blocking traffic from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204309#M391887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Karien,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great info, Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. That's as important as a Thanks. &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 20:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbfw-not-blocking-traffic-from-dmz/m-p/2204309#M391887</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-09T20:53:38Z</dc:date>
    </item>
  </channel>
</rss>

