<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone Based Firewall ASR1002 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-asr1002/m-p/1960691#M434910</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shuai Yu: I guess it depends on what you are trying to achive, maybe they have a http-server of something...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jackwikiski: Your parameter-maps confuses me because they don't have a name? Or is it because they are global so you don't need a name?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type inspect ANTI-DDOS_PARMAP&lt;/P&gt;&lt;P&gt;&amp;nbsp; session total 99000&lt;/P&gt;&lt;P&gt;&amp;nbsp; alert on&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box tcp syn-flood limit 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box max-incomplete tcp 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box max-incomplete udp 500&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box max-incomplete icmp 500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect ddos-fw&lt;/P&gt;&lt;P&gt; class type inspect ddos-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ANTI-DDOS_PARMAP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Jun 2012 20:17:52 GMT</pubDate>
    <dc:creator>Henrik Grankvist</dc:creator>
    <dc:date>2012-06-04T20:17:52Z</dc:date>
    <item>
      <title>Zone Based Firewall ASR1002</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-asr1002/m-p/1960689#M434908</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying to implement the ZBF on our router to assist us in limiting the intial impact of DDOS attacks.&lt;/P&gt;&lt;P&gt;We have configured the below and it appears that it's not working, as when un der attack the statistics don't increae.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be greatly appreciated:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type inspect global&lt;/P&gt;&lt;P&gt; session total 99000&lt;/P&gt;&lt;P&gt; alert on&lt;/P&gt;&lt;P&gt; per-box tcp syn-flood limit 2000&lt;/P&gt;&lt;P&gt; per-box max-incomplete tcp 2000&lt;/P&gt;&lt;P&gt; per-box max-incomplete udp 500&lt;/P&gt;&lt;P&gt; per-box max-incomplete icmp 500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-any ddos-class&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;match protocol tcp&lt;/P&gt;&lt;P&gt;match protocol UDP&lt;/P&gt;&lt;P&gt;match protocol icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type inspect global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect ddos-fw&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class type inspect ddos-class&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone security public&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone security private&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone-pair security public2private source public destination private&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy type inspect ddos-fw&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int GigabitEthernet0/0/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone-member security public&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int GigabitEthernet0/2/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone-member security private&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jack.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-asr1002/m-p/1960689#M434908</guid>
      <dc:creator>jackwikinski</dc:creator>
      <dc:date>2019-03-11T23:15:21Z</dc:date>
    </item>
    <item>
      <title>Zone Based Firewall ASR1002</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-asr1002/m-p/1960690#M434909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Just curious, should u put the policy-map to the public2self zone-pair to limit DOS attack?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2012 17:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-asr1002/m-p/1960690#M434909</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2012-06-04T17:17:43Z</dc:date>
    </item>
    <item>
      <title>Zone Based Firewall ASR1002</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-asr1002/m-p/1960691#M434910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shuai Yu: I guess it depends on what you are trying to achive, maybe they have a http-server of something...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jackwikiski: Your parameter-maps confuses me because they don't have a name? Or is it because they are global so you don't need a name?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type inspect ANTI-DDOS_PARMAP&lt;/P&gt;&lt;P&gt;&amp;nbsp; session total 99000&lt;/P&gt;&lt;P&gt;&amp;nbsp; alert on&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box tcp syn-flood limit 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box max-incomplete tcp 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box max-incomplete udp 500&lt;/P&gt;&lt;P&gt;&amp;nbsp; per-box max-incomplete icmp 500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect ddos-fw&lt;/P&gt;&lt;P&gt; class type inspect ddos-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ANTI-DDOS_PARMAP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2012 20:17:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-asr1002/m-p/1960691#M434910</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2012-06-04T20:17:52Z</dc:date>
    </item>
  </channel>
</rss>

