<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ZBF and NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zbf-and-nat/m-p/1831977#M492295</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as I studied,&amp;nbsp; Interface ACLs and Zone based Firewall should not be applied at the same time. This it means that every packet is processed by the router (I'm thinking NAT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, an unwanted traffic is processed by NAT before is it drop by ZBF. Do you think is it optimal ?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:56:03 GMT</pubDate>
    <dc:creator>ipagliani</dc:creator>
    <dc:date>2019-03-11T21:56:03Z</dc:date>
    <item>
      <title>ZBF and NAT</title>
      <link>https://community.cisco.com/t5/network-security/zbf-and-nat/m-p/1831977#M492295</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as I studied,&amp;nbsp; Interface ACLs and Zone based Firewall should not be applied at the same time. This it means that every packet is processed by the router (I'm thinking NAT).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, an unwanted traffic is processed by NAT before is it drop by ZBF. Do you think is it optimal ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-and-nat/m-p/1831977#M492295</guid>
      <dc:creator>ipagliani</dc:creator>
      <dc:date>2019-03-11T21:56:03Z</dc:date>
    </item>
    <item>
      <title>ZBF and NAT</title>
      <link>https://community.cisco.com/t5/network-security/zbf-and-nat/m-p/1831978#M492297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is not something to be optimal or not. Packets processed by Zone-Based are either fast switched or processed switched so that's probably why NAT is processed before the Zone-based Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand inbound ACLs (if no further processing is necessary for other features) are processed by CEF so the packets don't go to the router's CPU and are processed before NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 16:43:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-and-nat/m-p/1831978#M492297</guid>
      <dc:creator>josecalv</dc:creator>
      <dc:date>2011-11-28T16:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF and NAT</title>
      <link>https://community.cisco.com/t5/network-security/zbf-and-nat/m-p/1831979#M492300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;what you said is logical and correct point of view for packet processing; but what do you think about firewall processing ? &lt;/P&gt;&lt;P&gt; I don't understand why an unwanted packet have to be processed by Nat before drop it &lt;/P&gt;&lt;P&gt;ASA behavior is a little bit different, it use real ip address but interface ACL is still used for block packet before other process.&lt;/P&gt;&lt;P&gt;Regard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 17:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-and-nat/m-p/1831979#M492300</guid>
      <dc:creator>ipagliani</dc:creator>
      <dc:date>2011-11-28T17:44:44Z</dc:date>
    </item>
  </channel>
</rss>

