<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic zone based firewall configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-configuration/m-p/1775910#M496705</link>
    <description>&lt;P&gt;Hi I'm trying to setup a zone based firewall. I can't seem to work out what is going wrong. I have added the class maps, policy map, extended acls, and have defined the zones and added the zones to the interfaces. Can anyone see why this wouldn't be working? This is the first time I've configured this type of firewall. I've applied zone-member security outside to the dialer3 interface as well as ip nat outside. It was working before with NAT. It only stopped working when I started applying the zone based firewall configuration so I know it's incorrect somewhere. It doesn't seem to be matching the access-list I've created when I ping from 10.1.1.11. The routers are also running bgp which is working fine. The 10.1.1.11 - 10.1.1.16 range is being NATed to a public address. What I'm trying to do is permit icmp outbound from the 10.1.1.11 addresses and restrict everything else outbound. Inbound I'm trying to permit hosts to the http server which can be accessed on 10.1.1.12 and also telnet but only to that address if that makes sense. I've provided some of my configuration below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all outbound&lt;/P&gt;&lt;P&gt; match protocol icmp&lt;/P&gt;&lt;P&gt; match access-group name inside&amp;gt;outside&lt;/P&gt;&lt;P&gt;class-map type inspect match-all inbound&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt; match protocol telnet&lt;/P&gt;&lt;P&gt; match access-group name outside&amp;gt;inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect ZONEINSIDE&lt;/P&gt;&lt;P&gt; class type inspect inbound&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;policy-map type inspect ZONEOUTSIDE&lt;/P&gt;&lt;P&gt; class type inspect outbound&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;zone security inside&lt;/P&gt;&lt;P&gt;zone security outside&lt;/P&gt;&lt;P&gt;zone-pair security ZONEINSIDE source inside destination outside&lt;/P&gt;&lt;P&gt; service-policy type inspect ZONEINSIDE&lt;/P&gt;&lt;P&gt;zone-pair security ZONEOUTSIDE source outside destination inside&lt;/P&gt;&lt;P&gt; service-policy type inspect ZONEOUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description Inside Interface&lt;/P&gt;&lt;P&gt; ip address 192.168.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; zone-member security inside&lt;/P&gt;&lt;P&gt; load-interval 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer3&lt;/P&gt;&lt;P&gt;ip route 10.1.1.17 255.255.255.255 192.168.10.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;ip nat inside source list NAT interface Dialer3 overload&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended NAT&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.12 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.13 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.14 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.15 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.16 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.11 any&lt;/P&gt;&lt;P&gt;ip access-list extended inside&amp;gt;outside&lt;/P&gt;&lt;P&gt; permit icmp any any&lt;/P&gt;&lt;P&gt;ip access-list extended outside&amp;gt;inside&lt;/P&gt;&lt;P&gt; permit 80 any host 10.1.1.12&lt;/P&gt;&lt;P&gt; permit 23 any host 10.1.1.12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:32:28 GMT</pubDate>
    <dc:creator>Charlotte098</dc:creator>
    <dc:date>2019-03-11T21:32:28Z</dc:date>
    <item>
      <title>zone based firewall configuration</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-configuration/m-p/1775910#M496705</link>
      <description>&lt;P&gt;Hi I'm trying to setup a zone based firewall. I can't seem to work out what is going wrong. I have added the class maps, policy map, extended acls, and have defined the zones and added the zones to the interfaces. Can anyone see why this wouldn't be working? This is the first time I've configured this type of firewall. I've applied zone-member security outside to the dialer3 interface as well as ip nat outside. It was working before with NAT. It only stopped working when I started applying the zone based firewall configuration so I know it's incorrect somewhere. It doesn't seem to be matching the access-list I've created when I ping from 10.1.1.11. The routers are also running bgp which is working fine. The 10.1.1.11 - 10.1.1.16 range is being NATed to a public address. What I'm trying to do is permit icmp outbound from the 10.1.1.11 addresses and restrict everything else outbound. Inbound I'm trying to permit hosts to the http server which can be accessed on 10.1.1.12 and also telnet but only to that address if that makes sense. I've provided some of my configuration below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all outbound&lt;/P&gt;&lt;P&gt; match protocol icmp&lt;/P&gt;&lt;P&gt; match access-group name inside&amp;gt;outside&lt;/P&gt;&lt;P&gt;class-map type inspect match-all inbound&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt; match protocol telnet&lt;/P&gt;&lt;P&gt; match access-group name outside&amp;gt;inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect ZONEINSIDE&lt;/P&gt;&lt;P&gt; class type inspect inbound&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;policy-map type inspect ZONEOUTSIDE&lt;/P&gt;&lt;P&gt; class type inspect outbound&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;zone security inside&lt;/P&gt;&lt;P&gt;zone security outside&lt;/P&gt;&lt;P&gt;zone-pair security ZONEINSIDE source inside destination outside&lt;/P&gt;&lt;P&gt; service-policy type inspect ZONEINSIDE&lt;/P&gt;&lt;P&gt;zone-pair security ZONEOUTSIDE source outside destination inside&lt;/P&gt;&lt;P&gt; service-policy type inspect ZONEOUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description Inside Interface&lt;/P&gt;&lt;P&gt; ip address 192.168.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; zone-member security inside&lt;/P&gt;&lt;P&gt; load-interval 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer3&lt;/P&gt;&lt;P&gt;ip route 10.1.1.17 255.255.255.255 192.168.10.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;ip nat inside source list NAT interface Dialer3 overload&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended NAT&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.12 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.13 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.14 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.15 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.16 any&lt;/P&gt;&lt;P&gt; permit ip host 10.1.1.11 any&lt;/P&gt;&lt;P&gt;ip access-list extended inside&amp;gt;outside&lt;/P&gt;&lt;P&gt; permit icmp any any&lt;/P&gt;&lt;P&gt;ip access-list extended outside&amp;gt;inside&lt;/P&gt;&lt;P&gt; permit 80 any host 10.1.1.12&lt;/P&gt;&lt;P&gt; permit 23 any host 10.1.1.12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:32:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-configuration/m-p/1775910#M496705</guid>
      <dc:creator>Charlotte098</dc:creator>
      <dc:date>2019-03-11T21:32:28Z</dc:date>
    </item>
    <item>
      <title>zone based firewall configuration</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-configuration/m-p/1775911#M496707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;class-map type inspect match-all inbound&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; match protocol http&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; match protocol telnet&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; match access-group name outside&amp;gt;inside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;class-map type inspect match-all inbound&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;match access-group name outside&amp;gt;inside&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and this:&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip access-list extended outside&amp;gt;inside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; permit 80 any host 10.1.1.12&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; permit 23 any host 10.1.1.12&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip access-list extended outside&amp;gt;inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; permit tcp any host 10.1.1.12 eq 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; permit tcp any host 10.1.1.12 eq 23&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if you want access to 10.1.1.12 from outside you need static PAT entries:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip nat inside source static tcp 10.1.1.12 80 interface dialer3 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip nat inside source static tcp 10.1.12.23 interface dialer3 23&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And add this global config command: &lt;STRONG&gt;ip inspect log drop-pkt&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Sep 2011 08:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-configuration/m-p/1775911#M496707</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-30T08:11:05Z</dc:date>
    </item>
  </channel>
</rss>

