<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic zone-based firewall questions, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-questions/m-p/1771151#M496748</link>
    <description>&lt;P&gt;I am trying to understand this following sentence regarding zone-based firewalls on a Cisco router, why they are wrong,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. "Interface ACLs are applied before zone-base policy firewalls when they are applied outbound."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. "The firewalls can be configured simultaneously on the same interface as classic CBAC using the IP inspect CLI command"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any light shed would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Han&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:32:11 GMT</pubDate>
    <dc:creator>hanwucisco</dc:creator>
    <dc:date>2019-03-11T21:32:11Z</dc:date>
    <item>
      <title>zone-based firewall questions,</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-questions/m-p/1771151#M496748</link>
      <description>&lt;P&gt;I am trying to understand this following sentence regarding zone-based firewalls on a Cisco router, why they are wrong,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. "Interface ACLs are applied before zone-base policy firewalls when they are applied outbound."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. "The firewalls can be configured simultaneously on the same interface as classic CBAC using the IP inspect CLI command"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any light shed would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Han&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-questions/m-p/1771151#M496748</guid>
      <dc:creator>hanwucisco</dc:creator>
      <dc:date>2019-03-11T21:32:11Z</dc:date>
    </item>
    <item>
      <title>zone-based firewall questions,</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-questions/m-p/1771152#M496749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) interface ACLs always take precedence over ZBF , I don't think the direction matters.&lt;/P&gt;&lt;P&gt;2) CBAC and ZBF are mutually exclusive on an interface to my best knowledge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to be sure I will lab it up later tonight and give you the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 17:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-questions/m-p/1771152#M496749</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-29T17:23:31Z</dc:date>
    </item>
    <item>
      <title>zone-based firewall questions,</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-questions/m-p/1771153#M496750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just tested ACL and ZBF and direction doesn't matter, it will always be taken into account if it denies a flow permitted by ZBF.&lt;/P&gt;&lt;P&gt;And CBAC and ZBF are mutually exclusive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Sep 2011 09:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-questions/m-p/1771153#M496750</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-30T09:46:43Z</dc:date>
    </item>
  </channel>
</rss>

