<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone Firewall policy configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-firewall-policy-configuration/m-p/1581542#M559228</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently using classic CBAC/inspect FW configuration on my 1801 router. I would like to implement a ZFW config. ZWF is new to me, I've read "Zone-Based Policy Firewall Design and Application Guide" &amp;amp; am a bit confused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following questions arise:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In the above guide on pg 19 (bottom) it states "HTTP Application Inspection (similar to other types of Application Inspection) can only be applied to HTTP traffic.Thus, you must define Layer 7 class-maps and policy-maps for specific HTTP traffic, then define a Layer-4 class-map specifically for HTTP, and apply the Layer-7 policy to HTTP inspection in a Layer-4 policy-map".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What isconfusing is that several L7 configuration examples are very different. One shows only L7 cmap &amp;amp; pmap (example pg.13).Another example shows a config with an L7 cmap/pmap, with a L4 cmap/pmap defined (exmaple pg 19). Please help clarify.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. Are all the ZFW parameters such as DoS protection, TCP connection/UDP session timers, and audit-trail logging settings that I want to use put into one (1) large policy parameter map? If so would someone be able to help reoganzie a parameter map based on my "ZFW config" doc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Where can I find the syntax for the following:tcp/udp fin &amp;amp; synwait times, inspect reassembly queue length, idle time tcp/udp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Prior to loading new ZFW config, does CBAC have be unloaded? what is command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is to implement my current CBAC/inspect swttings (see attached config) in the ZFW &amp;amp; lock down the router further if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My requirements are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. implement L7 inspection on the following protocols: HTTP/HTTPS/ESMPT/SMTP/POP3/DNS&lt;BR /&gt;2. implement current CBAC/inspect settings if possible and tighten secutiy further if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've put together a draft ZFW config that is probably full of configuration &amp;amp; syntax errors. I would appreciate if some of the FW experts might be able to help me develop a working ZFW config.&lt;BR /&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:11:51 GMT</pubDate>
    <dc:creator>ms4561</dc:creator>
    <dc:date>2019-03-11T20:11:51Z</dc:date>
    <item>
      <title>Zone Firewall policy configuration</title>
      <link>https://community.cisco.com/t5/network-security/zone-firewall-policy-configuration/m-p/1581542#M559228</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently using classic CBAC/inspect FW configuration on my 1801 router. I would like to implement a ZFW config. ZWF is new to me, I've read "Zone-Based Policy Firewall Design and Application Guide" &amp;amp; am a bit confused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following questions arise:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In the above guide on pg 19 (bottom) it states "HTTP Application Inspection (similar to other types of Application Inspection) can only be applied to HTTP traffic.Thus, you must define Layer 7 class-maps and policy-maps for specific HTTP traffic, then define a Layer-4 class-map specifically for HTTP, and apply the Layer-7 policy to HTTP inspection in a Layer-4 policy-map".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What isconfusing is that several L7 configuration examples are very different. One shows only L7 cmap &amp;amp; pmap (example pg.13).Another example shows a config with an L7 cmap/pmap, with a L4 cmap/pmap defined (exmaple pg 19). Please help clarify.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. Are all the ZFW parameters such as DoS protection, TCP connection/UDP session timers, and audit-trail logging settings that I want to use put into one (1) large policy parameter map? If so would someone be able to help reoganzie a parameter map based on my "ZFW config" doc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Where can I find the syntax for the following:tcp/udp fin &amp;amp; synwait times, inspect reassembly queue length, idle time tcp/udp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Prior to loading new ZFW config, does CBAC have be unloaded? what is command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is to implement my current CBAC/inspect swttings (see attached config) in the ZFW &amp;amp; lock down the router further if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My requirements are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. implement L7 inspection on the following protocols: HTTP/HTTPS/ESMPT/SMTP/POP3/DNS&lt;BR /&gt;2. implement current CBAC/inspect settings if possible and tighten secutiy further if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've put together a draft ZFW config that is probably full of configuration &amp;amp; syntax errors. I would appreciate if some of the FW experts might be able to help me develop a working ZFW config.&lt;BR /&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-firewall-policy-configuration/m-p/1581542#M559228</guid>
      <dc:creator>ms4561</dc:creator>
      <dc:date>2019-03-11T20:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Firewall policy configuration</title>
      <link>https://community.cisco.com/t5/network-security/zone-firewall-policy-configuration/m-p/1581543#M559230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls. follow this link.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-8028"&gt;https://supportforums.cisco.com/docs/DOC-8028&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may not be doing Trend content filtering but, it certainly goes over how to configure L7 inspection.&lt;/P&gt;&lt;P&gt;It also has parameter map configuration sample.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Removing old cbac command&lt;/P&gt;&lt;P&gt;sh run | i inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run int e0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you have any ip inspect commands configured you can remove them from the global configuration as well as interface configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Apr 2011 23:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-firewall-policy-configuration/m-p/1581543#M559230</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-04-09T23:12:25Z</dc:date>
    </item>
  </channel>
</rss>

