<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone Based Firewall and WAN interface ACL in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618320#M559647</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply paul.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have the VPN and ZBFW configured and working together.&amp;nbsp; My question is how I should go about securing the outside interface.&amp;nbsp; I want to restrict ssh access to just from out local nets, but wondering what else I should apply to the outside interface since we are running the zone based FW on the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Mar 2011 19:50:17 GMT</pubDate>
    <dc:creator>James Walsh</dc:creator>
    <dc:date>2011-03-17T19:50:17Z</dc:date>
    <item>
      <title>Zone Based Firewall and WAN interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618318#M559645</link>
      <description>&lt;P&gt;I am getting ready to deploy a 3945 ISR to serve as an internet and core router for and remote site.&amp;nbsp; I will be terminating a site-to-site VPN tunnel on it and also confiugring a zone based firewall config between my "outside" (internet link) and "inside" (all internal nets).&amp;nbsp; My question is about how to approach securing the WAN interface with the Zone based FW in place?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what kind of ACL do I need beyond those alllowing and restricing remote access to the outside ip?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, any thoughts are appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618318#M559645</guid>
      <dc:creator>James Walsh</dc:creator>
      <dc:date>2019-03-11T20:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Based Firewall and WAN interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618319#M559646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you configure first your VPN you could use the SDM to configure ZFW since it helps in setting up both configs without conflicting with each other.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 19:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618319#M559646</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-17T19:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Based Firewall and WAN interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618320#M559647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply paul.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have the VPN and ZBFW configured and working together.&amp;nbsp; My question is how I should go about securing the outside interface.&amp;nbsp; I want to restrict ssh access to just from out local nets, but wondering what else I should apply to the outside interface since we are running the zone based FW on the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 19:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618320#M559647</guid>
      <dc:creator>James Walsh</dc:creator>
      <dc:date>2011-03-17T19:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Based Firewall and WAN interface ACL</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618321#M559648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;to allow or deny management protocols there are different options. One way is to use the management plane, check this link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/htsecmpp.html"&gt;http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/htsecmpp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also configure acls allowing the desired IPs and apply the ACL on the specific lines of the router. This traffic has to be allowed by the ZFW from the specific zone to self.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 20:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-and-wan-interface-acl/m-p/1618321#M559648</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-17T20:01:53Z</dc:date>
    </item>
  </channel>
</rss>

