<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall for restricting access between VLAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-for-restricting-access-between-vlan/m-p/1625324#M565270</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am about to set up a network with about 20+ different VLANs and they are suppose to just access the Internet and not eachother, is this possible with a zone-based firewall? To put all the interfaces belonging to VLANs in one zone allowing them to just access the Internet and not eachother.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible and what do i need to configure for this to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Tommy Svensson&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:56:36 GMT</pubDate>
    <dc:creator>Tommy Svensson</dc:creator>
    <dc:date>2019-03-11T19:56:36Z</dc:date>
    <item>
      <title>Firewall for restricting access between VLAN</title>
      <link>https://community.cisco.com/t5/network-security/firewall-for-restricting-access-between-vlan/m-p/1625324#M565270</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am about to set up a network with about 20+ different VLANs and they are suppose to just access the Internet and not eachother, is this possible with a zone-based firewall? To put all the interfaces belonging to VLANs in one zone allowing them to just access the Internet and not eachother.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible and what do i need to configure for this to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Tommy Svensson&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-for-restricting-access-between-vlan/m-p/1625324#M565270</guid>
      <dc:creator>Tommy Svensson</dc:creator>
      <dc:date>2019-03-11T19:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall for restricting access between VLAN</title>
      <link>https://community.cisco.com/t5/network-security/firewall-for-restricting-access-between-vlan/m-p/1625325#M565271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can use Zone Based FW to restrict access, however, you do not want to put them into the same zone because same zone means they will be able to access each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't want to have access between each zone, you will place them in different zones, and just create policy and zone pair for each of the zone towards the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is configuration guide on ZBFW:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a008060f6dd.html"&gt;http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a008060f6dd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in general, here is what you have to configure:&lt;/P&gt;&lt;P&gt;1) Configure the access-list to match what you want to allow&lt;/P&gt;&lt;P&gt;2) Create class-map, to match on the access-list created on step1&lt;/P&gt;&lt;P&gt;3) Create policy-map, with the action of inspect for the class created on step2&lt;/P&gt;&lt;P&gt;4) Create zone member&lt;/P&gt;&lt;P&gt;5) Create zone-pair, with source zone being internal vlan, and destination zone being the outside/internet, and apply the policy-map to the zone-pair&lt;/P&gt;&lt;P&gt;6) Lastly place the zone under the vlan interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 08:30:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-for-restricting-access-between-vlan/m-p/1625325#M565271</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-25T08:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall for restricting access between VLAN</title>
      <link>https://community.cisco.com/t5/network-security/firewall-for-restricting-access-between-vlan/m-p/1625326#M565272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im using a Cisco 2911 router and want to restrict access between VLANs, is zone based firewall the way to go or am i missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Tommy Svensson&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2011 11:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-for-restricting-access-between-vlan/m-p/1625326#M565272</guid>
      <dc:creator>Tommy Svensson</dc:creator>
      <dc:date>2011-03-03T11:58:59Z</dc:date>
    </item>
  </channel>
</rss>

