<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone Based Firewall Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645992#M591416</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jennifer -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the self zone is automatically created for all IP's on the router, both the MPPP and the Tunnel interface on the router will reside in the self zone. That being said, I am not using the self zone in any zone pairs. Therefore shouldn't be a need to allow any VPN traffic (ISAKMP, ESP) or GRE traffic. Correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case, the tunnel interface will be assigned to the OUT-IN security zone.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Feb 2011 04:56:25 GMT</pubDate>
    <dc:creator>ksarin123_2</dc:creator>
    <dc:date>2011-02-18T04:56:25Z</dc:date>
    <item>
      <title>Zone Based Firewall Question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645990#M591410</link>
      <description>&lt;P&gt;Hello folks -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am confiuring ZFW on a Cisco 2951 Router. The router has the following interfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-collapse: collapse; mso-border-alt: solid windowtext .5pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt;"&gt;&lt;TBODY&gt;&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"&gt;&lt;TD style="padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; padding-top: 0in; mso-border-alt: solid windowtext .5pt; border: windowtext 1pt solid;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="mso-bidi-font-weight: normal; : ; color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Type&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: windowtext 1pt solid; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="mso-bidi-font-weight: normal; : ; color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;IP Address&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: windowtext 1pt solid; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="mso-bidi-font-weight: normal; : ; color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Use&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 1;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Port Channel 1.5&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;10.218.4.197/30&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;RTR-SW-Inband-MGMT VLAN&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 2;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Port Channel 1.10&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;10.218.4.1/26&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;User VLAN&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 3;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Port Channel 1.15&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;10.218.4.65/26&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;DB/Servers VLAN&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 4;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Port Channel 1.20&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;10.218.4.194/30&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;RTR-FW VLAN&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 5;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Gig 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Ether Channel (Po1) &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 6;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Gig 0/1&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Ether Channel (Po1) &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 7;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Tunnel 0&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;10.16.252.4/24&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;DMVPN Tunnel&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 8;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Multilink PPP&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;XX.XX.XX.XX/30&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Two Bundled T1’s for CORP MPLS&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 9;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Serial0/0/0:0&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;T1 interface part of MPPP&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 10; mso-yfti-lastrow: yes;"&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: windowtext 1pt solid; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;Serial0/0/1:0&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;N/A&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: windowtext 1pt solid; border-left: #d4d0c8; padding-bottom: 0in; background-color: transparent; padding-left: 5.4pt; padding-right: 5.4pt; border-top: #d4d0c8; border-right: windowtext 1pt solid; padding-top: 0in; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;T1 interface part of MPPP&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port Channel 1, 1.5, 1.10, 1.15, 1.20 have been added to the zone called IN-OUT. All the subinterfaces correspond to an internal VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router is connected to a MPLS network and has a BGP peer on interface MPPP. Over the MPLS network, an ecrypted DMVPN tunnel to HQ has been built (tunnel 0). EIGRP is the routing protocol running over the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic coming in from HQ has to be firewalled on this router (don't ask me why!!). As a result, I am configuring ZFW on this router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL start="1"&gt;&lt;LI&gt;This is how I am writing my class-maps. Is this the right way to do it?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-l 101 permit ip host 172.16.10.5 10.218.4.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class-map type inspect match-all HQ-2-Remote_office&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; match access-group 101&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; match protocol snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OR, should I do it this way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-l 101 permit tcp host 172.16.10.5 10.218.4.0 0.0.0.255 eq snmp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class-map type inspect match-all HQ-2-Remote_office&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; match access-group 101&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The router itself does not need to be protected, only the servers in the remote offices. That being said, I am not planning to create any self zone on this router. I don't want to break BGP, therefore the MPPP interface will NOT belong to any zone. Is this the correct way to do it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. The tunnel 0 interface will belong to OUT-IN zone that will protect all incoming traffic into this site from HQ. So when writing class-maps for the traffic coming INTO this site, do I need to write any class-maps for EIGRP or ESP? My guess is no, since that traffic will not be coming into the site, but rather just terminating on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks much for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645990#M591410</guid>
      <dc:creator>ksarin123_2</dc:creator>
      <dc:date>2019-03-11T19:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Based Firewall Question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645991#M591413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just a high level comment to start with: once you apply a zone member on 1 interface, your router is ZBFWed, which means, you will need to &lt;EM style="text-decoration: underline; "&gt;&lt;STRONG&gt;explicitly&lt;/STRONG&gt;&lt;/EM&gt; configure policy to allow any other communication between any other zone that you need traffic to pass, this includes the self zone (since you are running BGP, DMVPN, etc) --&amp;gt; all of these need to be explicitly configured as it is like (deny ip any any) once you have 1 policy/zone configured for any other ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 1:&lt;/P&gt;&lt;P&gt;You can configure the class-map either way, both method is correct.&lt;/P&gt;&lt;P&gt;Just a minor correction, are you using TCP or UDP based SNMP? typically default is UDP, so just wondering if you have typo on your ACL 101.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 2:&lt;/P&gt;&lt;P&gt;Not correct as per my comment above. Need to explicitly create other zones (including self zone) for any traffic that you want to allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 3:&lt;/P&gt;&lt;P&gt;Here is an example on ZBFW configurating for DMVPN traffic:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5710/ps1018/prod_white_paper0900aecd8062a909.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5710/ps1018/prod_white_paper0900aecd8062a909.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 23:01:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645991#M591413</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-17T23:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Based Firewall Question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645992#M591416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jennifer -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the self zone is automatically created for all IP's on the router, both the MPPP and the Tunnel interface on the router will reside in the self zone. That being said, I am not using the self zone in any zone pairs. Therefore shouldn't be a need to allow any VPN traffic (ISAKMP, ESP) or GRE traffic. Correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case, the tunnel interface will be assigned to the OUT-IN security zone.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 04:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645992#M591416</guid>
      <dc:creator>ksarin123_2</dc:creator>
      <dc:date>2011-02-18T04:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Based Firewall Question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645993#M591419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, as advised earlier, once an interface belongs to a zone, for any other interfaces (including the self zone), you would need to create policy-map for if you would like to pass traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case, you have an outside zone applied to the external interface (interface connected to the internet), if you will need to pass traffic between outside zone and self zone, then you will explicitly need to configure the policy for it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 05:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645993#M591419</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-18T05:47:37Z</dc:date>
    </item>
    <item>
      <title>Zone Based Firewall Question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645994#M591424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Two years later...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure that's correct Jennifer?&amp;nbsp; Unless a policy exists e.g. Outzone -&amp;gt; Self then all traffic from outzone to self will be implicitly permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is outlined in a table showing self -&amp;gt; zone member interface and zone member interface -&amp;gt; self on page 410 of Cisco Press' Implementing Cisco IOS Network Security (IINS 640-554) Foundation Learning Guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ivan Pepelnjak also talks about it here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Unless you specify a &lt;STRONG&gt;zone-pair&lt;/STRONG&gt; combining &lt;STRONG&gt;self&lt;/STRONG&gt; zone with another zone, all traffic from that zone&amp;nbsp; sent to the router itself is allowed (the router is not protected)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://blog.ioshints.info/2007/05/self-zone-in-zone-based-firewall.html"&gt;http://blog.ioshints.info/2007/05/self-zone-in-zone-based-firewall.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...and finally on cisco.com &lt;STRONG&gt;"The self zone is the only exception to the default deny all policy. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;All traffic to any router interface is allowed until traffic is explicitly &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;denied."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if the OP has a routing protocol running on the router itself (self zone, traffic generated by the router) and does NOT have a policy for outzone -&amp;gt; self, then the traffic will be permitted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 22:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645994#M591424</guid>
      <dc:creator>edwardyardley</dc:creator>
      <dc:date>2013-02-13T22:36:43Z</dc:date>
    </item>
    <item>
      <title>Zone Based Firewall Question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645995#M591426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There has been lots of changes to the ZBFW behaviour where the original behaviour is deny all. However, there must have been many complaints and they have made changes to the behaviour and now it's as per the book advised.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 04:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1645995#M591426</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2013-02-14T04:49:25Z</dc:date>
    </item>
  </channel>
</rss>

