<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone Base Firewall Design question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-base-firewall-design-question/m-p/1498931#M662414</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am planning to use ZBFW in my network but I face a problem with "extending the legs" for ZBFW. I have two router, Router A&amp;nbsp; is a L3 switch and is configured with all the IPs, Vlans and current ACL list. Router B will be added to the existing topology and configured with ZBFW. All Traffic is expected to flow through Router B before reaching Router A. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I have created the different zone on router B, how can I apply this configuration so that I can control traffic between different vlans in router A??? As the documentation from cisco, as I understand cisco expect all the invidual vlans and zone base configuration should be on the same router and not separate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:04:26 GMT</pubDate>
    <dc:creator>ytlee80</dc:creator>
    <dc:date>2019-03-11T18:04:26Z</dc:date>
    <item>
      <title>Zone Base Firewall Design question</title>
      <link>https://community.cisco.com/t5/network-security/zone-base-firewall-design-question/m-p/1498931#M662414</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am planning to use ZBFW in my network but I face a problem with "extending the legs" for ZBFW. I have two router, Router A&amp;nbsp; is a L3 switch and is configured with all the IPs, Vlans and current ACL list. Router B will be added to the existing topology and configured with ZBFW. All Traffic is expected to flow through Router B before reaching Router A. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I have created the different zone on router B, how can I apply this configuration so that I can control traffic between different vlans in router A??? As the documentation from cisco, as I understand cisco expect all the invidual vlans and zone base configuration should be on the same router and not separate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-base-firewall-design-question/m-p/1498931#M662414</guid>
      <dc:creator>ytlee80</dc:creator>
      <dc:date>2019-03-11T18:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Base Firewall Design question</title>
      <link>https://community.cisco.com/t5/network-security/zone-base-firewall-design-question/m-p/1498932#M662459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm slightly confused about the topology based on your description below.&amp;nbsp; Please confirm if this is indeed your topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ClientVlanX -&amp;gt; Router A (L3 Switch) -&amp;gt; Router B (with ZBF) -&amp;gt; Internet&lt;/P&gt;&lt;P&gt;ClientVlanY-&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you trunk the link between Router A and Router B, to include multiple Vlans (ie X and Y), you can configure sub-interfaces on the Router B.&amp;nbsp; With the sub-interfaces, you can assign each sub-interface to a different zone.&amp;nbsp; You would then specify different zone policies that define what traffic is allowed between ZoneXY and ZoneYX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this doesn't completely answer your question, please provide me more information about your topology and requirements and I'll do what I can assist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jul 2010 17:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-base-firewall-design-question/m-p/1498932#M662459</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2010-07-02T17:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Zone Base Firewall Design question</title>
      <link>https://community.cisco.com/t5/network-security/zone-base-firewall-design-question/m-p/1498933#M662500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the insight. i think its the correct way to do it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jul 2010 03:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-base-firewall-design-question/m-p/1498933#M662500</guid>
      <dc:creator>ytlee80</dc:creator>
      <dc:date>2010-07-06T03:53:05Z</dc:date>
    </item>
  </channel>
</rss>

