<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allowing RDP to pass through ZBF in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/allowing-rdp-to-pass-through-zbf/m-p/1487247#M663316</link>
    <description>&lt;P&gt;I am setting up ZBF for a remote office that has a single server that needs to be reachable via the Internet.&amp;nbsp; So that I can get into the server remotely since it is on a standalone connection from our MPLS network, I have entered the following lines into the router config -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended ACL_RDP&lt;/P&gt;&lt;P&gt;permit tcp any host x.x.x.x eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all RDP&lt;/P&gt;&lt;P&gt; match access-group name ACL_RDP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-policy-ccp-cls--1&lt;/P&gt;&lt;P&gt;&amp;nbsp; class type inspect RDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I type the class type line, I get an error %No specific protocol defined in class RDP for inspections all protocols will be inspected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a better way to do the allowing of RDP through the firewall ?&lt;/P&gt;&lt;P&gt;Is the error I listed anything to worry about ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:58:21 GMT</pubDate>
    <dc:creator>Ronald Nutter</dc:creator>
    <dc:date>2019-03-11T17:58:21Z</dc:date>
    <item>
      <title>Allowing RDP to pass through ZBF</title>
      <link>https://community.cisco.com/t5/network-security/allowing-rdp-to-pass-through-zbf/m-p/1487247#M663316</link>
      <description>&lt;P&gt;I am setting up ZBF for a remote office that has a single server that needs to be reachable via the Internet.&amp;nbsp; So that I can get into the server remotely since it is on a standalone connection from our MPLS network, I have entered the following lines into the router config -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended ACL_RDP&lt;/P&gt;&lt;P&gt;permit tcp any host x.x.x.x eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all RDP&lt;/P&gt;&lt;P&gt; match access-group name ACL_RDP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-policy-ccp-cls--1&lt;/P&gt;&lt;P&gt;&amp;nbsp; class type inspect RDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I type the class type line, I get an error %No specific protocol defined in class RDP for inspections all protocols will be inspected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a better way to do the allowing of RDP through the firewall ?&lt;/P&gt;&lt;P&gt;Is the error I listed anything to worry about ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allowing-rdp-to-pass-through-zbf/m-p/1487247#M663316</guid>
      <dc:creator>Ronald Nutter</dc:creator>
      <dc:date>2019-03-11T17:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing RDP to pass through ZBF</title>
      <link>https://community.cisco.com/t5/network-security/allowing-rdp-to-pass-through-zbf/m-p/1487248#M663326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That messasge is not a problem. But you can specify in your class map a protocol and a port. You could match protocol TCP and port 3389 instead of using the ACL. That way the message log will not appear. But&amp;nbsp; your current config must be working fine&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 14:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allowing-rdp-to-pass-through-zbf/m-p/1487248#M663326</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-06-23T14:28:33Z</dc:date>
    </item>
  </channel>
</rss>

