<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone based firewall question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326613#M811903</link>
    <description>&lt;P&gt;Hello... here is the question...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the following configuration which option is correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all myprotocols&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt;match protocol dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect myfwpolicy&lt;/P&gt;&lt;P&gt; class type inspect myprotocols&lt;/P&gt;&lt;P&gt; inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone security private&lt;/P&gt;&lt;P&gt;zone security public&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int fa0/0&lt;/P&gt;&lt;P&gt; zone-member security private&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int fa0/1&lt;/P&gt;&lt;P&gt; zone-member security public&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone-pair security priv-to-pub source private destination public&lt;/P&gt;&lt;P&gt; service-policy type inspect myfwpolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What will result from this config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) all traffic from the private zone to the public zone will be dropped&lt;/P&gt;&lt;P&gt;b)all traffic from the private zone to the public zone will be permitted but not inspected&lt;/P&gt;&lt;P&gt;c)all traffic from the private zone to the public zone will be permitted and inspected&lt;/P&gt;&lt;P&gt;d)all traffic from the public zone to the private zone will be permitted but not inspected&lt;/P&gt;&lt;P&gt;e) only HTTP and DNS traffic from the private zone to the public zone will be permitted and inspected&lt;/P&gt;&lt;P&gt;f)only HTTP and DNS traffic from the public zone to the private zone will be permitted and inspected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The test says that the correct answer is A but I say is E.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which one is right?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:00:49 GMT</pubDate>
    <dc:creator>allanc16</dc:creator>
    <dc:date>2019-03-11T16:00:49Z</dc:date>
    <item>
      <title>Zone based firewall question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326613#M811903</link>
      <description>&lt;P&gt;Hello... here is the question...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the following configuration which option is correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all myprotocols&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt;match protocol dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect myfwpolicy&lt;/P&gt;&lt;P&gt; class type inspect myprotocols&lt;/P&gt;&lt;P&gt; inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone security private&lt;/P&gt;&lt;P&gt;zone security public&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int fa0/0&lt;/P&gt;&lt;P&gt; zone-member security private&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int fa0/1&lt;/P&gt;&lt;P&gt; zone-member security public&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone-pair security priv-to-pub source private destination public&lt;/P&gt;&lt;P&gt; service-policy type inspect myfwpolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What will result from this config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) all traffic from the private zone to the public zone will be dropped&lt;/P&gt;&lt;P&gt;b)all traffic from the private zone to the public zone will be permitted but not inspected&lt;/P&gt;&lt;P&gt;c)all traffic from the private zone to the public zone will be permitted and inspected&lt;/P&gt;&lt;P&gt;d)all traffic from the public zone to the private zone will be permitted but not inspected&lt;/P&gt;&lt;P&gt;e) only HTTP and DNS traffic from the private zone to the public zone will be permitted and inspected&lt;/P&gt;&lt;P&gt;f)only HTTP and DNS traffic from the public zone to the private zone will be permitted and inspected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The test says that the correct answer is A but I say is E.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which one is right?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326613#M811903</guid>
      <dc:creator>allanc16</dc:creator>
      <dc:date>2019-03-11T16:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326614#M811904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;E is the correct answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex Yeung&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2009 14:49:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326614#M811904</guid>
      <dc:creator>Alex Yeung</dc:creator>
      <dc:date>2009-07-30T14:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326615#M811905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I knew it !!! Thanks a lot!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the SNRS exam today so I want to clear that out.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2009 14:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326615#M811905</guid>
      <dc:creator>allanc16</dc:creator>
      <dc:date>2009-07-30T14:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall question</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326616#M811907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Allan, &lt;/P&gt;&lt;P&gt;the correct answer is A, because your class-map is defined with "match-all" statemant witch says that the traffic must match both rules. In your case the traffic must be http and dns at the same time witch is impossible. To correct this you have to do:&lt;/P&gt;&lt;P&gt;class-map type inspect match-any my protocols&lt;/P&gt;&lt;P&gt;match protocol http&lt;/P&gt;&lt;P&gt;match protocol dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the correct answer will be "E" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards &lt;/P&gt;&lt;P&gt;Tihomir Yosifov &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 07:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-question/m-p/1326616#M811907</guid>
      <dc:creator>zenon_electronics</dc:creator>
      <dc:date>2009-11-06T07:39:00Z</dc:date>
    </item>
  </channel>
</rss>

