<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic help Zone Based Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-zone-based-firewall/m-p/1332499#M832065</link>
    <description>&lt;P&gt;I have a site-to-site vpn with two 2811 Cisco Routers with 2 interfaces each&lt;/P&gt;&lt;P&gt;(LAN and WAN) and a GRE Tunnel. I have an ACL implemented to allow some PCs to have access to the VPN and another PCs to have access to Internet but deny access to vpn.&lt;/P&gt;&lt;P&gt;I want to implement Zone Based Firewall, but I don't know how many zone-pair do I &lt;/P&gt;&lt;P&gt;have to configure. I think I need one private-to-vpn, one vpn-to-private, one&lt;/P&gt;&lt;P&gt;private-to-public, but I don't know if I need to configure one public-to-private zone pair if I need to telnet/ssh the router from a public IP from outside Internet.&lt;/P&gt;&lt;P&gt;I have also some doubts about ACLs and class-maps. I don't know if I have to include these ACLs in class-maps. Or if I have different zones for each interface (include GRE Tunnel) is enough.&lt;/P&gt;&lt;P&gt;Another question is that I have read several configurations to block P2P and Instant messaging, but each of them is for a specific applications, and I'd like to know if there is a way to block all of them or I have to block each individual protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:13:10 GMT</pubDate>
    <dc:creator>usuario0001</dc:creator>
    <dc:date>2019-03-11T16:13:10Z</dc:date>
    <item>
      <title>help Zone Based Firewall</title>
      <link>https://community.cisco.com/t5/network-security/help-zone-based-firewall/m-p/1332499#M832065</link>
      <description>&lt;P&gt;I have a site-to-site vpn with two 2811 Cisco Routers with 2 interfaces each&lt;/P&gt;&lt;P&gt;(LAN and WAN) and a GRE Tunnel. I have an ACL implemented to allow some PCs to have access to the VPN and another PCs to have access to Internet but deny access to vpn.&lt;/P&gt;&lt;P&gt;I want to implement Zone Based Firewall, but I don't know how many zone-pair do I &lt;/P&gt;&lt;P&gt;have to configure. I think I need one private-to-vpn, one vpn-to-private, one&lt;/P&gt;&lt;P&gt;private-to-public, but I don't know if I need to configure one public-to-private zone pair if I need to telnet/ssh the router from a public IP from outside Internet.&lt;/P&gt;&lt;P&gt;I have also some doubts about ACLs and class-maps. I don't know if I have to include these ACLs in class-maps. Or if I have different zones for each interface (include GRE Tunnel) is enough.&lt;/P&gt;&lt;P&gt;Another question is that I have read several configurations to block P2P and Instant messaging, but each of them is for a specific applications, and I'd like to know if there is a way to block all of them or I have to block each individual protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:13:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-zone-based-firewall/m-p/1332499#M832065</guid>
      <dc:creator>usuario0001</dc:creator>
      <dc:date>2019-03-11T16:13:10Z</dc:date>
    </item>
  </channel>
</rss>

