<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone based firewall VPN problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-vpn-problem/m-p/1227223#M875532</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides the NetSupport traffic, are you able to see any other traffic can be communicated between the remote VPN client and the local PC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For troubleshooting, instead of using the class-map to inspect NetSupport traffic, can you inspect all traffic (i.e. any to any) using the same policy-maps and zone-pair configs and see if that works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a TAC case opened for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex Yeung&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Mar 2009 00:02:04 GMT</pubDate>
    <dc:creator>Alex Yeung</dc:creator>
    <dc:date>2009-03-03T00:02:04Z</dc:date>
    <item>
      <title>Zone based firewall VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-vpn-problem/m-p/1227222#M875531</link>
      <description>&lt;P&gt;I am trying to set up a VPN using a 871 router. The VPN is to be used by a remote client who will gain remote access to a PC using NetSupport software, a product similar to PCAnywhere. I am able to establish the VPN connection but the NetSupport software at the client is unable to connect to the PC behind the router. I have not been able to figure out how to configure the router's firewall to allow NetSupport (port 5405) traffic. My attempt so far consists of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a port to application mapping for NetSupport:&lt;/P&gt;&lt;P&gt;ip port-map user-NetSupport port tcp 5405&lt;/P&gt;&lt;P&gt;I created a class map:&lt;/P&gt;&lt;P&gt;class-map type inspect match-any sdm_NetSupport_traffic&lt;/P&gt;&lt;P&gt; match protocol user-NetSupport&lt;/P&gt;&lt;P&gt;I created a second class map (probably unnessary but I was trying to replicate what SDM had created for the VPN)&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm_NetSupport_pt&lt;/P&gt;&lt;P&gt; match class-map sdm_NetSupport_traffic&lt;/P&gt;&lt;P&gt;I created a policy map:&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-permit-netsupport&lt;/P&gt;&lt;P&gt; class type inspect sdm_NetSupport_pt&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class type inspect SDM_IP&lt;/P&gt;&lt;P&gt;  pass&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;  drop&lt;/P&gt;&lt;P&gt;I then applied this policy to the VPN/Inzone zone pair&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-ezvpn-in1 source ezvpn-zone destination in-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-permit-netsupport&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I apologise for my lack of IOS knowledge, I have looked at all the CISCO documents on zone based firewalls and what I have done seems to make sense according to what I have read. Any help would be greatly appreciated. I have attached my running config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-vpn-problem/m-p/1227222#M875531</guid>
      <dc:creator>FredBloggs2</dc:creator>
      <dc:date>2019-03-11T14:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-vpn-problem/m-p/1227223#M875532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides the NetSupport traffic, are you able to see any other traffic can be communicated between the remote VPN client and the local PC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For troubleshooting, instead of using the class-map to inspect NetSupport traffic, can you inspect all traffic (i.e. any to any) using the same policy-maps and zone-pair configs and see if that works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a TAC case opened for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex Yeung&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 00:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-vpn-problem/m-p/1227223#M875532</guid>
      <dc:creator>Alex Yeung</dc:creator>
      <dc:date>2009-03-03T00:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Zone based firewall VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-vpn-problem/m-p/1227224#M875533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The answer to the first question is no. I have not even been able to ping the local PC over the VPN. I tried to inspect all traffic by doing the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended SDM_ALL_TCP&lt;/P&gt;&lt;P&gt; remark SDM_ACL Category=1&lt;/P&gt;&lt;P&gt; permit tcp any any&lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-any sdm_all_tcp_cmap&lt;/P&gt;&lt;P&gt; match access-group name SDM_ALL_TCP&lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm_inspect_tcp_all&lt;/P&gt;&lt;P&gt; class type inspect sdm_all_tcp_cmap&lt;/P&gt;&lt;P&gt;  no drop&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt;  exit&lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-ezvpn-in1 source ezvpn-zone destination in-zone&lt;/P&gt;&lt;P&gt; no service-policy type inspect sdm-permit-netsupport&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm_inspect_tcp_all&lt;/P&gt;&lt;P&gt; exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it made no difference. I have now opened a TAC case but thanks for your help anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 18:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-vpn-problem/m-p/1227224#M875533</guid>
      <dc:creator>FredBloggs2</dc:creator>
      <dc:date>2009-03-03T18:16:44Z</dc:date>
    </item>
  </channel>
</rss>

