<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zone-based firewall problem ! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090839#M893453</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Come on guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nobody knows about zone-based policy firewall and how it's working? Please, help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rvr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Nov 2008 14:06:22 GMT</pubDate>
    <dc:creator>rvr_76bg</dc:creator>
    <dc:date>2008-11-18T14:06:22Z</dc:date>
    <item>
      <title>Zone-based firewall problem !</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090838#M893451</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have problem with zone-based firewall on Cisco 2821 Router. This pretty new feature doesn't work for me. On the router I have one internal gigabit0/1 Interface which is in zone â&amp;#128;&amp;#156;INâ&amp;#128;&amp;#157; (in private network), gigabit0/0 Interface in zone â&amp;#128;&amp;#156;OUTâ&amp;#128;&amp;#157; (in Internet) and one VTI in zone â&amp;#128;&amp;#156;INâ&amp;#128;&amp;#157; (to be able to communicate with g0/1 without any problem, it carries OSPF over VPN). I have the following zone-pairs created: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-self-out source self destination out-zone&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-out-self source out-zone destination self&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-in-out source in-zone destination out-zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPN is passing traffic, because the routing table is updated and I see all routes coming from the other site of the VPN. The problem is that I cannot pass IP/TCP/UDP traffic beyond the routers (in the private networks) on both sides. May be I missed a zone-pair? Please help. The problem is a bit urgent for me and any help will be highly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rvr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090838#M893451</guid>
      <dc:creator>rvr_76bg</dc:creator>
      <dc:date>2019-03-11T14:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Zone-based firewall problem !</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090839#M893453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Come on guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nobody knows about zone-based policy firewall and how it's working? Please, help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rvr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Nov 2008 14:06:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090839#M893453</guid>
      <dc:creator>rvr_76bg</dc:creator>
      <dc:date>2008-11-18T14:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Zone-based firewall problem !</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090840#M893454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please provide the configuration of the router.&lt;/P&gt;&lt;P&gt;Also, if you could post the output of the IP INSPECT LOG DROP-PKT.&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Torchris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2008 16:38:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090840#M893454</guid>
      <dc:creator>torchris</dc:creator>
      <dc:date>2008-11-19T16:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Zone-based firewall problem !</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090841#M893455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, just as additional information, I had the same problem once where the VPN tunnel is established but I am unable to pass traffic between the Local LAN and the remote LAN.&lt;/P&gt;&lt;P&gt;In order to make it work, I did an access-list from the LOCAL LAN to the remote one and I put it on the zone-pair that is from the out-zone to the self zone.&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Nov 2008 16:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-problem/m-p/1090841#M893455</guid>
      <dc:creator>torchris</dc:creator>
      <dc:date>2008-11-20T16:29:26Z</dc:date>
    </item>
  </channel>
</rss>

