<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic zone based for IOS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086341#M914478</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to chose between zone based vs cbac for branch office configurations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any recommendations? I have configured cbac before and it seems simpler&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also - i notice that an outbound acl on zonebased restricting where users can go doesn't appear to be as simple as a regular acl - any idea why this is?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Comments welcome&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karl&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:31:37 GMT</pubDate>
    <dc:creator>karljonesTZ</dc:creator>
    <dc:date>2019-03-11T13:31:37Z</dc:date>
    <item>
      <title>zone based for IOS</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086341#M914478</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to chose between zone based vs cbac for branch office configurations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any recommendations? I have configured cbac before and it seems simpler&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also - i notice that an outbound acl on zonebased restricting where users can go doesn't appear to be as simple as a regular acl - any idea why this is?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Comments welcome&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karl&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:31:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086341#M914478</guid>
      <dc:creator>karljonesTZ</dc:creator>
      <dc:date>2019-03-11T13:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: zone based for IOS</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086342#M914479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Karl, please have a look at this link, it should help you learn the differences more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5710/ps1018/prod_white_paper0900aecd806f31f9.pdf" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5710/ps1018/prod_white_paper0900aecd806f31f9.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A considerable quote from the doc:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Cisco IOS Software Classic Firewall will continue to be&lt;/P&gt;&lt;P&gt;maintained for the foreseeable future, but will not be significantly enhanced with new features.&lt;/P&gt;&lt;P&gt;Instead, the strategic development direction for Cisco IOS Software's stateful inspection firewall is&lt;/P&gt;&lt;P&gt;carried by Zone-Based Policy firewall."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2008 14:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086342#M914479</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-15T14:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: zone based for IOS</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086343#M914480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Karl,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you noted, CBAC has a much simpler configuration which still allows you to get basic firewall functionality out of an IOS device. However, as Farrukh noted, much of the development focus will be on zone-based firewall in future releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zone-based firewall's configuration is more complex, but because of this it is much more granular and allows you to do a lot more with it. If you decide to go with zone-based firewall, you'll want to make sure you understand all of the traffic flows in your network before writing the configuration or you might find yourself doing a lot of troubleshooting after the config is implemented.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2008 21:33:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086343#M914480</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-15T21:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: zone based for IOS</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086344#M914481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks everyone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a couple of questions:&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;I created a zone policy for outside-to-self and allow IPSEC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also created a policy for self-to-out to allow IPSEC from the router, is this the correct configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) I created a zone policy inside-to-outside and in this i put match access-group 101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permits branch office clients as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit tcp 192.168.x.x any eq 80&lt;/P&gt;&lt;P&gt;permit tcp 192.168.x.x any eq 443&lt;/P&gt;&lt;P&gt;permit tcp 192.168.x.x any eq 5060&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i look at the config through SDM, there is a no-entry sign on the acl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a problem with applyign an ACL such as the one above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;advice welcome&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;karl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Aug 2008 23:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-for-ios/m-p/1086344#M914481</guid>
      <dc:creator>karljonesTZ</dc:creator>
      <dc:date>2008-08-15T23:04:36Z</dc:date>
    </item>
  </channel>
</rss>

