<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ZBF problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zbf-problem/m-p/3395181#M955457</link>
    <description>&lt;P&gt;Hi All!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new here, hope my question will&amp;nbsp; be in the right place, anyway here is the thing:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see my topology below. I have to configure ospf in domain east, end eigrp on west, (I know it is the other way around on the picture, but just ignore it)&lt;/P&gt;
&lt;P&gt;Im able to ping everything before I'm appling ZBF in the area of public WAN, but when applying the configuration on R1, ping is not working, and I do not know where the problem is. Please help to find it.&lt;/P&gt;
&lt;P&gt;Here is the configuration of zbf:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;R1&lt;/P&gt;
&lt;P&gt;conf t&lt;BR /&gt;zone security LAN&lt;BR /&gt;zone security WAN&lt;BR /&gt;exit&lt;BR /&gt;class-map type inspect match-any LAN_PROTOCOLS&lt;BR /&gt;match access-group 110&lt;BR /&gt;exit&lt;BR /&gt;ip access-list extended 110&lt;BR /&gt;permit tcp any any&lt;BR /&gt;permit udp any any&lt;BR /&gt;permit icmp any any&lt;BR /&gt;policy-map type inspect LAN_TO_WAN&lt;BR /&gt;class type inspect LAN_PROTOCOLS&lt;BR /&gt;inspect&lt;BR /&gt;exit&lt;BR /&gt;zone-pair security IN_TO_OUT_ZONE source LAN destination WAN&lt;BR /&gt;service-policy type inspect LAN_TO_WAN&lt;BR /&gt;exit&lt;BR /&gt;int g0/1&lt;BR /&gt;zone-member security LAN&lt;BR /&gt;int g0/0&lt;BR /&gt;zone-member security WAN&lt;BR /&gt;do wr&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topologia.jpg" style="width: 628px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12804iCB238645EE8D5AE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="topologia.jpg" alt="topologia.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:51:18 GMT</pubDate>
    <dc:creator>RacsfogV</dc:creator>
    <dc:date>2020-02-21T15:51:18Z</dc:date>
    <item>
      <title>ZBF problem</title>
      <link>https://community.cisco.com/t5/network-security/zbf-problem/m-p/3395181#M955457</link>
      <description>&lt;P&gt;Hi All!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new here, hope my question will&amp;nbsp; be in the right place, anyway here is the thing:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see my topology below. I have to configure ospf in domain east, end eigrp on west, (I know it is the other way around on the picture, but just ignore it)&lt;/P&gt;
&lt;P&gt;Im able to ping everything before I'm appling ZBF in the area of public WAN, but when applying the configuration on R1, ping is not working, and I do not know where the problem is. Please help to find it.&lt;/P&gt;
&lt;P&gt;Here is the configuration of zbf:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;R1&lt;/P&gt;
&lt;P&gt;conf t&lt;BR /&gt;zone security LAN&lt;BR /&gt;zone security WAN&lt;BR /&gt;exit&lt;BR /&gt;class-map type inspect match-any LAN_PROTOCOLS&lt;BR /&gt;match access-group 110&lt;BR /&gt;exit&lt;BR /&gt;ip access-list extended 110&lt;BR /&gt;permit tcp any any&lt;BR /&gt;permit udp any any&lt;BR /&gt;permit icmp any any&lt;BR /&gt;policy-map type inspect LAN_TO_WAN&lt;BR /&gt;class type inspect LAN_PROTOCOLS&lt;BR /&gt;inspect&lt;BR /&gt;exit&lt;BR /&gt;zone-pair security IN_TO_OUT_ZONE source LAN destination WAN&lt;BR /&gt;service-policy type inspect LAN_TO_WAN&lt;BR /&gt;exit&lt;BR /&gt;int g0/1&lt;BR /&gt;zone-member security LAN&lt;BR /&gt;int g0/0&lt;BR /&gt;zone-member security WAN&lt;BR /&gt;do wr&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topologia.jpg" style="width: 628px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12804iCB238645EE8D5AE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="topologia.jpg" alt="topologia.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-problem/m-p/3395181#M955457</guid>
      <dc:creator>RacsfogV</dc:creator>
      <dc:date>2020-02-21T15:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF problem</title>
      <link>https://community.cisco.com/t5/network-security/zbf-problem/m-p/3395805#M955458</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;R1 is the router configured with ZBFW? It's in the yellow circle and you are pinging from a device in the LAN, which is in the blue circle to a device in the WAN in the red circle?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your ZBFW configuration you've defined Gi0/1 as LAN and Gi0/0 as WAN, but in the diagram if the LAN is in the blue circle the interfaces are Serial 0/0/0 and 0/1/0 and the WAN is Gi0/1 (not LAN as per config). You may just need to apply the correct zone-member to the correct interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please clarify your configuration so we can troubleshoot further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-problem/m-p/3395805#M955458</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-06-07T15:32:13Z</dc:date>
    </item>
  </channel>
</rss>

