cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
743
Views
0
Helpful
2
Replies

Alternatives to Reflexive or CBAC on 4500r+e

Brian Saunders
Level 1
Level 1

Hey All,

 

Was going to deploy reflexive ACLs on some campus distribution switches last night and found out they aren't an option on 4500r+e switches or ISR 4321 routers.  Anyone have any recommendations on alternative options?  The reflexive ACLs would be applied on the VLAN interfaces and would restrict inbound traffic to only specific destinations (untrusted to trusted) and all outbound traffic (trusted to untrusted) would be permitted through the reflect.  From what I can tell there doesn't seem to be any options besides just having an extended ACL but that would require opening up alot of unnecessary access initiated from the untrusted side.

 

Brian

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

The ISRs should run ZBFW (Zone Based Firewall) presuming you have the right software bundle.

You won't be able to do anything with the 4500s in that regard except router acls which are not stateful.

Jon

View solution in original post

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

The ISRs should run ZBFW (Zone Based Firewall) presuming you have the right software bundle.

You won't be able to do anything with the 4500s in that regard except router acls which are not stateful.

Jon

That's what I figured - thanks!

Review Cisco Networking products for a $25 gift card