Hi,
I would recommend using Zone-Based Firewall. ZFW has more flexibility in inspecting traffic that CBAC FW. ZFW is based on security zone, where as CBAC is associated to interface.
In simple context, ZFW is like extended acl and CBAC is like standard acl.