cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2257
Views
0
Helpful
7
Replies

ASR 1000 ZBF

JIRI GRYGAREK
Level 1
Level 1

I have two questions about ZBF on ASR1000 with Firewall and Flexible Packet Inspection license:

1 is IPv6 supported?

2 can I use police action in an inspect rule? I want to limit some protocols to low bandwidth. There is no police command in ZBF policy map.

Thank you for your answer. Regards, Jiri Grygarek

1 Accepted Solution

Accepted Solutions

Hi,

The ASR platform currently does not support ipv6 Zone Based Firewall as of IOX-XE release 3.2 (15.1(1)S). The feature support is being scoped out, but no firm release date at this point yet. Hope this helps.

Thanks,

Wen

View solution in original post

7 Replies 7

padatta
Level 1
Level 1

Hi,

1. Yes, ipv6 is supported by ZBFW. Here is a reference.

http://www.cisco.com/en/US/docs/ios/ipv6/configuration/guide/ip6-sec_trfltr_fw.html#wp1072369

2. Yes, to an extent. For your reference;

http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_zone_polcy_firew.html#wp1121777

(Check under 'Rate Limiting (Policing) Traffic Within a Layer 3 and Layer 4 Policy Map')

Best Regards,

Paps

Thank you, but it seems that your answer concerns

IOS 12.4, and we use IOS XE: Cisco IOS Software, IOS-XE Software (PPC_LINUX_IOSD-ADVENTERPRISEK9-M),  Version 15.0(1)S1

Please can you confirm that this IOS is also IPv6 ZBF capable? Our basic testing indicates that IPv6 traffic pases without inspection.

We are also not able to find IPv6 ZBF in Cisco feature navigator for IOS XE.

Hi,

The ASR platform currently does not support ipv6 Zone Based Firewall as of IOX-XE release 3.2 (15.1(1)S). The feature support is being scoped out, but no firm release date at this point yet. Hope this helps.

Thanks,

Wen

Thank you for quick response.

Our testing leads to another questions:

It seems that ZBF protocol inspection goes only to L4. If we put 'match protocol sip' into class-map, we are able to connect to HTTP server running on port 5060. In the session table we can see this connection as SIP.

We thought that ZBF uses NBAR for application recognition, but now it inspects only L4. Is there any way to enable L7 protocol recognition?

We have Flexibe Packet Inspection license, what is it for?

In QOS class-map is  much more protocols recognized via match protocol command than in class-map type inspect for ZBF. What is the reason for this difference? Are both of them using NBAR?

Thank you for sharing your experiences.

Hi,

SIP ALG and AIC are only supported on the ISR platforms after 12.4(20)T. On the ASR, we currently only support SIP ALG (pinhole creation), and not AIC (application inspection and control). If the protocol is not SIP on port 5060, then the traffic is simply passed as you have observed, but it shouldn't mark the connection as SIP IMO. You may want to open a TAC case on that to have it investigated.

Sorry I don't know the answers to your other questions.

Thanks,

Wen

does the ASR platform support ipv6 Zone Based Firewall now with last IOS XE 15.1(3)S1 ?

thanks ,

Best Regards,

Marc

Hi Marc,

Not yet but its in the pipeline. Next year probably, you can contcat your Cisco accounts Team for more info from the Devs on it.

Varun

Thanks,
Varun Rao
Review Cisco Networking for a $25 gift card