03-24-2011 01:07 AM - edited 03-11-2019 01:12 PM
I have two questions about ZBF on ASR1000 with Firewall and Flexible Packet Inspection license:
1 is IPv6 supported?
2 can I use police action in an inspect rule? I want to limit some protocols to low bandwidth. There is no police command in ZBF policy map.
Thank you for your answer. Regards, Jiri Grygarek
Solved! Go to Solution.
03-24-2011 07:24 PM
Hi,
The ASR platform currently does not support ipv6 Zone Based Firewall as of IOX-XE release 3.2 (15.1(1)S). The feature support is being scoped out, but no firm release date at this point yet. Hope this helps.
Thanks,
Wen
03-24-2011 01:24 AM
Hi,
1. Yes, ipv6 is supported by ZBFW. Here is a reference.
http://www.cisco.com/en/US/docs/ios/ipv6/configuration/guide/ip6-sec_trfltr_fw.html#wp1072369
2. Yes, to an extent. For your reference;
(Check under 'Rate Limiting (Policing) Traffic Within a Layer 3 and Layer 4 Policy Map')
Best Regards,
Paps
03-24-2011 04:41 AM
Thank you, but it seems that your answer concerns
IOS 12.4, and we use IOS XE: Cisco IOS Software, IOS-XE Software (PPC_LINUX_IOSD-ADVENTERPRISEK9-M), Version 15.0(1)S1
Please can you confirm that this IOS is also IPv6 ZBF capable? Our basic testing indicates that IPv6 traffic pases without inspection.
We are also not able to find IPv6 ZBF in Cisco feature navigator for IOS XE.
03-24-2011 07:24 PM
Hi,
The ASR platform currently does not support ipv6 Zone Based Firewall as of IOX-XE release 3.2 (15.1(1)S). The feature support is being scoped out, but no firm release date at this point yet. Hope this helps.
Thanks,
Wen
03-25-2011 02:40 AM
Thank you for quick response.
Our testing leads to another questions:
It seems that ZBF protocol inspection goes only to L4. If we put 'match protocol sip' into class-map, we are able to connect to HTTP server running on port 5060. In the session table we can see this connection as SIP.
We thought that ZBF uses NBAR for application recognition, but now it inspects only L4. Is there any way to enable L7 protocol recognition?
We have Flexibe Packet Inspection license, what is it for?
In QOS class-map is much more protocols recognized via match protocol command than in class-map type inspect for ZBF. What is the reason for this difference? Are both of them using NBAR?
Thank you for sharing your experiences.
03-25-2011 01:32 PM
Hi,
SIP ALG and AIC are only supported on the ISR platforms after 12.4(20)T. On the ASR, we currently only support SIP ALG (pinhole creation), and not AIC (application inspection and control). If the protocol is not SIP on port 5060, then the traffic is simply passed as you have observed, but it shouldn't mark the connection as SIP IMO. You may want to open a TAC case on that to have it investigated.
Sorry I don't know the answers to your other questions.
Thanks,
Wen
10-17-2011 09:40 AM
does the ASR platform support ipv6 Zone Based Firewall now with last IOS XE 15.1(3)S1 ?
thanks ,
Best Regards,
Marc
10-17-2011 10:05 AM
Hi Marc,
Not yet but its in the pipeline. Next year probably, you can contcat your Cisco accounts Team for more info from the Devs on it.
Varun
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide