02-14-2012 07:44 PM - edited 03-11-2019 03:29 PM
What is the best way to deploy the IOS firewall feature?
I have a Cisco 1841 router running 12.4.
Solved! Go to Solution.
02-16-2012 12:44 PM
Well, if you have featured licensed on your router for ZoneBase firewall then stick with Zone Base, which is more flexible, if there ZoneBase Firewall is not licensed then stick with CBAC.
Hope that answers your question.
Thanks
Rizwan Rafeek
02-16-2012 12:44 PM
Well, if you have featured licensed on your router for ZoneBase firewall then stick with Zone Base, which is more flexible, if there ZoneBase Firewall is not licensed then stick with CBAC.
Hope that answers your question.
Thanks
Rizwan Rafeek
02-16-2012 06:46 PM
Well, I think on the 12.4 versions on those 1841s, so can really enable any of those features as long as you have the enterprise IOS version right? and I also believe that there is no license per se on these platforms.
For the new 15 versions I believe you do need the respective licenses to have certain features.
Please confirm.
Now, with regards to those 2 features, are they 2 totally different features? and if so, what is the difference?
What I am trying to accomplish here is simply make an 1841 running 12.4 enterprise behave like a real full stateful inspection engine (firewall). I know that the router CPU is gonna be taxed a bit, but I really needed and the load is not that heavy on this environment.
I also have another environment with a 2911 router and we purchased the IOS Firewall feature license. This license enabled us to activate the IP Inspect commands. What is this called? I thought it was only called IOS Firewall feature.
thank you
02-16-2012 08:18 PM
"What is this called? I thought it was only called IOS Firewall feature."
Yes there is feature called IOS firewall but nobody use it because it is not so flexialbe with applications.
So, best bet is CBAC or Zone Firewall.
thanks
Rizwan Rafeek
02-17-2012 09:09 PM
The "IOS Firewall Feature" is the one that you enable with the IP Inspect command and then apply it to an interface?
And are CBAC and Zone Firewall two different things or are they the same thing?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide