cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
370
Views
0
Helpful
1
Replies

CBAC in IOS-XE on ESR 6300

ronald loftus
Level 1
Level 1

Does IOS-XE 17.9.x still support the Stateful CBAC firewall features that use the IP INSPECT command set? This capability was available in IOS. We are transitioning from IOS to IOS-XE on edge router and are not seeing the same CLI commands for CBAC. Do we have to use ZBF?

1 Reply 1

urathod
Cisco Employee
Cisco Employee

Hello Ronald,

 

IOS-XE 17.9.x still supports Stateful CBAC firewall features, but the configuration has changed from using the "IP INSPECT" command set to using the "Zone-Based Policy Firewall" (ZBF) command set.

ZBF is a more advanced and flexible firewall technology than CBAC, and it allows you to define policies based on zones rather than IP addresses. ZBF also supports advanced features such as application-layer inspection and user-based policies.

Review Cisco Networking for a $25 gift card