cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2205
Views
0
Helpful
3
Replies

Cisco router IOS stateful inspection

Ruterford
Level 1
Level 1

Hi All,

Wondering if TCP state bypass can be applied on a Cisco router based IOS firewall (ip inspection)

Thanks!

3 Replies 3

lcambron
Level 3
Level 3

Hello,

TCP State Bypass in only on ASAs, I don't think there is something similar on CBAC(ip inspect).

You may need to migrate to ZBF.

With Zone Based Firewall, you can inspect,pass or drop traffic.

I hope it helps.

Regards,

Felipe.

Thanks for your reply.

Thinking on using reflexive ACL instead of stateful inspection.

Would it increase load on the CPU significantly?

I see that entry is created every time packet trespassing interface where the reflex access-list is in out state.

Even in both directions.

Hi,

I'm not an expert on reflexive ACLs but I dont think this will increase much the cpu.

Regards,

Felipe.

Review Cisco Networking for a $25 gift card