05-05-2015 09:55 AM - edited 03-11-2019 10:53 PM
we are replacing a couple 2901 with 4331 routers since we need the increased performance that the 4300 offers. But i ran into a snag, on the 2901 I have IP inspect commands allowing those protocols back in when they originate from the inside network.
the ISR 4300 software(IOS-XE) does not have IP inspect command specifically like i have on the 2901 anymore. I can still add the ACL properly but I'm not sure on the inspect commands or what they switched it to. I included the base setup for the 2901 firewall that is in place and running currently.
05-05-2015 12:07 PM
Mike
It looks like on the 2900 you were using CBAC as the firewall.
I did a quick check in Feature Navigator and for your platform it looks like CBAC is not supported so you would need to convert to Zone Based Firewalling (ZBFW).
I say looks like because Feature Navigator is not always accurate but I also couldn't find any configuration guides covering CBAC so it does suggest it isn't supported but I haven't used those routers myself.
See this link for configuration details -
I have never use ZBFW but if you are struggling to convert I'm sure there are people on here who can help out.
Jon
05-06-2015 06:42 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide