cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
419
Views
0
Helpful
3
Replies

IOS zone based firewall

sarahr202
Level 5
Level 5

HI everybody.

I have few questions.

policy-map type inspect PING

class type inspect PING

  inspect

class class-default

  pass

1)What is the order of operation?  The" inspect"  action will apply only to class " PING" . The action " pass" will be applied to class" default"   Am i correct?

-----------------------------------------------------

policy-map type inspect PING

class type inspect PING

  inspect

class class-default

2) What would be the action for class " default" when none is specified  as shown above ?

3)

class-map type inspect LEE

Above if we don't mention " match-all or match any"  , what is the default?

thanks and have a great day.

1 Accepted Solution

Accepted Solutions

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Sarah,

1)What is the order of operation?  The" inspect"  action will apply only to class " PING" . The action " pass" will be applied to class" default"   Am i correct?

You got it, from top to bottom we will check the policy-maps.

2) What would be the action for class " default" when none is specified  as shown above ?

Drop by default

3)class-map type inspect LEE

Above if we don't mention " match-all or match any"  , what is the default?

I think it's a match all by default

Do a quick show run | sec class-map to figure it out

Remember to rate all of the helpful posts.

For this community that's as important as a thanks.

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

3 Replies 3

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Sarah,

1)What is the order of operation?  The" inspect"  action will apply only to class " PING" . The action " pass" will be applied to class" default"   Am i correct?

You got it, from top to bottom we will check the policy-maps.

2) What would be the action for class " default" when none is specified  as shown above ?

Drop by default

3)class-map type inspect LEE

Above if we don't mention " match-all or match any"  , what is the default?

I think it's a match all by default

Do a quick show run | sec class-map to figure it out

Remember to rate all of the helpful posts.

For this community that's as important as a thanks.

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks Jcarvaja

Hey Sarah,

My pleasure,

Have a good one

Remember to rate all of the helpful posts.

For this community that's as important as a thanks.

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card