09-29-2011 09:03 AM - edited 03-11-2019 02:32 PM
I am trying to understand this following sentence regarding zone-based firewalls on a Cisco router, why they are wrong,
1. "Interface ACLs are applied before zone-base policy firewalls when they are applied outbound."
2. "The firewalls can be configured simultaneously on the same interface as classic CBAC using the IP inspect CLI command"
Any light shed would be appreciated.
Han
09-29-2011 10:23 AM
Hi,
1) interface ACLs always take precedence over ZBF , I don't think the direction matters.
2) CBAC and ZBF are mutually exclusive on an interface to my best knowledge.
Just to be sure I will lab it up later tonight and give you the results.
Regards.
Alain.
09-30-2011 02:46 AM
Hi,
just tested ACL and ZBF and direction doesn't matter, it will always be taken into account if it denies a flow permitted by ZBF.
And CBAC and ZBF are mutually exclusive.
Regards.
Alain.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide