05-16-2020 04:59 AM
I'm just implementing ZBF on a router and trying to secure the SELF zone.
Our router peers to the ISP 's PE router on a /30.
Should we just allow the PE router eg host 1.2.3.4 eq BGP or allow the the BGP subnet 1.2.3.0/24 eq bgp?
05-16-2020 05:10 AM
Hello
I would say be a specific as possible if you can.
05-16-2020 05:18 AM
If you like to work ZBF for the BGP, thinking that Router behind ZBF. ( i would suggest to allow only required IP rather /24 - for security reason)
here is good example :
https://www.802101.com/ccie-security-zone-based-firewalls/
05-16-2020 06:24 AM
Hello @louis0001 ,
just to add a side note about ACLs and BGP: the well known BGP port TCP 179 is used on one side so I would permit traffic from host PE router address with destination port BGP AND traffic from host PE address source port BGP using two statements.
Hope to help
Giuseppe
05-16-2020 11:55 PM
Thank you. I was thinking of two statements because I'm still not sure if inspect works on the self zone so was going to use the pass statement.
Thanks for the help.
05-18-2020 02:42 PM
Sure 2 statement good to go, if you are not sure inspect works or not. make the necessary changes and see if the BGP come up or not ( personally i would go with inspect).
if no BGP peer add inspect commands.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide