cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
404
Views
0
Helpful
3
Replies

CBAC Firewall Locations

rasoftware
Level 1
Level 1

Am I better to place the CBAC inspection on the outside "out" or inside "in" interface?

Is there a rule as with standard and exteneded ACLs?

1 Accepted Solution

Accepted Solutions

Yes, I would also think that it's better to apply it in the outside interface because that is more likely to be the point of entry for malicious traffic.

Paresh

View solution in original post

3 Replies 3

pkhatri
Level 11
Level 11

Hi,

The general rule with filtering is to filter as early as possible. However, your circumstances will dictate whether you place it on the inside or the outside interface.

Paresh

I'm guessing unless I need specific inspections for the inside "in" ie DMZ and LAN I would be better putting this on the outside "out" to prevent un-necessary traffic coming into the router then getting dropped?

I ask because I inherited two routers on a new network, one seems to filter on LAN other onthe outside.

Yes, I would also think that it's better to apply it in the outside interface because that is more likely to be the point of entry for malicious traffic.

Paresh

Review Cisco Networking for a $25 gift card