cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3743
Views
5
Helpful
9
Replies

ISR 1100 - Firewall. How it works.

pro100bear
Level 1
Level 1

Hi,

 

I almost figured out with everything I need from C1111-8P router. Overall it is an awesome machine and it can handle 1gb NAT perfectly.

I only need to config firewall and I am a little bit confused here. On RV models there is a simple "Firewall" on/off setting. What does it do? ACL config? Or something special that I need a license for?

 

Thank you!

9 Replies 9

balaji.bandi
Hall of Fame
Hall of Fame

RV Seriest more of Small business Router and FW, it does all for you it does not have CLI based config most is GUI based, yes when click FW, it enable ACL on the background high level.

 

ISR 1100  - based on the License your purchanged ( Security License you required) , you can use ACL on command level Like any other FW

 

https://www.cisco.com/c/en/us/products/collateral/routers/1000-series-integrated-services-routers-isr/datasheet-c78-739512.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you

 

I don't have a security license, just the basic one. But I don't need anything super crazy. I just need a firewall like any other home/SB router. So it is just an ACL?

yes you can use ACL.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you!

I just check the licenses and there is an option to activate securityk9. And after that I have firewall settings. Does it mean it is included with the license? But I did not buy anything besides the device itself. Or it is a trial? Or I have to pay for that every year?

you can click on License and see what License the kit have

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Like this one:

 

Tue Nov 02 2021 16:16:53 GMT-0400 (EDT)
===================================================================================
#show license all
Smart Licensing Status
======================
Smart Licensing is ENABLED
License Conversion:
Automatic Conversion Enabled: True
Status: Not started
Export Authorization Key:
Features Authorized:
<none>
Utility:
Status: DISABLED
Smart Licensing Using Policy:
Status: ENABLED
Data Privacy:
Sending Hostname: yes
Callhome hostname privacy: DISABLED
Smart Licensing hostname privacy: DISABLED
Version privacy: DISABLED
Transport:
Type: cslu
Cslu address: <empty>
Proxy:
Not Configured
Miscellaneous:
Custom Id: <empty>
Policy:
Policy in use: Merged from multiple sources.
Reporting ACK required: yes (CISCO default)
Unenforced/Non-Export Perpetual Attributes:
First report requirement (days): 365 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 90 (CISCO default)
Unenforced/Non-Export Subscription Attributes:
First report requirement (days): 90 (CISCO default)
Reporting frequency (days): 90 (CISCO default)
Report on change (days): 90 (CISCO default)
Enforced (Perpetual/Subscription) License Attributes:
First report requirement (days): 0 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 0 (CISCO default)
Export (Perpetual/Subscription) License Attributes:
First report requirement (days): 0 (CISCO default)
Reporting frequency (days): 0 (CISCO default)
Report on change (days): 0 (CISCO default)
Usage Reporting:
Last ACK received: <none>
Next ACK deadline: Nov 02 15:56:14 2022 GMT
Reporting push interval: 30 days
Next ACK push check: <none>
Next report push: Nov 02 15:58:14 2021 GMT
Last report push: <none>
Last report file write: <none>
Trust Code Installed: <none>
License Usage
=============
securityk9 (ISR_1100_8P_Security):
Description: securityk9
Count: 1
Version: 1.0
Status: IN USE
Export status: NOT RESTRICTED
Feature Name: securityk9
Feature Description: securityk9
Enforcement type: NOT ENFORCED
License type: Perpetual
Product Information
===================
UDI: PID:C1111-8P,SN:
Agent Version
=============
Smart Agent for Licensing: 5.1.21_rel/96
License Authorizations
======================
Overall status:
Active: PID:C1111-8P,SN:
Status: NOT INSTALLED
Purchased Licenses:
No Purchase Information Available
Tue Nov 02 2021 16:16:08 GMT-0400 (EDT)

securityk9 (ISR_1100_8P_Security):
Description: securityk9
Count: 1
Version: 1.0
Status: IN USE
Export status: NOT RESTRICTED
Feature Name: securityk9
Feature Description: securityk9
Enforcement type: NOT ENFORCED
License type: Perpetual
Product Information

you got License.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Can you please tell me if it is possible to ask you to help with the ACL config? As I mentioned before I only need the same level of protection as RV routers offer. I am honestly lost at this point. I found some articles, but they are old and would not work on version 17. Everything I tried make the Internet unreachable from vlan.

 

I would really appreciate it.

 

Thank you!

Ok post from Csico Router (command level)

 

show run (i can suggest best i can to  resolve as you expecting work like RV or near by)

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card