11-02-2021 12:24 PM
Hi,
I almost figured out with everything I need from C1111-8P router. Overall it is an awesome machine and it can handle 1gb NAT perfectly.
I only need to config firewall and I am a little bit confused here. On RV models there is a simple "Firewall" on/off setting. What does it do? ACL config? Or something special that I need a license for?
Thank you!
11-02-2021 12:30 PM
RV Seriest more of Small business Router and FW, it does all for you it does not have CLI based config most is GUI based, yes when click FW, it enable ACL on the background high level.
ISR 1100 - based on the License your purchanged ( Security License you required) , you can use ACL on command level Like any other FW
11-02-2021 12:34 PM
Thank you
I don't have a security license, just the basic one. But I don't need anything super crazy. I just need a firewall like any other home/SB router. So it is just an ACL?
11-02-2021 12:42 PM
yes you can use ACL.
11-02-2021 01:05 PM
Thank you!
I just check the licenses and there is an option to activate securityk9. And after that I have firewall settings. Does it mean it is included with the license? But I did not buy anything besides the device itself. Or it is a trial? Or I have to pay for that every year?
11-02-2021 01:15 PM
you can click on License and see what License the kit have
11-02-2021 01:18 PM
Like this one:
Tue Nov 02 2021 16:16:53 GMT-0400 (EDT) =================================================================================== #show license all Smart Licensing Status ====================== Smart Licensing is ENABLED License Conversion: Automatic Conversion Enabled: True Status: Not started Export Authorization Key: Features Authorized: <none> Utility: Status: DISABLED Smart Licensing Using Policy: Status: ENABLED Data Privacy: Sending Hostname: yes Callhome hostname privacy: DISABLED Smart Licensing hostname privacy: DISABLED Version privacy: DISABLED Transport: Type: cslu Cslu address: <empty> Proxy: Not Configured Miscellaneous: Custom Id: <empty> Policy: Policy in use: Merged from multiple sources. Reporting ACK required: yes (CISCO default) Unenforced/Non-Export Perpetual Attributes: First report requirement (days): 365 (CISCO default) Reporting frequency (days): 0 (CISCO default) Report on change (days): 90 (CISCO default) Unenforced/Non-Export Subscription Attributes: First report requirement (days): 90 (CISCO default) Reporting frequency (days): 90 (CISCO default) Report on change (days): 90 (CISCO default) Enforced (Perpetual/Subscription) License Attributes: First report requirement (days): 0 (CISCO default) Reporting frequency (days): 0 (CISCO default) Report on change (days): 0 (CISCO default) Export (Perpetual/Subscription) License Attributes: First report requirement (days): 0 (CISCO default) Reporting frequency (days): 0 (CISCO default) Report on change (days): 0 (CISCO default) Usage Reporting: Last ACK received: <none> Next ACK deadline: Nov 02 15:56:14 2022 GMT Reporting push interval: 30 days Next ACK push check: <none> Next report push: Nov 02 15:58:14 2021 GMT Last report push: <none> Last report file write: <none> Trust Code Installed: <none> License Usage ============= securityk9 (ISR_1100_8P_Security): Description: securityk9 Count: 1 Version: 1.0 Status: IN USE Export status: NOT RESTRICTED Feature Name: securityk9 Feature Description: securityk9 Enforcement type: NOT ENFORCED License type: Perpetual Product Information =================== UDI: PID:C1111-8P,SN: Agent Version ============= Smart Agent for Licensing: 5.1.21_rel/96 License Authorizations ====================== Overall status: Active: PID:C1111-8P,SN: Status: NOT INSTALLED Purchased Licenses: No Purchase Information Available Tue Nov 02 2021 16:16:08 GMT-0400 (EDT)
11-02-2021 01:25 PM
securityk9 (ISR_1100_8P_Security): Description: securityk9 Count: 1 Version: 1.0 Status: IN USE Export status: NOT RESTRICTED Feature Name: securityk9 Feature Description: securityk9 Enforcement type: NOT ENFORCED License type: Perpetual Product Information
you got License.
11-02-2021 03:50 PM
Can you please tell me if it is possible to ask you to help with the ACL config? As I mentioned before I only need the same level of protection as RV routers offer. I am honestly lost at this point. I found some articles, but they are old and would not work on version 17. Everything I tried make the Internet unreachable from vlan.
I would really appreciate it.
Thank you!
11-03-2021 02:20 AM
Ok post from Csico Router (command level)
show run (i can suggest best i can to resolve as you expecting work like RV or near by)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide