cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1141
Views
0
Helpful
1
Replies

Direct Internet Access with Zone Based Firewall Rules

John Telford
Level 1
Level 1

Hi,

I'm on the Security team and was provided the below devices for security evaluation by our network group.

Question for the Zone Based Firewall (ZBFW) on this hardware:

How do you create ZBFW Rules for Direct Internet Access (DIA) in vManage?

These rules could be Inspect or Drop.

 

Is it even possible?

 

I have used the Traffic Data Rule Policy settings to test DIA (VPN.0)  but the preference is to use ZBFW only and not have to use a hybrid of ZBFW rules that perform proper statefull firewall flows and Traffic Rules that require manual 2 way setup.

 

Unit 1:

Model: C1111X-8P

Version: 16.10.2

Connectivity: biz-internet (DHCP)

Unit 2:

Model: ISR4331

Version: 16.10.2

Connectivity: biz-internet Static

 

Thanks,

John

1 Accepted Solution

Accepted Solutions

John Telford
Level 1
Level 1
Solved
had to complete configuration for DIA,

View solution in original post

1 Reply 1

John Telford
Level 1
Level 1
Solved
had to complete configuration for DIA,
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: